Info. Security Analyst Principal
Listed on 2026-09-01
-
IT/Tech
Cybersecurity
Job Details
Type of
Requisition :
Regular. Clearance Level Currently Possess:
Secret. Clearance Level Must Be Able to Obtain:
Top Secret/SCI. Public Trust/Other
Required:
None. Job Family:
Cyber and IT Risk Management.
Job Qualifications:
Skills:
ACAS, DISA STIG, RMF, Splunk (Inactive).
Certifications:
None.
Experience:
10+ years of related experience. US Citizenship
Required:
Yes.
- Perform cybersecurity activities for a large program, coordinating with government program staff, USAF, and other agencies to assist in creation, dissemination, direction, and auditing of program policy, standards, and operating procedures.
- Utilize available resources to conduct cybersecurity activities and report to senior GDIT and government personnel on overall program security posture.
- Conduct network and system audits for vulnerabilities using Security Technical Implementation Guides (STIGs), DISA SCAP, ACAS vulnerability scanner, ESS Policy Auditor to mitigate findings for Linux, Windows, Cisco, Juniper, VMWare and other associated operating systems.
- Create, track, and review Plan of Action and Milestones (POA&Ms) and conduct solution identification to assist in problem remediation and resolution.
- Communicate tactical and strategic threat information to Government leaders, Cybersecurity-Ops, and A&A staff to assist them in making cyber risk decisions and mitigating threats.
- Carry out DoW Risk Management Framework (RMF) in accordance with DoW 8510 to ascertain information systems' security posture by utilizing security control validation activities and coordinating security testing.
- Maintain the Security Accreditation status, including system documentation of multiple DoW classified networks and interconnected systems.
- Coordinate with AFRL, USAF, and other organizations in support of audits and inspections and provide all necessary documentation as required for SAVs, STEs, and CCRI.
- Evaluate firewall change requests and assess organizational risk.
- Provide guidance on vulnerability countermeasures or mitigation of non‑compliant controls.
- Ensure the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
- Perform periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, and file system to determine compliance.
- Provide guidance and work leadership to less‑experienced technical staff members.
- Maintain current knowledge of relevant technology as assigned.
- Participate in special projects as required.
- 10+ years of experience required (8+ years preferred).
- Must possess and maintain a Secret clearance.
- BA/BS degree – may substitute additional years of experience.
- Comprehensive knowledge of data security administration principles, methods, and techniques.
- Must meet DOW 8570.01M requirements for IAT Level II (e.g., CASP CE).
- Requires understanding of DOW RMF (800‑53 Rev 4 and Rev
5). - Requires understanding of DoW policies and procedures, including FIPS 199, FIPS 200, NIST 800‑53 and other applicable policies.
- Ability to acquire and maintain a TS/SCI clearance.
- The ability to work and set priorities on multiple projects/tasks at once and operate in a dynamic, fast‑paced team‑oriented environment.
- Depending on job assignment, additional specific certifications may be required.
Likely salary range: $108,800 - $147,200 (subject to experience, geographic location and contractual requirements).
Location and ScheduleWork Location:
USA, VA – Langley AFB. Additional Work Locations: as required. Scheduled Weekly
Hours:
40.
Travel Required:
None. Telecommuting Options:
Onsite. Work Environment:
Office.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Opportunity Owned.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).