# Senior Information Analyst

**Company**: Anduril
**Location**: Costa Mesa, California
**Experience**: senior
**Job type**: full-time
**Salary**: $164,000-$194,000 USD
**Category**: IT
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/andurilindustries/jobs/5225898007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_17e07d38-b77

## Description

We are seeking a Senior Information Analyst to join our team. As a Senior Information Analyst, you will provide expertise in documenting security controls to reduce the administrative cost of deploying Anduril's products into operational environments.

Responsibilities:

- Provide expertise in documenting security controls to reduce the administrative cost of deploying Anduril's products into operational environments.

- Partner with program and security teams to coordinate security artifacts in support of classified deployments.

- Apply technology standards from the commercial space in classified, air-gapped environments.

- Collaborate with Information System Owners to understand key stakeholders' needs and provide complex technical solutions to meet contractual obligations.

- Tailor NIST 800-53 controls to determine applicability to the network environment and oversee the implementation of Continuous Monitoring for respective programs.

- Define, document, and conduct security scanning on Anduril's products and accredited information systems.

- Scope, shape, and orchestrate the development of features to ensure products meet compliance goals.

Required Qualifications:

- Design, develop, and implement secure systems and networks per NIST RMF, JSIG, and other industry standards.

- Integrate security best practices into Anduril's Software Development Lifecycle (SDLC) and infrastructure design, collaborating with internal IT and engineering teams.

- Conduct security risk assessments, vulnerability assessments, and audits to identify and mitigate threats.

- Recommend and implement security solutions, such as IDS/IPS, encryption protocols, and secure communications technologies.

- Develop and enforce access controls, encryption strategies, and other technical measures to safeguard systems.

- Maintain and update System Security Plans (SSPs), POA&Ms, and other accreditation documentation.

- Security Management (ISSM):

- Manage the organization's security posture, ensuring compliance with internal policies and external regulatory frameworks.

- Oversee Authorization and Accreditation (A&A) processes to obtain/maintain system Authority to Operate (ATO).

- Lead incident response efforts, including investigation, root cause analysis, containment, and reporting.

- Conduct regular audits, continuous monitoring, and risk assessments to ensure ongoing compliance and system resilience.

- Collaborate with government security officials, stakeholders, and teams to address security gaps and improve controls.

- Develop and deliver security awareness training and ensure adherence to security best practices.

- Provide leadership and mentorship to security team members, fostering a culture of cybersecurity excellence.

- Currently possesses and is able to maintain an active U.S. Top Secret security clearance.

Preferred Qualifications:

- Experience with application security paradigms such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).

- Proven experience in securing micro-services architecture, including implementing best practices and compliance with DoD cybersecurity standards.

- Experience with cybersecurity in unmanned and ground control system within DoD environments.

- Experience with containerization and kubernetes along with the best practices for securing them.

- Experience with Cloud Service Providers (CSPs) and the various tools they offer for implementing security and compliance best practices.

## Skills

### Required
- NIST RMF
- JSIG
- security risk assessments
- vulnerability assessments
- audits
- IDS/IPS
- encryption protocols
- secure communications technologies
- System Security Plans (SSPs)
- POA&Ms
- Security Management (ISSM)
- Authorization and Accreditation (A&A)
- incident response

### Nice to have
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- securing micro-services architecture
- DoD cybersecurity standards
- cybersecurity in unmanned and ground control system
- containerization
- kubernetes
- Cloud Service Providers (CSPs)

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/andurilindustries/jobs/5225898007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
