Cyber Security Analyst
Salary Statement
Estimated Starting Salary Range: USD $87,000.00/Yr. - USD $144,900.00/Yr. Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data.Description
Scientific Research Corporation (SRC) is an advanced information technology engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients. SRC is searching for a highly skilled and experienced Cybersecurity Analyst to manage and respond to cyber threats, focusing on processing Cyber Tasking Orders (CTOs), analyzing Security Operations Center (SOC) alerts, and conducting comprehensive threat intelligence activities. The ideal candidate will have at least 3 years of combined cybersecurity experience, including 2+ years in a SOC or Cyber Security Analyst role within SIPRNET or NIPRNET environments, and 2+ years in Windows and/or Linux system administration, along with an active DoD 8140 Workforce Certification. Key responsibilities include evaluating vulnerabilities, developing mitigation strategies, tracking zero-day threats, and preparing detailed threat intelligence reports and briefings for various stakeholders. Duties & Responsibilities include:
- Processing, coordinating, tracking, analyzing, documenting, and reporting Cyber Tasking Orders (CTOs) and high interest items
- Assessing, analyzing, and remediating Security Onion Console (SOC) alerts or other SIEMs
- Evaluating security vulnerabilities, developing mitigation strategies, implementing remediation activities, and creating Plans of Action and Milestones (POA&Ms)
- Administering systems in Windows 11, Windows Server 2019, 2022, or 2025, or Red Hat Enterprise Linux (RHEL) 8x or 9x
- Monitoring, collecting, and analyzing cyber threat intelligence from internal and external sources, including vendors and open-source intelligence
- Researching cyber threat actors, threat groups, campaigns, malware, vulnerabilities, fraud trends, and geopolitical events that may impact the organization or its clients
- Identifying emerging threats, assessing potential mission impact, and providing actionable recommendations to reduce risk
- Tracking zero-day vulnerabilities and high-risk CVEs, including preparing reports with potential impact, mitigation steps, and remediation guidance
- Developing and publishing tactical, operational, and strategic threat intelligence reports for cybersecurity teams, stakeholders, and executive leadership
- Consolidating and evaluating cyber threat intelligence feeds to improve the quality, relevance, and timeliness of threat assessments
- Analyzing internal security risks and threat exposure to identify potential weaknesses
- Responding to customer or stakeholder requests for information related to cyber threats, vulnerabilities, and risk trends
- Preparing briefings and executive summaries that communicate cyber risks in clear, non-technical language
- Developing and maintaining documentation, procedures, and playbooks related to threat intelligence and response processes
- Ensuring that security design and distribution actions are evaluated, validated, and implemented as required
- Ensuring that cybersecurity requirements are integrated into the architecture for the system or organization
- Evaluating development efforts to ensure that baseline security safeguards are planned for and appropriately installed
- Identifying alternative security strategies to address organizational security objectives of cyber taskings
- Assessing DoW security requirements and DISA Security Technical Implementation Guides (STIGs)
- Coordinating with other system SMEs to identify and develop authorization boundary diagrams, architecture diagrams, and hardware and software inventories
#LI-LH1
Requirements
- Three or more years of combined cybersecurity experience holding one or more of the following roles: ISSO, Cyber Security Analyst, and/or Systems/Network Administrator
- Two or more years of experience working Security Operations Center (SOC)/Cyber Security Analyst either in SIPRNET or NIPRNET environments
- Two or more years of experience working with Windows and/or Linux systems administration
- Active DoD 8140 Workforce Certification (e.g. Security+ CE, CISSP, CySA+, GCFA, etc.)
Desired Skills
- Experience working in DevSecOps (CI/CD) environments
- Knowledge of cybersecurity principles and DoD requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
- Knowledge of IT security principles and methods (e.g., firewalls, demilitarized zones, encryption, Zero Trust)
- Ability to communicate and establish collaborative relationships with government clients and associate contractor teammates to achieve program goals
Clearance Information
SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE SECRET LEVEL WITH TOP SECRET / SCI ELIGIBILITY
Travel Requirements
- Less than 10%
About Us
Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.
Ā
SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.
EEO
Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment.
All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.
Ā
Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact jobs@scires.com for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.