General Atomics Integrated Intelligence, Inc. (GA Intelligence), an affiliate of General Atomics, was founded in 1989. It provides custom software development and innovative information engineering solutions to customers in government and private industry. We build and develop best-in-class all domain and globally focused situational awareness capabilities that process petabytes of data from numerous streaming data sources in near real time. Our systems apply state-of-the-art algorithms and machine learning techniques to extract features and fuse data from multiple phenomenologies to form a rich live view of objects in the sky, on the sea, and on the ground. These analytics are designed to determine not just where something is, but what it is, where it's been and what it's doing. All of this "data to knowledge" is made available to end users in our own browser-based application for visualization, analysis, and understanding. We always want to do more, and that's where you come in!
GA-Intelligence is looking for an experienced Cyber Analyst with a Top Secret/SCI clearance to work in our Rome, NY office. This position is focused on securing and maintaining compliance of cloud workloads, including environments targeting DoD Impact Level 5 (IL5) and other U.S. Government (USG) federal information systems. The role works closely with internal teams, USG stakeholders, and external assessors to ensure cloud environments meet applicable security and compliance requirements.
DUTIES & RESPONSIBILITIES:
- Supports the design, implementation, and operation of secure AWS cloud environments (e.g., AWS GovCloud, DoD IL5), including identity and access management (IAM), network security, encryption, logging/monitoring, and configuration baselines.
- Implements and maintains security controls for cloud workloads that handle Controlled Unclassified Information (CUI) and/or USG federal information, ensuring alignment with applicable frameworks (e.g., CMMC/NIST 800-171, FedRAMP/FISMA/NIST 800-53), as directed by program requirements.
- Works with internal compliance leads to map and implement required controls in AWS and other cloud environments; provides technical input for System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and related documentation for cloud systems.
- Supports efforts to achieve and maintain DoD IL5 or equivalent impact levels for cloud workloads, including preparation for assessments, evidence collection, and remediation of findings.
- Collaborates with USG customers, program security teams, and other stakeholders to understand security requirements for specific tenants and workloads, including when environments transition to USG federal information systems and fall under non-CMMC frameworks.
- Conducts regular security control assessments and configuration reviews for cloud resources; validates that implemented controls are effective and aligned with approved baselines.
- Reviews and analyzes security logs, alerts, and reports from cloud-native services (e.g., AWS CloudTrail, GuardDuty, Security Hub, Config) and SIEM platforms to identify potential security and compliance issues in cloud environments.
- Supports vulnerability management for cloud workloads, including scanning, triage, coordination with engineering teams, and tracking remediation in accordance with applicable requirements and timelines.
- Contributes to the development, review, and maintenance of cloud security policies, standards, and procedures, including documentation of shared responsibility models and tenant-specific requirements.
- Prepares and delivers technical and compliance-related information to both technical and non-technical stakeholders, including internal leadership and USG representatives.
- Maintains the strict confidentiality of sensitive information.
- Performs other duties as assigned.
We recognize and appreciate the value and contributions of individuals with diverse backgrounds and experiences and welcome all qualified individuals to apply.