Sr. Cyber Network Vi Analyst
Current• Create customized scanning/testing configurations within testing tools to suit security configuration requirements.• Experience conducting security audits of information systems.• Vulnerability assessment and analysis experience utilizing SCAP, ACAS/NESSUS and DISA STIGs• Experience with DoD implementation of the Risk Management Framework (RMF) and governing directives (NIST, CNSS, DCSA, etc.)• Familiarity with the Defense Counterintelligence and Security Agency Assessment and Authorization Manual (DAAPM)• Assessed whether security controls are implemented correctly, operating as intended and producing the desired outcome• Installed, configured, and maintained DISA ACAS (Assured Compliance Assessment Solution) and HBSS (Host Based Security System) servers• Configured and conducted daily ACAS scans with the use of Security Center and conduct patching and remediation when necessary in accordance with the IAVM process• Perform security testing and evaluation of servers, workstations, databases, and network fabric devices (i.e. firewalls, switches, routers, load balancers) in order to determine security vulnerabilities and weaknesses, and to create reports of security findings in support of security authorization process. • Identify the applicable NIST 800-53 security controls or policies that correspond to any finding identified via manual or automated testing, to a specific CVE, IT technologies.• Perform analysis of cybersecurity directives, policies, and instructions to include, but not limited to: Communications Task Orders (CTOs), Fragmentary/Task/Operation Orders (FRAG/TASK/OPORDs), IA Vulnerability Management (IAVM), Public Key Infrastructure (PKI) guidance, and STIG requirements.• Track and report compliance status in the Vulnerability Remediation Asset Manager (VRAM) and similar reporting tools as applicable.• Perform risk analysis/independent verification on security configuration and STIG finding risk reports / POA&Ms for devices on the network.