
Information Security Analyst (Journeyman)
Oasys
Job description
Who We Are: Oasys International LLC (Oasys) is a growing federal government contractor delivering innovative technology, engineering, and professional services in support of critical missions across the civilian, defense, and homeland security communities. Our continued growth and commitment to excellence have earned Oasys recognition on the Inc. 5000 list of America’s fastest-growing private companies for five consecutive years and as a Best Place to Work in Virginia for the past two years.
At Oasys, our people are at the heart of everything we do. Our team of talented technologists, engineers, consultants, and subject-matter experts works alongside our federal customers to solve complex challenges, modernize critical systems, and make a meaningful impact on the missions we support.
What makes Oasys different is the experience we strive to create for our employees. We offer the opportunity to do meaningful work while being part of a collaborative, people-focused organization where your ideas, expertise, and contributions are valued. We believe great people do their best work when they have opportunities to grow, are recognized for what they bring to the team, and have the flexibility and support needed to build a rewarding career.
Whether you are looking to deepen your technical expertise, take on new challenges, or grow into your next leadership opportunity, Oasys is a place where you can build your career while contributing to missions that matter.
Join Team Oasys and bring your talent to a company where your work is valued, your growth is supported, and your impact matters.
Position Summary:
Oasys is seeking an Information Security Analyst - Journeyman to support cybersecurity, information assurance, security operations, and Risk Management Framework (RMF) activities for mission-critical information systems. The successful candidate will help protect computer networks, applications, digital information, and electronic infrastructure by assessing cybersecurity risk, validating security controls, supporting authorization and assessment activities, monitoring security posture, and identifying and remediating vulnerabilities. This role works closely with security, technical, and Government stakeholders to ensure systems meet applicable cybersecurity requirements and remain compliant throughout the system development life cycle.
Primary Responsibilities:
-
Plan, implement, upgrade, monitor, and support security measures designed to protect computer networks, systems, applications, digital files, and electronic infrastructure.
-
Evaluate and validate technical processes supporting authorization and assessment activities to ensure systems meet organizational cybersecurity requirements.
-
Perform Risk Management Framework (RMF) activities for information systems, including systems operating in Government cloud environments.
-
Assess cybersecurity risks across systems, applications, and processes against applicable security control frameworks, regulations, policies, and requirements.
-
Assist the Security Controls Auditor with security control validation and RMF activities.
-
Perform vulnerability and risk analyses of computer systems and applications throughout all phases of the system development life cycle.
-
Analyze vulnerability management activities, recommend remediation solutions, and develop and maintain Plans of Action and Milestones (POA&Ms).
-
Use Security Information and Event Management (SIEM) capabilities to support security monitoring, analysis, and identification of potential cybersecurity events and violations.
-
Identify, report, track, and support the resolution of cybersecurity violations, vulnerabilities, security incidents, and other information assurance concerns.
-
Recommend information assurance and cybersecurity solutions that support customer and system security requirements.
-
Support the design, engineering, integration, and implementation of computer system security solutions.
-
Evaluate, test, monitor, and maintain information security policies, procedures, and security-related hardware, firmware, and software.
-
Ensure risk analyses are consistent with applicable regulations and policies and support internal and external compliance requirements.
-
Provide functional and systems analysis and technical support to resolve information assurance and cybersecurity-related issues.
-
Develop cybersecurity training, processes, procedures, plans, and documentation to support system transitions and ongoing operations.
-
Prepare correspondence, reports, white papers, meeting minutes, spreadsheets, briefs, communications products, and other cybersecurity documentation as required.
-
Identify and develop methods, plans, and documentation to streamline operating procedures, improve security operations, and support long-range program and project planning.
Skills and Qualifications:
-
Working knowledge of cybersecurity principles, information assurance, security operations, vulnerability management, and security risk assessment.
-
Experience supporting Risk Management Framework (RMF) activities, security controls assessment/validation, and cybersecurity compliance.
-
Experience using Security Information and Event Management (SIEM) technologies in a security operations or information security environment.
-
Ability to perform vulnerability and risk analysis and support development and management of POA&Ms and remediation activities.
-
Basic knowledge of Active Directory, UNIX, Windows, and relational database environments.
-
Knowledge of security policies, procedures, controls, and technical safeguards for hardware, firmware, software, applications, and networks.
-
Experience with functional and systems analysis and the ability to evaluate technical security issues and recommend practical solutions.
-
Strong analytical, problem-solving, organizational, written, and verbal communication skills.
-
Ability to collaborate effectively with cybersecurity personnel, system owners, technical teams, auditors, and Government/client stakeholders
Required Education and Experience:
-
Bachelor's or associate degree in Computer Science, Math, Information Technology, Engineering, or a related field, or at minimum an IT certification. Two (2) years of relevant experience may substitute for one (1) year of education.
-
Minimum of two (2) years of experience in information security as an analyst or in security operations.
-
Minimum of two (2) years of experience with Security Information and Event Management (SIEM).
-
Minimum of two (2) years of experience supporting Risk Management Framework (RMF) activities.
-
Basic knowledge of Active Directory, UNIX, Windows, and relational databases.
Preferred Certifications:
-
CompTIA Security+ or equivalent cybersecurity certification.
-
CompTIA CySA+ (Cybersecurity Analyst) or equivalent cybersecurity analyst certification.
-
ISC2 Certified in Cybersecurity (CC) or Systems Security Certified Practitioner (SSCP).
-
GIAC Security Essentials (GSEC), GIAC Certified Incident Handler (GCIH), or other relevant GIAC certification.
-
Certified Authorization Professional (CAP) / ISC2 Certified in Governance, Risk and Compliance (CGRC), or other relevant RMF/GRC certification.
-
Splunk Core Certified Power User, Splunk Enterprise Security Certified Admin, or another certification relevant to the candidate's SIEM platform experience.
Clearance:
-
US Citizenship required
-
Active SECRET clearance required
Work Location:
- Elizabeth City, North Carolina - Onsite/Hybrid Preferred.
Oasys is proud to be an equal opportunity employer for all protected groups, including protected veterans and individuals with disabilities.