Senior InfoSec Analyst – DoD/Cloud Security and cRMF
Remote
United States
Posted 2 weeks ago
This is a full-time, remote Senior InfoSec Analyst role at Rise8, a company focused on transforming the US Government through advanced technology and collaborative, agile practices. This senior role leads the security strategy, ensuring complex systems are secure and compliant with DoD frameworks, with expertise required in cloud security, containerization, and Continuous RMF (cRMF).
- Location: Remote, United States.
- Salary Range: $115,688 – $144,611 annually.
- Experience: 6–10 years of experience in cybersecurity, information assurance, security operations, or related fields.
- Focus: Leading security assessments, applying best practices to cloud/container environments, engaging with DoD RMF and cRMF compliance, and incident response.
- Culture: Emphasis on pairing, continuous learning, empowerment, and kind collaboration.
As a Senior InfoSec Analyst, You Will: Leadership, Compliance, and Mentorship
The analyst drives security posture across the technology stack and serves as a mentor and escalation point within the team.
- Assessment & Risk Management: Lead portions of cybersecurity assessments across the technology stack, identifying vulnerabilities and recommending remediation strategies. Assist in shaping cybersecurity risk management activities to prioritize security initiatives.
- Compliance & Frameworks: Engage with external cybersecurity and compliance organizations to support alignment with Continuous RMF (cRMF) and DoD frameworks .
- Incident Response: Lead incident response investigations for medium-complexity events, conducting root cause analyses and proposing resilience improvements.
- Proactive Security: Collaborate with cross-functional teams to apply cybersecurity best practices across systems, applications, and cloud environments.
- Mentorship & Reporting: Provide cybersecurity education and regular reporting on risks, metrics, and issues to technical and leadership audiences. Mentor junior team members, supporting skills development.
Qualifications: DoD, Cloud, Containerization, and Certifications
The role demands extensive experience with government security compliance coupled with modern cloud and application security proficiency.
- Experience & Education: 6–10 years of experience. BA/BS degree in Cybersecurity, Computer Science, or equivalent practical experience.
- Core Security Knowledge: Solid understanding of cybersecurity principles, including risk management, vulnerability management, encryption, boundary defense, auditing, and authentication.
- Platform Security: Proficient with cloud, application, and platform security practices, including CIS benchmarks, container security, and cloud-native security tools.
- Security Technologies: Experience implementing and managing technologies such as firewalls, IDS/IPS, anti-malware, vulnerability scanners, encryption technologies, and IAM platforms.
- DoD Compliance: Strong familiarity with DoD security frameworks (e.g., DoD RMF, NIST 800-53) and exposure to Impact Level (IL4, IL5, IL6) requirements.
- Certifications (Required/Plus):
- Required: CISSP (or Associate CISSP), CISM, CySA+, or equivalent.
- Plus: Cloud certifications (AWS, Azure, or GCP) or security-related certifications (e.g., Security+, CCSK).
- Preferred Experience:
- Experience working within a Continuous RMF (cRMF) environment.
- Hands-on experience with cloud security tools, vulnerability management platforms, and compliance automation frameworks.
Benefits Highlights (Provided by Rise8)
- Retirement: 401k match at 10% gross pay.
- PTO: 4 weeks accrued PTO/sick leave, 11 Federal holidays, plus your birthday, jury duty, and bereavement.
- Education: Accrued budget of up to $3,500 per year for professional development.
- Equipment: Company-provided MacBook Pro.
- Wellness: Annual wellness budget ($500) or a $75 monthly credit towards a Life Time membership.
Job Features
| Job Category | Cloud Engineering, IT & Cybersecurity |