Job Description
The Cybersecurity Analyst will be responsible for ensuring the
confidentiality, integrity, and availability of enterprise IT systems, applications, and
data. This position involves monitoring, detecting, analyzing, and responding to security
events; conducting vulnerability and risk assessments; assisting in the implementation
of security controls; and supporting compliance with federal information security
policies, standards, and frameworks (e.g., FISMA, NIST 800-53, FedRAMP).
Key Responsibilities
Security Monitoring and Incident Response
- Monitor SIEM tools and security dashboards for potential threats,
anomalies, or suspicious activities. - Perform triage, containment, eradication, and recovery actions as part of
the incident response process. - Conduct root cause analysis, document findings, and provide
recommendations for preventive measures. 
Vulnerability Management and Risk Assessment
- Perform regular vulnerability scans, analyze results, and work with
system owners to remediate findings. - Conduct security risk assessments and participate in risk management
reviews. 
Compliance and Governance
- Ensure systems and operations comply with federal mandates including
FISMA, NIST 800-53, FedRAMP, OMB, and agency-specific security
policies. - Prepare and maintain documentation for ATO (Authority to Operate)
packages, POA&Ms, and continuous monitoring reports 
Security Tools and Processes
- Support deployment and tuning of security tools such as SIEM, endpoint
protection, IDS/IPS, vulnerability management, and data loss prevention
(DLP). - Recommend improvements in security posture, processes, and tooling.
 
Awareness and Collaboration
- Assist in developing security awareness training and participate in
exercises, tabletop sessions, and security audits. - Collaborate with IT, development, and network engineering teams to
ensure security is integrated into systems throughout their lifecycle. 
Required Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology,
or related field (or equivalent experience). - 3+ years of experience in cybersecurity or information security roles.
 - Hands-on experience with security monitoring, vulnerability management, and
incident response. - Familiarity with security frameworks (NIST 800-53, RMF, CIS Controls) and
federal compliance requirements (FISMA, FedRAMP). - Strong analytical and problem-solving skills.
 - U.S. Citizenship required (due to federal contract requirements).
 
Preferred Qualifications
- Industry certifications such as Security+, CEH, CySA+, CISSP (or working toward
certification). - Experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel), endpoint
security tools, and cloud security controls (AWS, Azure). - Knowledge of scripting or automation (PowerShell, Python) for security analysis
and reporting.