Cyber Security Analyst II

Scientific Research CorporationSan Diego, CA
$84,000 - $139,950Onsite

About The Position

Developing and updating assessment and authorization documentation (Body of Evidence) for management and continuous monitoring of information systems. Performing ongoing compliance assessments using tools, such as Assured Compliance Assessment Solution (ACAS), Secure Content Automation Protocol (SCAP), and Trellix Virus Scan Enterprise while reviewing, documenting, and maintaining all results. Verifying patches and virus definitions to the systems using existing automated tools. Adhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systems. Performing security audits using to track multiple events including any signs of inappropriate or unusual activity, intrusion events, data transfers, etc. Performing security assessments of NCS Family of Systems in accordance with NIST, Navy, NSA, and NAVINTEL IA guidance. Working with system engineers to take corrective action to resolve identified problems. Performing Site Based Security Assessments (SBSAs) of systems and recommending authorization to the Designated Authorizing Official (DAO) as a certified Trusted Agent. Reporting security incidents in accordance with the Command Incident Response Plan (CIRP). Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices.

Requirements

  • 5-8 years of cybersecurity experience
  • Must currently hold a DoD 8140-compliant IAT II certification ( Security+CE with appropriate CE/OS certificate), or IAT level II certification within six months
  • Knowledge of Risk Management Framework (RMF) v3 and v5 (Processes, workflow, etc.)
  • Experience with System Security Plans (SSPs), POA&Ms, ACAS/Nessus, SCAP, DISA STIGs, and all ATO package artifacts
  • Ability to work collaboratively with sys admins/ISSE's, communicate effectively, and coordinate STIG remediation with system administrators and developers
  • Experience with continuous monitoring tools such as LATTEART, BISCOTTI, and CYBORGBUNNY
  • Ability to manage tasks with little to no oversight or support as well as manage multiple, and at times, competing priorities without loss of productivity
  • Ability to use eMASS to execute, RMF v5, to include document and update system status, identify, document, and manage implementation of operational and technical security controls, implementation and risk assessment tabs, non-compliant and non-validated controls, POAM management (entry, evidence, close-out), produce report and track Plan of Action and Milestone (POA&M) due dates, etc.
  • Be open to new and innovative ideas
  • Must be able to be appointed ISSO for NCS systems within 6 months of employment

Nice To Haves

  • Experience with Windows and UNIX based information systems standards with a working knowledge of networking devices
  • Knowledge of configuration and manual STIG reviews of various SQL databases, including MS SQL, PostgreSQL, MongoDB, MariaDB, MySQL, and Elasticsearch
  • Knowledge of web servers, including Apache Web Server, and Apache Tomcat
  • Experience with container security and DevSecOps
  • Knowledge of data flows and the ability to work up readable network topology and data flow diagrams
  • Experience with NAVINTEL IA and NSA enterprise services: Continuous Monitoring
  • Experience with the following systems/platforms/tools: XACTA, XACTA 360 (preferred), eMASS, HBSS, ACAS, Nessus, and SPLUNK
  • Experience implementing and/or monitoring for zero trust compliance

Responsibilities

  • Developing and updating assessment and authorization documentation (Body of Evidence) for management and continuous monitoring of information systems
  • Performing ongoing compliance assessments using tools, such as Assured Compliance Assessment Solution (ACAS), Secure Content Automation Protocol (SCAP), and Trellix Virus Scan Enterprise while reviewing, documenting, and maintaining all results
  • Verifying patches and virus definitions to the systems using existing automated tools
  • Adhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systems
  • Performing security audits using to track multiple events including any signs of inappropriate or unusual activity, intrusion events, data transfers, etc.
  • Performing security assessments of NCS Family of Systems in accordance with NIST, Navy, NSA, and NAVINTEL IA guidance
  • Working with system engineers to take corrective action to resolve identified problems
  • Performing Site Based Security Assessments (SBSAs) of systems and recommending authorization to the Designated Authorizing Official (DAO) as a certified Trusted Agent
  • Reporting security incidents in accordance with the Command Incident Response Plan (CIRP)
  • Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices

Benefits

  • medical
  • dental
  • vision plans
  • 401(k) with a company match
  • life insurance
  • vacation and sick paid time off accruals with amounts increasing based on role and years of service
  • 11 paid holidays
  • tuition reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service