Type of Requisition:
RegularClearance Level Must Currently Possess:
NoneClearance Level Must Be Able to Obtain:
NonePublic Trust/Other Required:
NACI (T1)Job Family:
Cyber and IT Risk ManagementJob Qualifications:
Skills:
Continuous Improvement, Cybersecurity Risk Assessment, Cybersecurity Strategies, Information SystemsCertifications:
NoneExperience:
4 + years of related experienceUS Citizenship Required:
YesJob Description:
GDIT has an opportunity for a Cybersecurity Analyst to support the modernization and sustainment of a large portfolio of enterprise business solutions used by the National Aeronautics and Space Administration (NASA). The position supports the NASA Consolidated Applications and Platform Services Program (NCAPS). NCAPS consolidates enterprise-wide applications and platform services across the Agency and supports the Office of the Chief Information Officer (OCIO) Application Division transformation into the Application and Platform Service (APS) Line with agile based service delivery and IT Infrastructure Library (ITIL) based service management practices. This is a remote position.
Responsibilities:
Apply expert knowledge of concepts, processes, practices, and procedures on technical assignments.
Support enterprise Cybersecurity standards.
In coordination with Government develop and implement Cybersecurity standards and procedures.
Coordinate, develop, and recommend security processes for an organization.
Recommend Cybersecurity solutions to support customers’ requirements.
Identify and report security violations.
Recommend and satisfy Cybersecurity requirements based upon the analysis of CSPP, policy, regulatory, and resource demands.
Support customers at the highest levels in the development and implementation of processes and policies.
Apply know-how to government and commercial common user systems, as well as to dedicated special purpose systems requiring specialized security features and procedures.
Supports design and development of security features for system architecture requirements.
Analyze and make recommendations of security requirements for computer systems which may include mainframes, workstations, and personal computers.
Support design, development, engineering, and implementation of solutions that meet CSPP requirements.
Provide integration and implementation of the computer system security solution.
Analyze general Cybersecurity-related technical problems and provide basic engineering and technical support in solving these problems.
Supports vulnerability/risk analyses of computer systems and applications during all phases of the system development life cycle.
Perform all procedures necessary to ensure the safety of information systems data assets and to protect systems from intentional or inadvertent access, theft, or destruction.
Ensure that all information systems are functional and secure.
Provide subject matter expertise, direction, guidance, tracking, and support on cyber security, risk management, continuous monitoring, security Assessment and Authorization (A&A), and business processes that support a metric-driven environment.
Develop, maintain, and update Plans of Action and Milestones (POA&M) to identify system weaknesses, mitigation, and timelines for applying corrective actions.
Qualifications:
Required:
4 or more years of applicable experience in Cybersecurity and Cloud Security experience at a large Government agency
Bachelor’s degree in computer science, electronics engineering, or other engineering or technical discipline.
Demonstrated knowledge of NIST Information Technology Security Special Publications (SP) 800 series
Demonstrated experience with Assured Compliance Assessment Solution (ACAS)/Tenable Nessus Vulnerability Scanner
Demonstrated experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage
Demonstrated familiarity and experience with Firewalls, Intrusion Prevention Systems, WebGateways, and/or enterprise Antivirus software technologies
Demonstrated knowledge of CSPP requirements.
Working knowledge of Federal Information Security Management Act (FISMA) reporting requirements and processes
Proven ability in planning, implementing, upgrading, and monitoring security measures to protect computer networks and information.
Ability to apply advanced principles, theories, and concepts, and contribute to the development of innovative IA principles and ideas
Working knowledge of Agile Scrum Methodology
Must be able to obtain and maintain a NASA Public Trust background investigation.
Desired:
Experience supporting the NASA Web Services Operational Environment
Familiar with domain structures, user authentication, and digital signatures
Understanding of firewall theory and configuration
Excellent written and verbal communication skills
- One or more of the following: certifications: CISSP, CISA, CISM, CRISC
Scheduled Weekly Hours:
40Travel Required:
Less than 10%Telecommuting Options:
RemoteWork Location:
Any Location / RemoteAdditional Work Locations:
