GEM Technologies, Inc.

Cybersecurity Analyst (1344)

GEM Technologies, Inc. West Mifflin, Pennsylvania, United States · $114K–$150K/yr

Environmental Services · 201-500 employees

19 h ago
Remote security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Cybersecurity Analyst will support information system authorization and compliance activities for the Naval Nuclear Laboratory in accordance with NIST and RMF directives. Responsibilities include developing security documentation, managing system security plans, and tracking remediation of cybersecurity findings.

What they look for

Cybersecurity NIST Risk Management Framework RMF System Security Plans Security Assessment Reports RSA Archer POA&M Compliance Information System Security Vulnerability Management FedRAMP Security+ CISSP CCSK Infrastructure Security

Requirements

Candidates must hold a Bachelor's degree in Engineering or a related discipline with at least 5 years of relevant experience. Applicants are required to be U.S. citizens capable of obtaining a government security clearance and must possess a current CompTIA Security+ certification.

Benefits

Medical Insurance Dental Insurance Vision Insurance HSA PPO Paid Time Off Paid Holidays Life Insurance 401(k) Retirement Plan

Full description

ABOUT THE ROLE

We are seeking a Cybersecurity Analyst to join our team supporting the Naval Nuclear Laboratory (NNL) at their Bettis Atomic Power Laboratory site! This position is full-time and will be based out of West Miffln, PA or Niskayuna, NY with hybrid flexibility.

Responsibilities

  • Support cybersecurity activities for Naval Nuclear Laboratory (NNL) information systems and the Naval Nuclear Propulsion Program (NNPP).
  • Execute cybersecurity activities in accordance with National Institute of Standards and Technology (NIST) directives and requirements.
  • Support implementation and execution of the Risk Management Framework (RMF) throughout the information system authorization process.
  • Assist Information System Owners (ISOs) with the development, review, and maintenance of System Security Plans (SSPs).
  • Develop and support Security Assessment Reports (SARs) required for system authorization.
  • Utilize the existing RSA Archer application on the Naval Nuclear Propulsion Network (NNPP Net) to document and manage cybersecurity and authorization activities.
  • Assist with the development and maintenance of Plans of Action and Milestones (POA&Ms) for cybersecurity deficiencies identified during the authorization process.
  • Support the development and documentation of Risk-Based Decisions (RBDs) associated with identified security deficiencies and risks.
  • Identify, document, track, and support remediation of cybersecurity findings and deficiencies.
  • Work with Information System Owners and other stakeholders to collect and maintain required security documentation and evidence.
  • Support ongoing information system authorization and compliance activities to ensure adherence to applicable NIST, RMF, and organizational cybersecurity requirements.
  • Maintain accurate cybersecurity documentation and records throughout the system authorization lifecycle.
  • Support cybersecurity activities at the Bettis Atomic Power Laboratory or Knolls Atomic Power Laboratory location.

Requirements

  • Education & Years of Experience – Bachelor’s Degree in Engineering or related discipline and 5+ years of relevant experience.
  • Citizenship – To be considered, you must be a United States (U.S.) citizen due to the federal nature of the work.
  • Clearance – To be considered, you MUST be able to obtain and maintain a government issued clearance before you can start.
  • Candidates with an active DOE "L" Clearance or DOD "Secret" clearance are HIGHLY DESIRED.
  • Minimum of four years of combined cybersecurity experience in one or more of the following roles:
  • Security Control Validator
  • Security Control Assessor (SCA)
  • Information System Security Officer (ISSO)
  • Information System Security Manager (ISSM)
  • Minimum of two years of experience supporting the development of information system security authorization packages in accordance with the NIST Risk Management Framework (RMF).
  • Working knowledge and experience applying NIST SP 800-37, NIST SP 800-53, and NIST SP 800-53A requirements.
  • Minimum of two years of experience working with the Federal Risk and Authorization Management Program (FedRAMP).
  • Current CompTIA Security+ certification.

Desired Skills

  • Experience using the RSA Archer application for cybersecurity, risk management, compliance, or system authorization activities.
  • Minimum of two years of experience working as part of IT security or cybersecurity project teams.
  • At least one year of experience managing IT or cybersecurity projects.
  • Knowledge of IT infrastructure and services, including:
  • Data centers
  • Physical and virtual servers
  • Local Area Networks (LAN) and Wide Area Networks (WAN)
  • Cloud Infrastructure as a Service (IaaS)
  • Platform as a Service (PaaS)
  • Software as a Service (SaaS)
  • Knowledge of cybersecurity policies, standards, and guidance, including NIST Special Publications and Security Technical Implementation Guides (STIGs).
  • Familiarity with the DoD Cloud Computing Security Requirements Guide (SRG).
  • Knowledge of infrastructure security, endpoint protection, and vulnerability management tools and practices.
  • Previous experience supporting the authorization of information systems within classified Department of Energy (DOE) or Department of Defense (DoD) environments.
  • Familiarity with NIST SP 800-171 and requirements for protecting Controlled Unclassified Information (CUI).
  • Certified Information Systems Security Professional (CISSP) certification.
  • Certificate of Cloud Security Knowledge (CCSK) certification.

About the Site

The Naval Nuclear Laboratory is comprised of the Bettis Atomic Power Laboratory, located in West Mifflin, Pennsylvania, the Knolls Atomic Power Laboratory located in Niskayuna, New York, the Kesselring Site, located in West Milton, New York, and the Naval Reactor Facility located in Idaho Falls, Idaho. Together, they develop advanced technology for the United States Naval Nuclear Propulsion Program, ensure the safety and reliability of naval nuclear reactors, and train Sailors who operate reactors in submarines and aircraft carrier fleets (energy.gov).

ABOUT GEM

GEM Technologies, Inc. (GEM) is an award-winning federal contractor with more than 30 years of experience providing environmental, construction, facility management, and technical services to federal agencies, state and local governments, and commercial organizations. Founded in 1994 as a nuclear engineering firm to support federal operations in East Tennessee, GEM has since expanded into a nationwide, multi-disciplinary provider with over 270 employees and a diverse portfolio of contracts in the environmental, nuclear, and defense sectors. Some reasons to join GEM are:

  • Our philosophy – We believe in the power of effective collaboration and recognize that good partnerships are the building blocks to success.
  • Our relationships – Partnering with federal clients, we solve complex problems, exceed expectations, and advance critical missions.
  • Our team – We are committed to managing a cohesive workforce and cultivating a supportive workplace for our employees on contracts and in-office.
  • Our community involvement – Supporting our communities, we invest time and money in local schools and non-profit organizations.

COMPENSATION AND BENEFITS

GEM’s offered compensation is dependent on candidates’ education, qualifications, and relevant years of experience. To recruit and retain our exceptional staff, we offer the opportunity to elect benefit packages that best suit our employee’s needs; this includes, but is not limited to, a competitive Salary, Medical, Dental and Vision Insurance (including HSA & PPO options), Paid Time Off (PTO), Paid Holidays, Life Insurance, and a matching 401(k) Retirement Plan.

Please Note: With the exception of mandated state requirements, GEM does not publish salary information on external job boards; as such, most ranges listed are estimates made by vendors and not actual salary ranges.

EQUAL OPPORTUNITY EMPLOYER

GEM Technologies, Inc. is an Equal Opportunity/Affirmative Action Employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

Similar roles