Information Security Analyst Senior
Listed on 2026-08-28
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Information Security Analyst SeniorFull Time Professional Colorado Springs, CO, US
2 days ago Requisition
INFORMATION SECURITY ANALYST SENIORJob Title: Information Security Analyst Senior
Company: Sugpiat Defense, LLC
Program: Missile Defense Agency (MDA)
Location: Colorado Springs, CO – On-Site
Employment Status: Regular, Full-Time
FLSA Status: Exempt
Security Clearance: Active Top Secret with SCI Eligibility Required
Position Status: Contingent upon Contract Award
The Information Security Analyst Senior is responsible for providing senior-level information assurance, cybersecurity, and risk management support to the Missile Defense Agency (MDA). This position supports the protection and secure operation of classified and unclassified mission-critical information systems through the implementation and maintenance of Department of Defense (DoD) cybersecurity requirements, Risk Management Framework (RMF) activities, continuous monitoring, vulnerability management, security control assessments, and Assessment and Authorization (A&A) activities.
The Information Security Analyst Senior works closely with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), engineers, system administrators, Authorizing Officials, Government personnel, and other program stakeholders to maintain system security posture and compliance. The position provides technical cybersecurity guidance throughout the system lifecycle, identifies and communicates cybersecurity risks, supports incident response and corrective actions, and provides technical leadership and mentorship to junior cybersecurity personnel.
ESSENTIAL JOB FUNCTIONS:- Support the implementation and maintenance of cybersecurity requirements across classified and unclassified information systems.
- Maintain system compliance with the DoD Risk Management Framework (RMF), National Institute of Standards and Technology (NIST) guidance, MDA requirements, and applicable DoD cybersecurity policies.
- Support Assessment and Authorization (A&A) activities necessary to obtain and maintain system Authority to Operate (ATO).
- Develop, review, update, and maintain RMF documentation and supporting cybersecurity artifacts, including:
- System Security Plans (SSPs)
- Security Assessment Reports (SARs)
- Plans of Action and Milestones (POA&Ms)
- Security control documentation
- Supporting authorization and compliance artifacts
- Conduct continuous monitoring activities, including vulnerability management, configuration compliance, security control assessments, and ongoing evaluation of system security posture.
- Analyze vulnerability scan results, assess findings, track identified vulnerabilities, and coordinate remediation efforts with system administrators, engineers, and program leadership.
- Support the implementation, review, and validation of Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs).
- Support Security Content Automation Protocol (SCAP) compliance activities.
- Support security audits, inspections, assessments, and cybersecurity compliance reviews.
- Monitor cybersecurity posture and identify vulnerabilities, compliance deficiencies, and risks that may affect mission systems.
- Investigate cybersecurity incidents and support incident response, documentation, reporting, remediation, and corrective actions in accordance with established requirements.
- Review proposed system changes, configurations, and technical modifications to identify cybersecurity impacts and recommend appropriate security controls.
- Ensure cybersecurity activities comply with applicable DoD, MDA, NIST, and federal cybersecurity requirements.
- Coordinate cybersecurity activities with ISSMs, ISSOs, Authorizing Officials, engineers, system administrators, Government personnel, and other program stakeholders.
- Provide cybersecurity guidance to engineering, technical, and operational teams throughout the system lifecycle.
- Participate in cybersecurity working groups, technical reviews, program meetings, and other…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).