Back to career page

Cybersecurity Analyst / ISSE Support (ATO Focus)

E Logic

Job Title: Cybersecurity Analyst (RMF/ATO) - SECRET Clearance Required

Location: Vandenberg Space Force Base (VSFB), CA (On-site)

Clearance: Active SECRET Clearance Required; U.S. Citizenship required

Job Type: Full-time

Contract Type: Government Contract (Base Year + 4 Option Years)

Position Overview

We are seeking a dedicated Cybersecurity Analyst to lead the Authority to Operate (ATO) compliance efforts for the On-premises Safety Analysis System (SAS) and its classified counterpart (SAS-C) at Vandenberg Space Force Base. This role focuses heavily on the Risk Management Framework (RMF) lifecycle, vulnerability management, eMASS documentation, and continuous monitoring, ensuring the systems meet NIST SP 800-53 Revision 5 requirements.

The ideal candidate is a cybersecurity professional with deep knowledge of DoD security frameworks and proven experience managing ATO packages from initiation to authorization. This position requires an on-premises presence, as the SAS systems are not accessible via external connections.

This is a non-personal services contract position. The contractor employee reports directly to the Prime Contractor for all human resources, disciplinary, and administrative matters, while receiving work direction and prioritization from SLD 30/RM management and the Information Systems Security Engineer (ISSE).

Key Responsibilities

Cybersecurity & ATO Compliance

  • Manage the ATO application process for the SAS/SAS-C systems to completion, utilizing NIST SP 800-53 Revision 5 requirements with a goal of completion by the end of FY27.
  • Implement continuous monitoring practices in accordance with Department of War (DoW) standards to proactively identify and mitigate potential cyber threats, reducing the risk of cyber breaches.
  • Establish and manage an ACAS server that applies appropriate Security Technical Implementation Guides (STIGs) to the SAS/SAS-C systems.
  • Conduct weekly security tests and ongoing security monitoring to identify and mitigate potential vulnerabilities, in alignment with ATO policy.
  • Gather and furnish system artifacts for the SAS/SAS-C systems, as specified by the ISSE, in a timely and comprehensive manner to support ongoing security assessments and compliance requirements.
  • Work with the ISSE to implement security controls and ensure that vulnerabilities are identified and addressed in a timely manner.
  • Enter, track, and manage Plans of Actions and Milestones (POA&Ms) and control implementations within eMASS.
  • Perform all work using industry standards, to include Security Controls as specified in NIST 800-53 and approved by the system owner and ISSM.

Compliance & Documentation

  • Ensure all created and maintained records remain the property of the Government and are returned upon contract completion.
  • Maintain network integrity and safeguard against loss of materials.
  • Comply with all security protocols outlined in the DD Form 254.

Deliverables

  • Submit SAS and SAS-C ATO artifacts to the SLD 30/RM requiring office as per policy.
  • Provide all application materials, controls, and POA&Ms to eMASS in accordance with ATO timelines.

Required Qualifications

  • Education: High School Diploma or equivalent (Bachelor's Degree in Cybersecurity, Information Assurance, Computer Science, or related field preferred).
  • Experience: Minimum 2-4 years of experience in DoD Risk Management Framework (RMF) and Authority to Operate (ATO) processes.
  • Citizenship: U.S. Citizenship required.
  • Security Clearance: Active SECRET clearance required; Must be eligible for a Common Access Card (CAC).
  • Certifications: Must possess a current Information Assurance Technical (IAT) Level II certification (e.g., CompTIA Security+ CE). IAT Level III or CISSP certification is highly desired.
  • Technical Skills: Expert knowledge of NIST SP 800-53 (Revision 5), eMASS, ACAS, and Security Technical Implementation Guides (STIGs).
  • Knowledge: Deep understanding of FISMA compliance, continuous monitoring practices, and DoD cybersecurity frameworks and policies.
  • Language: Proficient in written and verbal English.
  • Interpersonal: Ability to work cross-functionally with System Owners, ISSEs, and ISSMs to drive ATO success.
  • Judgment: Ability to exercise sound judgment and work independently to accomplish goals while maintaining strict compliance with security protocols.

Schedule & Work Conditions

  • Hours: Standard business hours, Monday through Friday (40 hours per week). Specific start/end times to be coordinated with government management.
  • Location: Bldg. 8500, 1515 Iceland Ave, Vandenberg SFB, CA 93437.
  • On-Site Requirement: Work must be performed on-premises; no external or remote access to the SAS systems is permitted.
  • Federal Holidays Off: All Federal holidays observed.
  • Additional Closures: As directed by Vandenberg SFB leadership.

Time Off Policies

  • Planned absences and vacation must be coordinated at least 2 weeks in advance with the Prime Contractor and government POC to ensure ATO milestones and operational thresholds are maintained.
  • Approved vacations shall not exceed 14 consecutive calendar days.
  • No temporary substitutions are allowed without prior government approval.
  • Absences exceeding 20 days in a 90-day period without substantiated approval may lead to termination.

Dress Code

Business casual professional attire required while performing contract duties. Inappropriate attire includes sweats, skirts shorter than 2 inches above the knee, exposed midriff, spaghetti straps, sheer clothing, low-cut tops, shorts, flip flops, slippers, sleepwear, bib overalls, offensive logos/slogans, halter tops, and t-shirts. Hats are not permitted except for religious or cultural head coverings.

Security Requirements

  • CAC & Clearance: Must maintain an active SECRET clearance and CAC for the duration of the contract. Must pass FBI fingerprint check and NACI background investigation as required.
  • Computer Security: Must complete DoD Cyber Awareness Challenge training prior to network access and annually thereafter.
  • Contractor Badge: Must wear government-issued identification badge at all times, visible on outer clothing.
  • CUI Compliance: Must comply with Freedom of Information Act and Privacy Act requirements for handling Controlled Unclassified Information.
  • Key Control: Must safeguard government-issued keys; lost or duplicated keys may result in re-keying costs deducted from payment.
  • Non-Personal Services: Employee reports directly to the Prime Contractor for HR, disciplinary, and administrative matters. Government provides orientation to VSFB facilities and government-unique systems only.

Equal Opportunity Employer

We are an equal opportunity employer and do not discriminate on the basis of race, color, religion, sex, gender identity, sexual orientation, national origin, genetics, disability, age, or veteran status.

Job type
Full Time