Cybersecurity Analyst Job at Mount Indie, San Miguel, CA

S0xQemt5KzNHZUNRcytlOWxFMlFZU2pZ
  • Mount Indie
  • San Miguel, CA

Job Description

Job Description

Job Description

The Local Defender serves as a critical cybersecurity role that combines ISSO responsibilities with traditional Security Operations Center (SOC) and Threat Analyst functions. The position is pivotal in maintaining the cybersecurity posture of systems under its purview by supporting system authorization, implementing cybersecurity policies, and ensuring continuous monitoring in accordance with DoD Risk Management Framework (RMF). This individual will proactively manage compliance with cybersecurity directives, respond to incidents, and provide support to the Government customer by implementing technical and procedural safeguards based on RMF controls. This role requires the ability to work independently, support system owners, and lead the documentation, authorization, and ongoing assessment of information systems. May require CONUS and/or OCONUS travel to customer sites.

Responsibilities:

  • Serve as the ISSO in support of the ISO for assigned systems, ensuring full compliance with RMF, DoDI 8510.01, and NIST SP 800-53 security control baselines.
  • Manage and maintain all RMF-related documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and Plan of Action and Milestones (POA&Ms).
  • Conduct security control assessments and facilitate ongoing authorization (ATO/ATC) activities.
  • Work directly with system owners, administrators, and the Government cybersecurity team to ensure all security controls are properly implemented and documented.
  • Coordinate and support all phases of the RMF lifecycle from categorization to continuous monitoring.
  • Lead vulnerability and compliance assessments using automated tools (e.g., ACAS, STIG Viewer) and ensure all findings are remediated or tracked via POA&Ms.
  • Participate in Configuration Control Boards (CCBs) and validate that system changes do not negatively impact security controls or the authorization boundary.
  • Track and report on system compliance metrics, ensuring timely updates to APMS and eMASS and supporting audit readiness activities.
  • Develop and deliver security awareness training, user role validation, and account recertification in accordance with policy.
  • Act as liaison with Authorizing Officials (AOs), Control Assessors (CAs), and NETCOM to facilitate ATO packages and compliance reviews.
  • Monitor and analyze security events from SIEM platforms, firewalls, IDS/IPS, and EDR tools to detect threats and abnormal activity.
  • Support incident response activities and coordinate with local defender to assess impact, containment, and recovery actions.
  • Document all security incidents in alignment with incident handling procedures and provide after-action reports for leadership.
  • Ensure that incident findings are mapped back to RMF controls, and that system documentation is updated accordingly.
  • Monitor Cyber Tasking Orders (CTOs), security bulletins, CVEs, and threat intelligence feeds for relevance to the operational environment.
  • Analyze potential threat vectors and adversary TTPs using frameworks such as MITRE ATT&CK and translate findings into actionable security enhancements.
  • Collaborate with stakeholders to recommend technical and policy-based countermeasures aligned with organizational risk tolerance and mission impact.
  • Prepare detailed risk assessment reports, compliance dashboards, and security briefings for senior leadership and stakeholders.
  • Submit timely updates and artifacts to eMASS and participate in regular cybersecurity status meetings.
  • Provide clear, data-driven recommendations for improving system security postures and addressing identified risks.
  • Coordinate with mission owners and developers to implement security in system development lifecycles (SDLC).
  • Maintain awareness and proper configuration of continuous monitoring tools including SIEMs, vulnerability scanners, and audit logging tools.
  • Ensure tools and scripts used for compliance monitoring (e.g., RMF assessments, ACAS scans) are operating effectively and producing accurate outputs.
  • Collaborate with system administrators to remediate security findings and improve hardening based on STIGs and best practices.

Required Experience

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Assurance, or a related field (or equivalent experience). Minimum of 3 related certifications may be used in place of related academic field.
  • Minimum of 10 plus years of work related experience.
  • Minimum 2+ years of direct ISSO or cybersecurity compliance experience, preferably within a DoD or Federal environment.
  • DoD 8570 baseline certification.
  • Active DoD Secret Security Clearance with the ability to obtain Top Secret Security; US Citizenship required 
  • Strong working knowledge of RMF, NIST SP 800-53, DoDI 8510.01, DoDI 8500.01, CNSSI 1253, and associated security control families.
  • Familiarity with vulnerability management tools such as ACAS, STIG Viewer, and SCAP Compliance Checker.
  • Familiarity with (DRAGOS, Corelight, Splunk, Snort).
  • Experience managing cybersecurity artifacts within eMASS or other compliance platforms.
  • Understanding of NETCOM directives and cybersecurity service provider (CSSP) coordination. 

Preferred Qualifications:

  • Experience supporting Authority to Operate (ATO) processes, both initial and continuous monitoring.
  • Strong analytical skills for evaluating control effectiveness, incident impact, and system vulnerabilities.
  • Proficiency in security documentation, audit preparation, and stakeholder communication.
  • Familiarity with scripting (e.g., PowerShell, Python) for automating compliance checks or log analysis.
  • Demonstrated ability to balance RMF compliance with operational mission support. 
  • Previous experience with Dragos OT Sensor Equipment Preferred.
  • Certifications: CompTIA Security+, CISSP, or equivalent DoD 8570 IAT Level II/III certification; CAP (Certified Authorization Professional); CISM; GSNA, or RMF-focused GIAC certifications.

Job Tags

Local area,

Similar Jobs

Veolia Water Technologies & Solutions

Intern - Process Improvement Job at Veolia Water Technologies & Solutions

 ...for talented, passionate individuals to join the sector. This internship offers students the opportunity to gain hands-on experience in...  ...generations. Job Description The Summer 2026 Process Improvement Intern role at Veolia is designed for students seeking practical... 

Edikted

Senior Fashion Designer Job at Edikted

 ...Job Description We are seeking a highly experienced and visionary Senior Fashion Designer to join our team and play a pivotal role in shaping the creative direction of our fast-growing Gen-Z fashion brand. The Senior Designer is responsible for developing 4560 innovative... 

TechForcePros

Greenhouse ATS Analyst - Remote Job at TechForcePros

 ...TechForcePros is committed to driving business success through innovative solutions and exceptional client service. Job Title: Greenhouse ATS Analyst Location: Remote Employment Type: Long-Term Contract Experience Level: Senior (Minimum 5 Years)... 

Airbus Helicopters, Inc.

Senior Aircraft Technician - MAR Sheet Metal (Contract) Job at Airbus Helicopters, Inc.

 ...for an experienced helicopter sheetmetal mechanic to join our Maintenance & Repair (MAR)...  ...Perform repair/maintenance work on assigned aircraft to include any mechanical, sheet metal...  ...:*RequiredNonePreferredNone*Experience:*RequiredMinimum of six (6) years related... 

WEX

Sr. Product Manager, Guardrails and Growth Systems (Washington) Job at WEX

 .... Change Management: Guide teams through the rollout of new tools and processes, driving adoption through clear communication, training, and support. Measure Success: Define KPIs and metrics upfront, tracking performance to demonstrate business impact and ROI....