
The Senior Information Security Analyst is a highly experienced cybersecurity professional responsible for ensuring the confidentiality, integrity, and availability of an organization's information systems. This role serves as a subject matter expert on all matters of operational cybersecurity, leading efforts to secure systems, manage risks, and ensure compliance with all governing policies and regulations. The Senior Analyst is responsible for implementing and managing the security posture of assigned systems throughout their lifecycle, from initial authorization to decommissioning. This individual works with system owners, administrators, and users to enforce security controls, respond to threats, and maintain the formal Authority to Operate (ATO).
Typical Task List:
Risk Management Framework (RMF) and Compliance:
documentation required to achieve and maintain the system's ATO
under the RMF process.
Security Plan (SSP), Contingency Plan, and Incident Response Plan.
compliance and prepare the system for security assessments and
audits.
Vulnerability Management and Remediation:
approved tools (e.g., ACAS/Nessus).
mission impact, and coordinate with system administrators to ensure
timely remediation.
and Milestones (POA&Ms) for vulnerabilities that cannot be
immediately fixed.
Security Operations and Monitoring:
firewalls, endpoint security tools) to identify, analyze, and respond to
suspicious activity.
including identifying the source of a threat, containing the impact, and
leading eradication and recovery efforts.
detect and report unauthorized activity.
Policy and Guidance:
procedures, and guidelines based on DoD, DAF, and NIST standards.
owners, developers, and administrators to ensure security is integrated
into all phases of the system lifecycle ("security by design").
system users.
Minimum Qualifications / Requirements
information security, cybersecurity, or Information Assurance (IA)
role.
Information Systems Security Officer (ISSO) or a similar role with
responsibility for managing the RMF/ATO process for DoD systems.
Certifications (Baseline):
higher) to meet DoD 8140 requirements for IAT Level II.
Certifications (ISSO Environment - Desired):
highly desired, such as:
CASP+ CE
CISM (Certified Information Security Manager)
Security Clearance:
Must be eligible to obtain and hold a DoW security clearance
Technical Skills:
and NIST Special Publications (e.g., SP 800-53, SP 800-37).
(Windows/Linux), and application security principles.
systems and other security monitoring tools.
(STIGs) and the STIGing process.

Wood River Federal is a family of Alaska Native Corporation (ANC) companies, including Intelligent Technology, LLC (I-Tech), Umyuaq Technology, LLC (U-Tech), and Wood River Services, delivering IT, professional, and mission support services to Federal Government customers worldwide. Backed by proven success in Network Modernization & Sustainment, Cybersecurity & Compliance, Test & Integration Services, and Enterprise IT Operations, our SBA-certified 8(a) companies combine technical expertise and a commitment to supporting Alaska Native communities through our parent company, Choggiung Limited.