Wood River Federal

Senior Information Security Analyst

Wood River Federal  •  San Antonio, TX (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

The Senior Information Security Analyst is a highly experienced cybersecurity professional responsible for ensuring the confidentiality, integrity, and availability of an organization's information systems. This role serves as a subject matter expert on all matters of operational cybersecurity, leading efforts to secure systems, manage risks, and ensure compliance with all governing policies and regulations. The Senior Analyst is responsible for implementing and managing the security posture of assigned systems throughout their lifecycle, from initial authorization to decommissioning. This individual works with system owners, administrators, and users to enforce security controls, respond to threats, and maintain the formal Authority to Operate (ATO).

Typical Task List:

Risk Management Framework (RMF) and Compliance:

  • Lead the development, maintenance, and submission of all

documentation required to achieve and maintain the system's ATO

under the RMF process.

  • Develop and maintain key security artifacts, including the System

Security Plan (SSP), Contingency Plan, and Incident Response Plan.

  • Conduct periodic reviews of security controls to ensure ongoing

compliance and prepare the system for security assessments and

audits.

Vulnerability Management and Remediation:

  • Perform regular vulnerability scanning of systems and networks using

approved tools (e.g., ACAS/Nessus).

  • Analyze scan results, prioritize vulnerabilities based on severity and

mission impact, and coordinate with system administrators to ensure

timely remediation.

  • Track and report on remediation progress, and develop Plans of Action

and Milestones (POA&Ms) for vulnerabilities that cannot be

immediately fixed.

Security Operations and Monitoring:

  • Monitor security logs and alerts from various sources (e.g., SIEM,

firewalls, endpoint security tools) to identify, analyze, and respond to

suspicious activity.

  • Serve as a key player in the security incident response process,

including identifying the source of a threat, containing the impact, and

leading eradication and recovery efforts.

  • Conduct regular audits of user accounts and system access logs to

detect and report unauthorized activity.

Policy and Guidance:

  • Develop, implement, and enforce information security policies,

procedures, and guidelines based on DoD, DAF, and NIST standards.

  • Provide expert cybersecurity guidance and consultation to system

owners, developers, and administrators to ensure security is integrated

into all phases of the system lifecycle ("security by design").

  • Promote security awareness by providing training and guidance to all

system users.

Minimum Qualifications / Requirements

Experience

  • A minimum of seven (7) years of progressive experience in an

information security, cybersecurity, or Information Assurance (IA)

role.

  • At least three (3) years of direct, hands-on experience serving as an

Information Systems Security Officer (ISSO) or a similar role with

responsibility for managing the RMF/ATO process for DoD systems.

Certifications (Baseline):

  • Must possess a current CompTIA Security+ CE certification (or

higher) to meet DoD 8140 requirements for IAT Level II.

Certifications (ISSO Environment - Desired):

  • Advanced certifications demonstrating subject matter expertise are

highly desired, such as:

CASP+ CE

CISM (Certified Information Security Manager)

Security Clearance:

Must be eligible to obtain and hold a DoW security clearance

Technical Skills:

  • Expert-level knowledge of the Risk Management Framework (RMF)

and NIST Special Publications (e.g., SP 800-53, SP 800-37).

  • Proficiency with vulnerability scanning tools such as ACAS/Nessus.
  • Strong understanding of network security, operating system hardening

(Windows/Linux), and application security principles.

  • Experience with Security Information and Event Management (SIEM)

systems and other security monitoring tools.

  • Familiarity with DoD Security Technical Implementation Guides

(STIGs) and the STIGing process.

Wood River Federal

About Wood River Federal

Wood River Federal is a family of Alaska Native Corporation (ANC) companies, including Intelligent Technology, LLC (I-Tech), Umyuaq Technology, LLC (U-Tech), and Wood River Services, delivering IT, professional, and mission support services to Federal Government customers worldwide. Backed by proven success in Network Modernization & Sustainment, Cybersecurity & Compliance, Test & Integration Services, and Enterprise IT Operations, our SBA-certified 8(a) companies combine technical expertise and a commitment to supporting Alaska Native communities through our parent company, Choggiung Limited.

Industry
Unknown
Company Size
11-50 employees
Headquarters
North Charleston, South Carolina
Year Founded
Unknown
Social Media