Security Analyst
Overview
Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform® provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai.
Empower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company’s commitment to hiring and supporting active-duty and veteran employees.
Responsibilities
As a Security Analyst, you will assist the Subject Matter Expert (SME) and Cybersecurity Engineers with Risk Management Framework (RMF) related activities including Security Control Assessments (SCA) and assisting system owners in the transition to RMF compliance. In assuming this position, you will be a critical contributor to meeting Empower AI’s mission: To deliver innovative, cost-effective solutions and services that enable our customers to rapidly adapt to dynamic environments. This position is located in Fort Huachuca, Arizona. Must have active Secret clearance or the ability to obtain one.
Highlights of Responsibilities:
- Working under close supervision, performs a variety of relatively routine project tasks applied to specialized technology problems (e.g. logic design, circuit design, I/O design, firmware development, computer architecture analysis and design, network structure design, etc.)
- May be responsible for program coding, testing, debugging, patching, and documentation
- Analyzes user requirements, concept of operations documents, and high-level system architecture to develop system requirement specifications
- Guides users in formulating requirements, advises alternative approaches and conducts feasibility studies
- Typical assignments may involve integration of software, systems, and electronic processes or methodologies to resolve total system problems or applications
- Processes may range from simple to moderately complex use of computers or other electronic technology and equipment
- Edit and manage written cybersecurity deliverables, including Risk Management Framework (RMF) packages and associated artifacts.
- Assess Department of War Information Systems against the RMF security controls in accordance with Department of Defense Instruction (DoDI) 8500, DoDI 8510, and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Revision 5
- Develop and review RMF documentation and artifacts such as Configuration Management Plans, Network Infrastructure Plans, Business Continuity and Disaster Recovery Plans, Plan of Action and Milestones (POA&Ms), topology diagrams and all supporting policies in support of RMF Assess and Authorize (A&A) activities
- Interview technical SMEs as well as non-technical management personnel to ascertain the security posture of an Information Technology (IT) system
- Evaluate a wide array of IT devices for Security Technical Implementation Guide (STIG) compliance using Assured Compliance Assessment Solution (ACAS)/ Nessus, Security Content Automation Protocol (SCAP) Compliance Checker (SCC), and manual checklist reviews.
- Ensure Security Technical Implementation Guides (STIG’s) are in compliance with NIST SP-800-53 by providing thorough technical written explanations and proof
- Apply STIGs on baseline environment consisting of a variety of software and devices to ensure security compliance with NIST SP-800-53
- Manage packages in Enterprise Mission Assurance System (eMASS) based on a strong understanding of the NIST SP-800-53 requirements and the application of Control Correlation Identifiers (CCI) outlined in the Committee on National Security Systems Instruction (CNSSI) 1253 to achieve system compliance
Qualifications
Requirements:
Current/active Secret clearance.
At minimum 3 years of Cybersecurity Experience.
Bachelors degree or equivalent combination of education and related work experience
Security+ certification required
Physical Requirements:
- Sitting for long periods
- Standing for long periods
- Ambulate throughout an office
- Ambulate between several buildings
- Stoop, kneel, crouch, or crawl as required
About Empower AI
All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm’s overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.