Castalia Systems, LLC

Software Assurance Analyst

Job Locations US-MO-St Louis
ID
2024-1804
Category
Information Technology
Position Type
Regular Full-Time

Overview

Join Our Stellar Team at Castalia Systems!

 

Are you ready to skyrocket your career with us? We're on the lookout for ambitious individuals who are eager to make their mark in a diverse and thriving environment.

 

At Castalia Systems, we're not just another company – we're a certified Woman Owned Small Business (WOSB) and Small Disadvantage Business (SDB) committed to excellence since 2011. Join us in delivering top-tier solutions to the dynamic Defense and Intelligence sector.

 

As valued members of our team, we prioritize your well-being. Enjoy a comprehensive benefits package, including medical, dental, and vision coverage, 401k matching, generous PTO, paid holidays, professional training opportunities, and even pet insurance to ensure your furry friends are cared for too.

Responsibilities

Castalia Systems is seeking a Software Assurance Analyst in the St. Louis, MO area.

 

A Software Assurance Analyst will directly protect and defend against network cyber-attacks across the entire agency. NGA delivers world-class geospatial intelligence that provides a decisive advantage to our warfighters, policymakers, intelligence professionals, and first responders. This is an exciting opportunity to protect NGA’s mission critical systems for one of America’s Intelligence Agencies! Our team safeguards these systems by using forward-leaning Cybersecurity Integration, Software Assurance and Cybersecurity Business Intelligence solutions.

 

A qualified candidate will perform the following duties and responsibilities, but are not limited to:

  • Determine the risk of using commercial, government, and open source software within NGA. 
  • Investigate the software’s provenance and history of use within NGA.
  • Categorize software based on potential risk indicators. 
  • Coordinate with internal and external Offices of Primary Responsibility (e.g., Counterintelligence) to determine risks related to foreign owned, controlled, or influenced software.
  • Identify vulnerabilities and verify that vulnerabilities are mitigated. 
  • Provide input for generating Memorandum of Approvals using the SWAP tool.
  • Consult with SWAP tool developers to provide user stories, participate in planning meetings and demonstrations to enable adjustments to the SWAP tool.  
  • Validate SWAP accuracy, to include Retirement of versions no longer supported by the vendor, non-compliant versions of software, and SWAP approved software where vulnerabilities have been discovered. 
  • Recommend process improvement and innovative techniques to strengthen the efficiency of the SWAP process.
  • Adapt to changing mission requirements, as persistent technology changes occur.  
  • Provide Information System Owner’s guidance on effective implementation of NGA software code analysis tool(s) during the SDLC to include:
    • Plan scanning resource requirements.
    • Specify what source code will be evaluated.
    • Integrate scans within software build processes.  
  • Provide integration of software code analysis within NGA DevOps environments. 
  • Update and maintain code analysis tools (such as HP Fortify) in NGA’s DevOps environments.  
  • Analyze problem reports and identify corrective actions to remediate security issues in code prior to the software transitioning from development to operations.  
  • Recommend new code analysis tools and innovative techniques to strengthen software assurance processes.    
  • Manage Security Impact evaluation in NGA Test Organizations (NTO) test cases.  
  • Review all NIST install Request for Services (RFS), coordinate with programs to obtain supporting documentation for review of security relevant changes, and approve or deny this NTO security phase within the Government approved evaluation process and workflow management tool.
  • Perform security scans on an as needed bases in support of NTO testing and security validation.
  • Validate programs security patching (Security Grams (SECGRAM’s), Simplified EZ memos) within the NTO environment. 
  • Create approval or denial memo utilized in the final RFS decision.

Qualifications

Security Clearance Requirement:

  • Active/current TS/SCI minimum with the ability to obtain/maintain a Polygraph clearance is required.

 

Required Qualifications:

  • Bachelor's degree or equivalent.
  • 1+ year of relevant IT experience.
  • 8570 IAT Level II Certification, e.g. CompTIA Security+.

 

Castalia Systems is an equal employment opportunity and affirmative action employer and strives to comply with all applicable laws prohibiting discrimination based on race, color, creed, sex, sexual orientation, age, national origin, or ancestry, physical or mental disability, veteran status, marital status, HIV-positive status, as well as any other category protected by federal, state, or local laws. All such discrimination is unlawful, and all persons involved in the operations of the company are prohibited from engaging in this type of conduct.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed