Information Security Analyst

3 weeks ago


Hanover Maryland, United States Allegis Group Full time
Overview:
Job Summary: 

 

The Information Security Analyst, for Threat & Vulnerability, will provide service and operational support to all ACS Information Security Office service offerings and capabilities.  The InfoSec Analyst will support project work upon request.

 

The Threat & Vulnerability Analyst will be responsible for consuming threat intelligence from internal and external sources and converting intelligence into actionable use cases and detection methodologies. The Threat & Vulnerability Analyst reviews security events and conducts additional analytics to determine if an event requires additional incident response actions by Allegis Group InfoSec or other departments.

Responsibilities:
Essential Functions:

Correlate threat data from various sources. Conduct research and evaluate threat intelligence to develop in-depth analysis and assessment on threats to critical networks and infrastructure components.

Conduct cyber intelligence analysis, coordination, and interaction across networks and infrastructure components.

Support the identification and impact classification for new vulnerabilities identified in the environment.

Execute and support vulnerability assessments, penetration testing and social engineering activities.

Support the implementation, adoption, configuration, and maintenance of T&V tools.

Conduct analysis and aggregation of vulnerability data from various Allegis Group and external sources

Conduct periodic reviews of SOC security event activities to identify trends for potential efficiency and potential gaps with services.

Provide InfoSec Leadership team information on the emerging cyber threat landscape, including threat actor tactics, techniques, and procedures.

Incident and Problem management system support working with Security Operations Centers and SIEMS

Develop and maintain analytical procedures to improve security incident identification and response efficiency.

Support InfoSec leadership and architecture teams to identify capability gaps in vulnerability management services and tools.

Interact with entities across OPCOs to understand information criticality and use cases for detection of threats targeting such data.

Develop strong working relationships with counterparts within Information Services (IS).

Conduct incident response actions from security incidents as directed by leadership team, including during off-hours as needed.

Create and maintain T&V metrics data.

Continue self-development of knowledge, skills, and abilities to better support execution of the InfoSec analyst function.

Qualifications:
Minimum Education and/or Experience:

Bachelor's degree in the field of MIS, Cybersecurity, computer science, information systems or computer engineering or equivalent experience.

3 to 5 years of experience with identifying, analyzing, and communicating cyber threat and vulnerability information.

Experience applying threat and vulnerability analyses models, examples include the Lockheed Martin (LM) Cyber Kill Chain, the Diamond Model of Intrusion Analysis, the Mitre ATT&CK Framework, and the Common Vulnerability Scoring System (CVSS).

Understanding of Agile and ITIL methodologies

Ideal candidates will hold one or more of the following certifications:

CISSP, NET+, SEC+, SANS GIAC (GISF, GSEC or other)

Skills and Abilities:

Ability to conduct detailed security event analysis from network traffic attributes and host-based attributes (memory analysis, binary analysis, etc.)

Ability to operate effectively with minimal supervision.

Ability to prioritize activities to support program execution.

Familiarity with malware reverse engineering concepts

Rapid7/InsightVM security scanning and management tools

Familiarity of Data Loss Prevention and threat detections systems

Basic understanding of Federal/International regulations related to information security (GDPR, ISO, NIST, SSAE, HIPAA, FISMA etc.)

Ability to support the development and enhancement of security policies, standards, and processes.

Working knowledge of information services capabilities including network, system, database, encryption & identity technologies

Excellent verbal and written communication skills.

Demonstrated ability to think strategically and perform detailed analysis, and data interpretation.

Effective interpersonal skills, the ability to build consensus, and interface with all levels of staff.

Ability to work under pressure and deal with ambiguous situations.

Core Competencies:

Build relationships

Develop people

Lead change

Inspire Others

Think critically

Communicate clearly

Create accountability



  • Maryland, United States Technology Security Associates Full time

    JHNA Technology Security is seeking a Cyber Security Analyst to serve as an Information System Security Engineer (ISSE) for the support of tasking that involves the analysis of the posture of systems in support of system certification and accreditation. Duties/Responsibilities: A junior level person is responsible for assisting more senior positions and/or...


  • Maryland, United States American Systems Full time

    Job Title / Level Information Security Analyst, Senior - Top Secret Clearance Clearance Required? Top Secret Location: Patuxent River, MD 20670 US (Primary) % Travel 0 - 10% Job Description We are looking for an Information Security Analyst with demonstrated experience planning, documenting, implementing, upgrading, and monitoring security measures for the...


  • Hanover, United States Elevance Health Full time

    Job Family: IFT > IT Security & Compliance Type: Full time Date Posted: May 11, 2024 Anticipated End Date: Jul 29, 2024 Reference: JR117082 Description **Security Analyst III** A proud member of the Elevance Health family of companies, Carelon Behavioral Health, formerly Beacon Health Options, offers superior clinical mental health and substance use...


  • Maryland, United States InDyne Full time

    InDyne is a full-service military, civilian and commercial operations company. Our Mission is to provide tailored cost effective, quality services and solutions. Our Vision is to exceed customer expectations by delivering results through agility, flexibility and responsiveness. Our Core Values include integrity, trust and loyalty. RT&T, a joint venture of...

  • Cyber Threat Analyst

    4 weeks ago


    Hanover, Maryland, United States A.C. Coy Full time

    Overview: Cyber Threat Analyst long-term contract; Morrisville, NC (hybrid) SUMMARY: • Tier One Technologies is looking for a Cyber Threat Analyst to work with our direct US Government client supporting its Detection Automation and Engineering Unit located in Morrisville, NC. • SELECTED CANDIDATES WITHOUT REQUIRED CLEARANCE WILL BE SUBJECT TO A FEDERAL...


  • Maryland Heights, United States Brooksource Full time

    *Security Analyst/Engineer**On-going Contract**St. Louis - HYBRID - Must be in St. Louis or willing to relocate*Brooksource's Fortune 500 telecommunication client is looking for an information Security Analyst/Engineer. This Security Analyst/Engineer that will participate in a vulnerability management project regarding network specific devices. The role will...


  • Hanover, United States Farfield Systems Full time

    Job DescriptionJob DescriptionAbout Farfield Systems, IncAt Farfield we are committed to delivering trusted expertise to our government clients.  As we grow, our focus is on increasing opportunities for you to grow with us while still delivering the same excellence customers have grown to expect from us. We continually evaluate our environment to provide a...


  • Hanover, United States Lockheed Martin Full time

    **Job ID**: 660871BR **Date posted**: Feb. 05, 2024 Overall, the ISSO is responsible for the oversight of the information system's security posture and will develop/revise the necessary RMF documentation to support the authorization of the individual systems. Standard RMF artifacts include the System Security Plan (SSP), Plan of Action and Milestones...


  • Maryland, United States Columbia Technology Partners Full time

    Description: The Information Systems Security Engineer shall perform or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations andrecommend mitigation strategies. Validates and verifies system security requirements definitions...


  • Maryland, United States Athenix Solutions Group Full time

    Athenix Cyber & SIGINT is seeking a Senior Information Systems Security Engineer to support a large program in the Annapolis Junction, MD area. Participate as a security engineering representative on engineering teams for the design, development, implementation and/or integration of secure networking, computing, and enclave environments Participate as a...


  • Hanover, United States Jacobs Engineering Group Inc Full time

    Job Description Principle Information Systems Security Officer - ( CYB0000FQ ) **Job Description (** *describe the day-to-day* **):** Jacobs is currently seeking an Information System Security Office (ISSO). Duties will include: Must be willing to travel to Virginia 1 day a week **Essential Functions (** *Enter essential functions that are not listed below...


  • Hanover, United States Kaizen Approach Full time

    Are you mission-focused and ready to be with a company that truly values your contributions? We are currently looking to hire Information Systems Security Engineer (ISSE) to support one of our mission-critical programs. To succeed in this role, you must exhibit an innovative, meticulous, team-oriented mindset. Generally, ISSEs are responsible for providing...


  • Hanover, United States Kaizen Approach Full time

    Are you mission-focused and ready to be with a company that truly values your contributions? We are currently looking to hire Information Systems Security Engineer (ISSE) to support one of our mission-critical programs. To succeed in this role, you must exhibit an innovative, meticulous, team-oriented mindset. Generally, ISSEs are responsible for providing...


  • Maryland, United States CareerBuilder Full time

    Velos is a full-service engineering and technical services and government relations consulting firm representing leaders in the defense, aerospace, intelligence, and related industries. As an SBA-certified HUBZone company, Velos incorporates technical prowess into the execution of corporate strategies and business development experience, providing clients...


  • Hanover, United States ASRC Federal Holding Company Full time

    Job Description ASRC Federal Broadleaf Division is hiring for an Information Systems Security Engineer II to support the DCSA in Hanover, MD. JOB DESCRIPTION:As a Information Systems Security Engineer II you will lead efforts to manage the Security Technical Implementation Guide (STIG) progress within the PEO program. You will work closely with program...


  • Hanover, United States ASRC Federal Holding Company Full time

    Job Description ASRC Federal Broadleaf Division is hiring for an Information Systems Security Engineer II to support the DCSA in Hanover, MD. JOB DESCRIPTION:As a Information Systems Security Engineer II you will lead efforts to manage the Security Technical Implementation Guide (STIG) progress within the PEO program. You will work closely with program...


  • Bethesda, Maryland, United States Hummingbirds Innovations Full time

    • Provide information assurance support to system(s) and program • Demonstrated experience with coordinating and implementing cyber security policies, standards and processes • Maintain operational security posture for system(s) through customized Risk Management Framework (RMF) to ensure established security processes and procedures are...


  • Maryland, United States Birchmere Group Full time

    ***This position requires a TS/SCI Clearance with a Polygraph*** Information System Security Manager (ISSM) Level 3 Provide management support for a program, organization, system, or enclave’s Information Assurance program. Provide management support for proposing, coordinating, implementing, and enforcing Information System Security policies, standards,...


  • Maryland, United States Birchmere Group Full time

    ***You MUST already have a TS/SCI Clearance with a Polygraph to qualify*** Information Systems Security Engineer Level 2 The Information Systems Security Engineer (ISSE) shall perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Cybersecurity standards and...


  • Patuxent River Estates, Maryland, United States Resource Management Concepts, Inc. Full time

    Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America. RMC is hiring an Information Security Analyst for the...