Cybersecurity Risk Assessment Analyst

2 weeks ago


Ashburn, Virginia, United States Leidos Full time

Job Overview
The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a vital US Government initiative dedicated to safeguarding CBP networks from cyber threats. This role involves monitoring, detecting intrusions, and providing protective security services for CBP information systems, which encompass local area networks/wide area networks (LAN/WAN), commercial Internet connections, public-facing websites, wireless and mobile systems, cloud environments, security devices, servers, and workstations.

Key Responsibilities
- Conduct comprehensive risk assessments of CBP systems, including data collection, research, and coordination.
- Analyze the applicability and implementation status of controls for enterprise risk assessments.
- Integrate the NIST Cybersecurity Framework (CSF) into NIST controls analysis.
- Evaluate the effectiveness of Plan of Actions and Milestones (POA&M) management during risk assessments.
- Analyze MITRE Tactics and Techniques relevant to CBP's Cyber Threat Intelligence (CTI) Threat Actors and other potential threats.
- Prioritize system assets based on their impact levels.
- Identify response activities, including contingency planning, data backups, and alternate processing sites.
- Recommend strategies to mitigate identified risks.
- Apply knowledge of the Risk Management Framework (RMF) and the System Development Life Cycle (SDLC) in daily operations.
- Review and analyze Security System Plans (SSPs), Risk Assessment Reports, and other security-related documentation.
- Formulate compliance requirements for security systems.
- Identify security concerns during the review of security documents.
- Utilize CBP's intelligence and security tools to gather data for risk assessments, including Axonius, CrowdStrike, Swimlane, CSAM, Splunk, Active Risk Manager (ARM), Digital Guardian, and Recorded Future.

Support Responsibilities
- Assist the Cybersecurity Acquisition Risk Management (C-CARM) team in establishing a robust security infrastructure by identifying, assessing, and documenting cybersecurity threats and risks throughout the acquisition lifecycle.
- Monitor the Body of Evidence (BoE) for each Acquisition Decision Event (ADE) and communicate concerns to facilitate program success.
- Organize and secure program BoE through effective management of communication channels.
- Facilitate communication between programs and cybersecurity risk assessment teams.
- Guide programs on the methodology and sequence for consistent Threat Assessments.
- Ensure that the C-CARM Standard Operating Procedures (SOP) are current and aligned with existing processes.
- Prepare various presentation briefs for government stakeholders.

Qualifications
- All CBP SOC employees must successfully complete a 5-year Background Investigation.
- A Bachelor's degree in Computer Science, Engineering, Information Technology, Cyber Security, or a related field, along with 4 to 8 years of relevant experience. Additional experience and cybersecurity certifications may substitute for a degree.
- Familiarity with the management, operational, and technical aspects of IT Security in a complex enterprise environment.

Preferred Qualifications
- Experience in reviewing results from operating system, application, and database scans.
- Proficiency in vulnerability assessment, analysis, and management.

Preferred Certifications
- CAP, CISM, CISSP, CISA, CASP, CEH, GCED, CRISC, Security +.

Compensation
The pay range for this position is between $81,000 and $146,875. This range serves as a general guideline and is not a guarantee of compensation. Factors considered in extending an offer include job responsibilities, education, experience, skills, and internal equity.



  • Ashburn, Virginia, United States AgileTek Solution LLC Full time

    Essential Job Responsibilities: This position functions as a hands-on mid-level cybersecurity analyst tasked with collaborating with security engineering, operational, and development teams. The analyst will contribute to the creation and upkeep of various Plans of Action and Milestones (POAMs), assist in drafting System Security Plans (SSP), and manage...


  • Ashburn, Virginia, United States AgileTek Solution LLC Full time

    Essential Job Responsibilities: This position is designed for a proactive mid-level cybersecurity analyst who will engage with security engineering, operational teams, and development units. The analyst will play a crucial role in the creation and upkeep of various Plans of Action and Milestones (POAMs), contribute to System Security Plans (SSP), and manage...


  • Ashburn, Virginia, United States Leidos Full time

    Position Overview:Leidos is seeking a Cybersecurity Threat Analyst to enhance our Network Operations Security Center (NOSC) Cyber Team. The ideal candidate is analytical, inquisitive, and adept at recognizing subtle patterns and irregularities in data.About the Role:The Department of Homeland Security (DHS) operates the NOSC Cyber program, dedicated to...


  • Ashburn, Virginia, United States AgileTek Solution LLC Full time

    Essential Job Responsibilities: This position functions as a hands-on mid-level cybersecurity analyst tasked with collaborating with security engineering, operational, and development teams. The analyst will contribute to the creation and upkeep of various Plans of Action and Milestones (POAMs), provide input for System Security Plans (SSP), and maintain...


  • Ashburn, Virginia, United States AgileTek Solution LLC Full time

    Essential Job Qualifications: This position is designed for a proactive intermediate-level cybersecurity analyst who will engage with security engineering, operational, and development teams. The primary responsibilities include assisting in the formulation and upkeep of various Plans of Action and Milestones (POAMs), contributing to System Security Plans...


  • Ashburn, Virginia, United States Leidos Full time

    Are you ready to contribute to a mission-driven organization? At Leidos, we are committed to delivering cutting-edge solutions through the expertise of our diverse workforce, dedicated to achieving success for our clients. We empower our teams, engage with our communities, and prioritize sustainability. Our operations are grounded in a steadfast commitment...


  • Ashburn, Virginia, United States Visa Full time

    About the RoleVisa is a leading global payments technology company, and we're seeking a highly skilled Director of Cybersecurity Operations to join our team. As a key member of our cybersecurity team, you will be responsible for leading a team of incident responders at one of our Cyber Fusion Centers located in Ashburn, VA.Key ResponsibilitiesCoordinate and...


  • Ashburn, Virginia, United States Apex Systems Full time

    Position OverviewApex Systems is seeking a dedicated Cybersecurity Systems Specialist to join our dynamic team. This role is integral to safeguarding our information systems and ensuring the integrity of our networks against cyber threats.Key Responsibilities:Support the complete system engineering lifecycle, encompassing requirements analysis, design,...


  • Ashburn, Virginia, United States Leidos Full time

    Leidos is on the lookout for a skilled Cybersecurity Content Specialist to enhance our team focused on threat detection within a prominent cyber security initiative. Your primary responsibilities will include: Proactively identifying potential threats and inspecting network traffic for irregularities and emerging malware patterns. Conducting thorough...


  • Ashburn, Virginia, United States Leidos Full time

    Job SummaryLeidos is seeking an experienced Cybersecurity Operations Center Deputy Team Lead to join our team. As a leader of this highly visible cyber Security Operations Center (SOC) for U.S. Customs and Border Protection (CBP), you will be responsible for managing day-to-day operations of the team, coordinating efforts of the team, leading by example and...


  • Ashburn, Virginia, United States Leidos Full time

    The U.S. Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is dedicated to safeguarding the integrity of its networks. This government initiative is tasked with the prevention, identification, containment, and eradication of cyber threats to CBP's information systems through vigilant monitoring,...

  • Cyber Threat Analyst

    2 weeks ago


    Ashburn, Virginia, United States Leidos Full time

    Position OverviewLeidos is on the lookout for a Cyber Threat Analyst to enhance our Cybersecurity Team. The successful candidate will be analytical, inquisitive, and skilled at recognizing subtle patterns and irregularities in data.Develop Threat Models to gain insights into the organization, pinpoint security weaknesses, and prioritize remediation...


  • Ashburn, Virginia, United States Leidos Full time

    OverviewLeidos is looking for a Cybersecurity Strategy Consultant to become an integral part of our dynamic cyber defense team. In this pivotal role, you will focus on thwarting, detecting, and eliminating cyber threats to our systems. Your primary responsibility will be to devise and articulate strategies that ensure our organization remains a leader in the...


  • Ashburn, Virginia, United States Visa Full time

    About the RoleWe are seeking a highly experienced and skilled Director of Cybersecurity Operations to lead our incident response team at one of our Cyber Fusion Centers located in Ashburn, VA. As a key member of our cybersecurity organization, you will be responsible for coordinating and overseeing incident response activities, providing leadership to...


  • Ashburn, Virginia, United States Visa Full time

    Company OverviewAs a global leader in digital payment solutions, Visa is dedicated to connecting the world through innovative, secure, and reliable payment networks. Our advanced processing infrastructure, VisaNet, facilitates secure transactions globally, handling an impressive volume of transaction messages every second. Our commitment to innovation is at...

  • Cybersecurity Engineer

    16 hours ago


    Ashburn, Virginia, United States Leidos Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Engineer to join our team at Leidos. As a key member of our Security Operations Center (SOC), you will play a critical role in protecting our clients' networks and systems from cyber threats.Key ResponsibilitiesSupport the full system engineering life-cycle, including requirements analysis, design,...


  • Ashburn, Virginia, United States Leidos Full time

    Position Overview:We are seeking a proficient cybersecurity content specialist to enhance our capabilities at Leidos. This role focuses on the proactive identification of threats, scrutinizing network traffic for irregularities and emerging malware signatures, along with log analysis. You will be responsible for crafting tailored content within the Splunk...


  • Ashburn, Virginia, United States Leidos Full time

    Position Overview:We are seeking a proficient Cybersecurity Content Engineer to enhance our operations at Leidos. This role is centered around the proactive identification of threats, scrutinizing network traffic for irregularities and emerging malware signatures, as well as conducting log analysis. You will be responsible for crafting tailored content...


  • Ashburn, Virginia, United States Leidos Full time

    Position Overview:We are seeking a proficient Cybersecurity Content Specialist to enhance our capabilities at Leidos. This role focuses on the proactive identification of threats, scrutinizing network traffic for irregularities and emerging malware signatures, as well as conducting log analysis. You will be responsible for crafting tailored content within...


  • Ashburn, Virginia, United States 00100 LEIDOS, INC. Full time

    Job SummaryLeidos is seeking a highly skilled Cyber Threat Hunter to join our NOSC Cyber Team. As a Cyber Threat Hunter, you will play a critical role in identifying and mitigating cyber threats to the Department of Homeland Security (DHS) networks.Key ResponsibilitiesCreate and maintain threat models to identify defensive gaps and prioritize mitigations in...