Job Description
Title: Cybersecurity Risk & Exposure Analyst
Location: Colorado Springs, CO
Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph
Job Details:
- Support operational cyber risk, vulnerability/exposure, and continuous-monitoring activities that provide security context to SOC watch operations and affected system stakeholders
- Review ACAS/Tenable vulnerability data, runZero asset information, STIG/configuration findings, system documentation, and other approved sources to help identify known weaknesses and relevant asset context
- Assist in enriching SOC investigations with available information about affected assets, known vulnerabilities, security configuration, system ownership, and documented controls
- Support coordination of SOC-derived security findings with system ISSOs/ISSMs, system owners, administrators, engineers, and remediation personnel; maintain clear records of findings, actions, and status
- Assist with tracking vulnerabilities, remediation actions, POA&M-related items, and continuous-monitoring evidence when SOC findings identify or validate a system security weakness
- Contribute to recurring exposure, vulnerability, and continuous-monitoring metrics and reporting used to support operational awareness and risk reduction
- Apply foundational knowledge of networking, operating systems, vulnerabilities, security controls, and RMF concepts to connect technical findings with system security context
- Analyze identified vulnerabilities and configuration weaknesses to determine technical risk, potential exploitation scenarios, affected assets, and mission/operational impact
- Support continuous-monitoring metrics, customer/service reporting, and assessment and authorization activities as required
Requirements:
- Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
- Minimum two (2) years of relevant cybersecurity experience in addition to education
- Strong written and verbal communication skills and the ability to document technical work clearly
- Demonstrated knowledge of vulnerability management, asset and exposure analysis, DoD continuous monitoring, RMF/security controls, and technical risk assessment appropriate to the position level
- Experience with ACAS/Tenable, runZero or comparable asset-discovery/exposure tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, security-control evidence, or comparable technologies and processes is desired
- Ability to coordinate technical findings, risk context, remediation status, and supporting evidence with SOC personnel, system ISSOs/ISSMs, system owners, engineers, and other stakeholders
- Must possess current DoD 8570 IAT II or IAM II certification
- Experience working in a DoD or IC environment desired
- Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph
Equal Opportunity Employer/Veteran/Disabled