Information Security Analyst

At Cryptic Vector, we are dedicated to mission success. We take the time to understand our customers' needs, delivering products that perform when our nation needs them most. We understand that properly supporting the most unique missions of the United States government requires the nation’s best. Our focus is on creating a culture where the best and brightest want to grow, learn, and stay. If producing out-of-the-box solutions is your specialty, then you’ll feel right at home at Cryptic Vector. We are solving the country’s most unique problems in an environment where problem solvers and hard workers thrive. We've replaced corporate red tape with transparency and servant leadership. Honestly, it’s hard not to love this culture!


Information Security Analyst (Classified Systems)


The Information Security Analyst (Classified Systems) will support compliance, auditing, and documentation activities for classified information systems. In this role, you will serve as the Information System Security Officer (ISSO) for assigned systems, focusing on the full Risk Management Framework (RMF) lifecycle — including security control assessments, continuous monitoring, and system authorization (ATO) maintenance. You will work closely with system owners, engineers, and the Information System Security Manager (ISSM) to keep classified systems compliant and mission ready.


You will have the opportunity to play a meaningful role in protecting high-stakes classified environments by ensuring robust security posture, driving compliance excellence, and directly supporting critical national security missions.


Responsibilities:

  • Act as ISSO for classified systems, supporting the RMF lifecycle, including:
    • Security control assessments
    • System authorization (ATO) maintenance
    • Continuous monitoring and reporting
  • Manage and maintain RMF documentation in eMASS or manually (based on customer requirements), including:
    • System Security Plans (SSP)
    • Security Control Traceability Matrices (SCTM)
    • Risk Assessment Reports (RAR)
    • Plans of Action & Milestones (POA&M)
  • Conduct and document vulnerability assessments using tools such as:
    • SCAP Compliance Checker
    • STIG Viewer
  • Perform audits and reviews to verify compliance with applicable security controls and standards, including:
    • NIST SP 800-53
    • JSIG/DISA guidance (as applicable)
    • DCSA requirements
  • Maintain asset inventory and configuration documentation for classified systems
  • Track findings and coordinate remediation with system owners, system admins, and ISSM
  • Support inspections, audits, and government assessments for classified systems
  • Stay current on RMF guidance, cybersecurity standards, and government training requirements (e.g., DCSA CBTs)

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available