Design, implement, and manage security solutions, including firewalls, intrusion detection/prevention systems, endpoint protection, and encryption mechanisms to ensure the organization's networks and systems remain secure.
Conduct regular security assessments to identify vulnerabilities and weaknesses in systems, networks, and applications.
Develop and implement incident response plans to effectively address security breaches, incidents, and breaches.
Collaborate with cross-functional teams to establish and enforce security policies, standards, and procedures.
Monitor network traffic, system logs, and security alerts to detect and respond to potential security incidents.
Analyze and investigate anomalies and security breaches, taking appropriate actions to mitigate risks.
Work closely with cross-functional teams, including IT, software development, and compliance, to integrate security into all phases of the development lifecycle and ensure a comprehensive approach to cybersecurity.
Maintain thorough and accurate documentation of security processes, procedures, and configurations. Prepare detailed reports on security findings, incidents, and actions taken.
Requirements
Active Secret clearance, or ability to obtain one
4+ years of experience as a cybersecurity analyst with a specialization in Government System ATO support, demonstrating deep knowledge of government ATO principles, methodologies, and tools.
Strong experience in government regulatory frameworks, compliance requirements, and security standards specific to ATO (e.g., NIST SP 800-53, RMF, ICD 503, FISMA, FedRAMP).
Demonstrated and repeat experience achieving and maintaining ATO for cloud services and solutions from IL5 to IL6+ on NIPR and SIPR.
Understanding of network protocols, operating systems, and infrastructure components.
Strong proficiency in incident response, security incident handling, and forensic analysis techniques.
Expertise with government specific ATO assessment tools, vulnerability scanning tools, and intrusion detection/prevention systems.
Effective communication skills, with the ability to convey complex technical concepts to both technical and non-technical stakeholders.
CISSP or equivalent certification to support DoD 8140 requirements.