OASYS, INC.
Cybersecurity ISSO / SOC Analyst
OASYS, INC., Southport, North Carolina, United States, 28461
OASYS, INC., a Leading-Edge Government contractor, is seeking applicants for a Cybersecurity ISSO / SOC Analyst position to support our Army customer at Camp Roberts in San Miguel, California.
Job Responsibilities include: Supports our Army customer by providing a critical cybersecurity role by ensuring continuous monitoring in accordance with DoD Risk Management Framework (RMF), and through system monitoring and analysis support for the detection of cyber incidents and provides recommendations on how to correct findings. This role combines the duties of an ISSO, Security Operations Center (SOC) Analyst and Threat Analyst to ensure a holistic defense against emerging threats. Performs tasks in a variety of areas to include:
Serve as the ISSO in support of the ISO for assigned systems, ensuring full compliance with RMF, DoDI 8510.01, and NIST SP 800-53 security control baselines.
Manage and maintain all RMF-related documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and Plan of Action and Milestones (POA&Ms).
Conduct security control assessments and facilitate ongoing authorization (ATO/ATC) activities.
Lead vulnerability and compliance assessments using automated tools (e.g., ACAS, STIG Viewer) and ensure all findings are remediated or tracked via POA&Ms.
Monitoring security logs, analyzing and reporting cyber incidents, reviewing Common Vulnerabilities and Exposures (CVEs), and implementing directives from NETCOM (e.g., Cyber Tasking Orders - CTO).
Work is performed on-site with occasional on-call duties for critical incidents in a collaborative, demanding environment requiring attention to emerging threats and vulnerabilities.
Monitor and analyze security events and alerts generated by SIEM platforms, firewalls, IDS/IPS, and endpoint detection tools to identify potential threats and anomalous behavior.
Submits and tracks all service tickets submitted internally and externally for Operational Technology (OT) systems.
Analyze potential security incidents and investigate to determine the scope, impact, and root cause, and recommend effective remediation strategies, based on SIEM data analysis, in accordance with SLAs and OLAs.
Conduct research on the latest organization's environment threat vectors, attack methodologies, and adversarial tactics, techniques, and procedures (TTPs).
Support the configuration, tuning, and optimization of security monitoring tools, including SIEM and threat detection platforms.
Generate detailed and actionable reports for leadership from SIEM platforms summarizing identified threats, incidents, and remediation steps.
Minimum Requirements
Bachelors Degree or higher, additional years of experience may be substituted for degree
Minimum of 10 years of work-related experience.
Minimum of 2+ years of ISSO type experience.
Security+, or other DoD 8570/8140 IAT Level II certification.
Ability to work on-site daily.
eMASS experience.
Experience or familiarity with the ATO process.
Familiarity with vulnerability management tools such as ACAS, STIG Viewer, and SCAP Compliance Checker.
Familiarity with (DRAGOS, Corelight, Splunk, Snort).
Proficiency in analyzing security events, logs, and alerts from various security tools (e.g., SIEM, firewalls, IDS/IPS).
Familiarity with CVEs, threat intelligence frameworks (e.g., MITRE ATT&CK), and vulnerability management practices.
Knowledge of NETCOM policies, Cyber Tasking Orders (CTOs), and cybersecurity compliance requirements.
A high-level performer with the ability to be proactive and respond rapidly to changing conditions in a fast-paced environment
Preferred Requirements
Any of these Certifications: CISSP, CySA+, GIAC Penetration Tester (GPEN), CEH, or GIAC certifications (e.g., GCIH, GCIA), Splunk Core Certified User / Power User, Cisco Certified CyberOps Associate,Offensive Security Certified Professional (OSCP).
Experience with scripting languages (e.g., Python, PowerShell) for automating security tasks.
Understanding of advanced threat detection methodologies and incident response processes.
Required Education: Candidates should possess a bachelor's degree, preferably in Engineering, Cyber, Computer Information Systems, Computer Science, Math, Physics, or other STEM discipline however, years of experience may be substituted for a degree.
Eligibility: Candidates must have the ability to obtain and maintain a DoD Secret Clearance. An Active Secret Clearance is highly desired.
About OASYS, INC.: Located in Huntsville, Alabama, OASYS, INC. is a technology services and products company dedicated to delivering the right solutions to our government and commercial clients.
Benefits: OASYS, INC. offers a robust benefit plan to include: BC/BS of Alabama Heath & Dental, VSP Vision, Employee Stock Ownership Plan (ESOP), 401-K with Matching, Flexible Spending Account, Tuition Reimbursement, Holidays, Vacation, Short-term/Long-term Disability.
Equal Employment Opportunity is the Law: http://www1.eeoc.gov/employers/upload/eeoc_self_print_poster.pdf
#J-18808-Ljbffr
#J-18808-Ljbffr