Cyber Information Assurance Analyst

The Pennsylvania State UniversityUniversity Park, FL
2dHybrid

About The Position

We are searching for an experienced Information Systems Security Manager (ISSM) to join our Cybersecurity Division at the Applied Research Laboratory (ARL) at Penn State. Information Technology Services provides ARL’s administrative and research computing environments and capabilities, delivering secure, responsive, efficient, effective, and compliant IT services and operations to meet the demanding needs of ARL’s leading edge research. This position will have a focus on the unclassified space, overseeing and owning the unclassified information security program, including implementing our various compliance requirements like the Cybersecurity Maturity Model Certification (CMMC). This ISSM will however operate within and support both unclassified and collateral spaces, backing up fellow ISSM’s and enforcing commonalities between environments where possible. They will be responsible for developing and maintaining policy and security documentation, providing cybersecurity recommendations for system, network, and application design, leading information system risk assessments, assist in leading incident response actions, setting standards for continuous monitoring processes such as auditing or vulnerability assessments, and ensuring cybersecurity requirements are effectively and efficiently communicated to operational and researcher team leadership to ensure integration into their respective team processes. ARL is an authorized DoD SkillBridge partner and welcomes all transitioning military members to apply.

Requirements

  • Current eligibility for access to classified information at the Top-Secret level or higher and may be subject to a government background investigation to upgrade clearance eligibility, if required
  • Assessment and Authorization experience of systems and networks using CMMC and RMF NIST/ISO standards (eg. NIST SP 800-53 and NIST SP 800-171), Department of Defense directives, DISA STIG, and regulatory requirements
  • Strong technical background, with significant experience using multiple operating systems to include Windows and Linux
  • Policy, procedure, plan of action and milestone, risk assessment and security plan development with experience of continuous monitoring for compliance with said documentation
  • System functions, security policies, technical security safeguards, and operational security measures
  • The ability to certify and maintain information security related certifications (eg. Security+, CISSP, and any other required certifications)
  • Excellent communications, analytical and problem-solving skills
  • Efficient organizational, multitasking, and time management abilities

Nice To Haves

  • A Bachelor’s degree in Information Security, Information Technology, or Computer Science
  • Management or leadership experience in IT and information security space
  • Vulnerability scanning and mitigation utilizing Nessus, Retina, GFI Languard, or similar tool
  • Experience with networking fundamentals including various concepts, tools, and administrative functions
  • Working knowledge of container image security and experience overseeing security for containerized environments (docker, podman, etc)
  • SEIM management or use for analysis, such as Splunk, ELK, or AlienVault
  • VMWare and management of Virtual Machines
  • Training material development

Responsibilities

  • Develop, validate, submit, and maintain information system security plans, certification and authorization packages, and plans of action and milestones in support of compliance requirements
  • Oversee development and implementation of risk assessments against information systems in all phases of their lifecycles
  • Provide cybersecurity recommendations for system, network, and application design
  • Monitor and assist in the assessment and review of current and new systems and networks to ensure compliance with current cybersecurity policies, concepts, and measures
  • Develop training material related to compliance and audit requirements to assist employees in individual compliance/audits as applicable
  • Assist in technical requirements such as; vulnerability scanning, review of security/event logs, network analysis, and incident response on an as-needed basis

Benefits

  • Penn State provides a competitive benefits package for full-time employees designed to support both personal and professional well-being.
  • In addition to comprehensive medical, dental, and vision coverage, employees enjoy robust retirement plans and substantial paid time off which includes holidays, vacation and sick time.
  • One of the standout benefits is the generous 75% tuition discount, available to employees as well as eligible spouses and children.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service