The Senior Information Security Analyst provides advanced cybersecurity, system accreditation, and security compliance support for Navy systems maintained by the Naval Sea Logistics Center (NAVSEALOGCEN). This role is responsible for developing, evaluating, and maintaining security controls, preparing accreditation documentation, conducting system assessments, and ensuring platforms across development, test, and production environments meet DoD, DON, and RMF cybersecurity requirements.
The Senior Analyst works closely with Information System Security Officers (ISSOs), system administrators, developers, system engineers, and program leadership to ensure that all NAVSEA systems maintain the highest levels of security readiness and accreditation compliance.
Key Responsibilities
RMF & System Accreditation Support
- Prepare, maintain, and update system accreditation documentation in accordance with Navy, DoD, and NIST RMF standards, including:
- System Security Plans (SSPs)
- Security Assessment Reports (SARs)
- Plan of Action & Milestones (POA&M)
- Continuous Monitoring artifacts
- Risk and vulnerability assessments
- System Security Plans (SSPs)
- Support system owners and ISSOs through all RMF steps, including categorization, control selection, implementation, validation, and authorization.
Security Configuration & Hardening
- Evaluate and validate the security configurations of systems and applications across development, test, and production environments.
- Apply and maintain security controls, ensuring compliance with:
- Navy STIGs and SRGs
- DISA Security Technical Implementation Guides
- DoD cybersecurity directives
- Navy STIGs and SRGs
- Conduct security configuration scans, review findings, and work with technical teams to implement mitigations.
Security Monitoring & Vulnerability Management
- Perform vulnerability assessments, analyze scan results, and verify remediation actions.
- Track and document vulnerabilities in accordance with Navy cybersecurity policy.
- Support continuous monitoring plans by updating artifacts and maintaining current system configurations.
Technical Security Analysis
- Analyze security logs, audit events, and system behaviors to identify possible incidents or policy violations.
- Evaluate emerging threats and recommend updates to system configurations or security policies.
- Support investigation of cybersecurity incidents and coordinate response actions as required.
Documentation & Reporting
- Develop and maintain system cybersecurity documentation, including configuration guides, diagrams, security test results, and accreditation evidence.
- Provide inputs for monthly technical reports outlining system status, significant risks, and security updates.
- Support engineering reviews, technical briefings, and audit readiness activities.
Collaboration & Stakeholder Engagement
- Work closely with developers, system engineers, database administrators, and network teams to ensure all system changes incorporate required security controls.
- Collaborate with program leadership to align system security postures with mission priorities.
- Participate in Agile development cycles, change management reviews, and CDRs as required.
Minimum Education & Experience Requirements
- Bachelor’s degree or higher in Computer Science, Cybersecurity, Information Systems, Information Technology, or related field.
- Minimum of seven (7) years of experience in an IT or cybersecurity role that includes:
- Preparing DoD/Navy system accreditation documentation
- Evaluating and validating system security configurations
- Applying, configuring, and maintaining security controls across multiple environments
- Supporting secure configuration management and compliance activities
- Preparing DoD/Navy system accreditation documentation
Security Clearance Requirements
- Must hold an Active Secret Security Clearance.