Easter Seals Jobs

Job Information

UIC Government Services and the Bowhead Family of Companies Cybersecurity Analyst in Dahlgren, Virginia

Overview

Cybersecurity Analyst (EDOS-2024-21126):

Bowhead is seeking a skilled full-time Cybersecurity Analyst to join our team in Dahlgren, VA. The ideal candidate will be responsible for ensuring GWS fleet and land-based configurations are assessed and authorized with respect to Department of Defense (DOD) Cybersecurity policies.

Responsibilities

The Cybersecurity Analyst is responsible for ensuring GWS fleet and land-based configurations are assessed and authorized with respect to Department of Defense (DOD) Cybersecurity policies.

Key Responsibilities:

  • Conducting vulnerability scans and recognizing vulnerabilities in security systems.

  • Using DoD network analysis tools to identify vulnerabilities (e.g., ACAS, HBSS, etc.).

  • Conducting application vulnerability assessments.

  • Identifying systemic security issues based on the analysis of vulnerability and configuration data.

  • Sharing meaningful insights about the context of the organization’s threat environment that improve its risk management posture.

  • Applying cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

  • Troubleshooting and diagnosing cyber defense infrastructure anomalies and working through resolution.

  • Performing impact/risk assessments.

Required Skills:

  • Conducting vulnerability scans and recognizing vulnerabilities in security systems.

  • Using DoD network analysis tools to identify vulnerabilities (e.g., ACAS, HBSS, etc.).

  • Skill in system, network, and OS hardening techniques (e.g., remove unnecessary services, password policies, network segmentation, enable logging, least privilege, etc.).

  • Conduct vulnerability assessments.

  • Ability to identify systemic security issues based on the analysis of vulnerability and configuration data.

  • Ability to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). Tenable Assured Compliance Assessment Solution (ACAS)

  • Applying host/network access controls (e.g., access control list).

  • Use of Virtual Private Network (VPN) devices and encryption.

  • Protecting a network against malware. (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters).

  • Troubleshooting and diagnosing cyber defense infrastructure anomalies and work through resolution.

  • Performing impact/risk assessments.

  • Other duties as assigned.

Qualifications

Required:

  • DoDM 8140.03 certified,( any IAT level 2 certification will meet requirement)

  • Seven (7) years of professional experience as a Cybersecurity Specialist with a specialization in cross domain solution implementation.

  • 5 + years of computer networking concepts and protocols, and network security methodologies experience.

  • Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth & concept of zero trust).

  • Experience working with Intrusion Detection System (IDS)/Intrusion Prevention System (IPS) tools and applications.

  • Experience working with network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.

  • Knowledge of application vulnerabilities.

  • Knowledge of system administration, network, and operating system hardening techniques.

  • Knowledge of system administration concepts for operating systems such as but not limited to Unix/Linux, IOS, Android, and Windows operating systems.

Preferred:

  • Knowledge of cyber threats and vulnerabilities.

  • Knowledge of specific operational impacts of cybersecurity lapses.

  • Knowledge of host/network access control mechanisms (e.g., access control list, capabilities list).

  • Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

  • Knowledge of network traffic analysis methods.

  • Knowledge of Virtual Private Network (VPN) security.

  • Knowledge of transmission records (e.g., Bluetooth, Radio Frequency Identification (RFID), Infrared Networking (IR), Wireless Fidelity (Wi-Fi). paging, cellular, satellite dishes, Voice over Internet Protocol (VoIP)), and jamming techniques that enable transmission of undesirable information, or prevent installed systems from operating correctly.

  • Knowledge of network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML).

  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).

  • Knowledge of different classes of attacks (e.g., passive, active, insider, close-in, distribution attacks).

  • Knowledge of application security risks.

Physical Demands:

  • Must be able to lift up to 25 pounds.

  • Must be able to stand and walk for prolonged amounts of time.

  • Must be able to twist, bend and squat periodically.

SECURITY CLEARANCE REQUIREMENTS: Must currently hold a security clearance at the Secret level. US Citizenship is a requirement for Secret clearance at this location.

#LI-BG1

Applicants may be subject to a pre-employment drug & alcohol screening and/or random drug screen, and must follow UIC’s Non-DOT Drug & Alcohol Testing Program requirements. If the position requires, an applicant must pass a pre-employment criminal background history check. All post-secondary education listed on the applicant’s resume/application may be subject to verification.

Where driving may be required or where a rental car must be obtained for business travel purposes, applicants must have a valid driver license for this position and will be subject to verification. In addition, the applicant must pass an in-house, online, driving course to be authorized to drive for company purposes.

UIC is an equal opportunity employer. We evaluate qualified applicants without regard to race, age, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other protected characteristics EOE/AA/M/F/D/V. In furtherance, pursuant to The Alaska Native Claims Settlement Act 43 U.S.C. Sec. 1601 et seq., and federal contractual requirements, UIC and its subsidiaries may legally grant certain preference in employment opportunities to UIC Shareholders and their Descendants, based on the provisions contained within The Alaska Native Claims Settlement Act. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities. Please view Equal Employment Opportunity Posters provided by OFCCPhere (https://www.dol.gov/agencies/ofccp/posters) .

All candidates must apply online at www.uicalaska.com, and submit a completed application for all positions they wish to be considered. Once the employment application has been completed and submitted, any changes to the application after submission may not be reviewed. Please contact a UIC HR Recruiter if you have made a significant change to your application. In accordance with the Americans with Disabilities Act of 1990 (ADA), persons unable to complete an online application should contact UIC Human Resources for assistance (https://uicalaska.com/careers/recruitment/).

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)

UIC Government Services (UICGS / Bowhead) provides innovative business solutions to federal and commercial customers in the areas of engineering, maintenance services, information technology, program support, logistics/base support, and procurement. Collectively, the fast-growing Bowhead Family of Companies offers a breadth of services which are performed with a focus on quality results. Headquartered in Springfield, VA, we are a fast-growing, multi-million-dollar company recognized as a top Alaska Native Corporation providing services across the Department of Defense and many federal agencies. Bowhead offers competitive benefits including medical, dental, vision, life insurance, accidental death and dismemberment, short/long-term disability, and 401(k) retirement plans as well as a paid time off programs for eligible full-time employees. Eligible part-time employees are able to participate in the 401(k) retirement plans and state or contract required paid time off programs.

Join our Talent Community!

Join our Talent Community (https://talentconnect.uicalaska.com/government-services/talentcommunity) to receive updates on new opportunities and future events.

ID 2024-21126

Category Cybersecurity/Information Security

Location : Location US-VA-Dahlgren

Clearance Level Must Be Able to Obtain N/A

Minimum Clearance Required Secret

Travel Requirement Less than 10%

DirectEmployers