Cloud Information Security Analyst

SAIC•Scott AFB, IL
•Onsite

About The Position

SAIC is seeking an Information Systems Assessment and Authorization analyst for the Cloud team to support an IT Service Management effort for USTRANSCOM located at Scott Air Force Base (AFB) in Illinois. The USTC Managed Information Technology Services (MITS) contract provides strategic, technical, and program management guidance and support services to facilitate the operations and modernization of the combatant command’s infrastructure, systems, and applications. This support will be provided to the USTC Command, Control, Communications & Cyber Systems Directorate (TCJ6). The successful candidate will be responsible for working on high-visibility or mission critical aspects of a given program and performing all functional duties with some oversight.

Requirements

  • 5+ Years with BS or 3+ Years with MS or 0 Years with PhD.
  • DoD Secret clearance or higher.
  • Must have at least one of these IAT Level II certifications: Security+, CECCNA-Security, CySA+ , GICSP, GSEC, CND, SSCP.
  • Must have at least one Computing Environment (CE) certification or certificate for the technical area of responsibility for Network. support/defense (e.g., Splunk, Cisco, McAfee, etc.) OR Operating System (e.g., Microsoft, Linux, Solaris, AWS Cloud Practitioner, AWS Solutions Architect etc.
  • Familiarity with AWS cloud concepts and services.
  • Familiarity with DevOps practices in an agile environment.

Nice To Haves

  • MA/MS.
  • ITIL Foundations (v4 or higher) certification.
  • One of the IAM Level II certifications: CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC, CCISO, HCISPP.

Responsibilities

  • Develop and coordinate all authorization documentation associated including the Systems Categorization, Systems Security Plan, and Systems risk assessment.
  • Support the control assessment, reporting and monitoring processes using the Cyber Security and Assessment Management (CSAM) system.
  • Create and maintain all minor/major modification documentation.
  • Maintain all waivers and Risk assessment for the ISSMs.
  • Assist the ISSMs with decisions that affect security of their systems and networks.
  • Facilitate preparations for all Contingency/Incident response assessments.
  • Perform and document risk assessments, analyzing security vulnerabilities, and the metrics to measure the risks associated with those vulnerabilities.
  • Design and development of comprehensive Systems Security Plan, covering at a high level the infrastructure, policies and procedures which define the systems security profile for the enclave systems.
  • Review and validate System Test and Evaluation (ST&E) and Interim Authority to Test (IATT) reviews for new and/or legacy systems.
  • Review and conduct NIST-based Self Assessments, identifying any weaknesses which need to be addressed, and developing a POA&M for each of those weaknesses based on industry best practices.
  • Requesting risk acceptance for vulnerabilities that cannot be remediated or mitigated.
  • Based on the risk profile, Create and track Plan of Action and Milestones (POA&M) for mitigation of risks identified via the ACAS and STIG processes.
  • Design and development of Initial Privacy Assessment (IPA) and Privacy Impact Assessments (PIAs) for each major Federal Government IT Systems
  • Developing and conducting System Test and Evaluations (ST&Es) and Independent Verification and Validation (IV&Vs) of the security profiles of Federal Government IT Systems.
  • Utilize the eMass tool to manage the security profile for the system.
  • Utilize the PPSM tool and processes to register ports protocols and services in use by the enclaves.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service