> Markdown version of [/jobs/ext/1180205-cybersecurity-analyst-remote](https://www.wearedevelopers.com/jobs/ext/1180205-cybersecurity-analyst-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst (Remote) - **Company:** OXLEY ENTERPRISES INC - **Location:** Stafford, VA, United States (Remote available) - **Experience:** Experienced - **Salary:** $90,897.0 - $118,016.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Extranet, Software Vulnerability Management, Information Technology, Servicenow, Plan of Action and Milestones - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7bf7c943930ca45f ## About the Role Minimum/General Experience: 5 years of experience in cybersecurity and information assurance Minimum Education: Bachelor's Degree in cybersecurity, information technology, or related field; CompTIA Security+ or Certified Authorization Professional (CAP) certification (preferred) Essential Skills/Qualifications: * Excellent experience creating and maintaining POA&Ms (e.g., periodic review, milestone updates, and mitigation plan detail) * Excellent ability to ensure POA&M alignment to National Institute of Standards and Technology (NIST) security control families and Control Correlation Identifiers (CCI) * Excellent experience drafting and maintaining TRM submissions * Excellent ability to submit and maintain Business Partner Extranet (BPE) connection requests (e.g., information gathering, request submission, and BPE admin team coordination) * Excellent knowledge of POA&M closure criteria * Above average experience maintaining security documentation (e.g., Security Impact Analysis (SIA), Information System Vulnerability Management Plan (ISVMP), Privacy Impact Assessment (PIA), Privacy Threshold Analysis (PTA), and Configuration Management Plan artifacts) * Experience supporting a federal agency * Excellent verbal and written communication skills ## Description Position Description: The Cybersecurity Analyst manages POA&M tracking, TRM submissions, Business Partner Extranet (BPE) connection management, and supports security documentation for the platform., * Sedentary Work - Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects. * Typing, communicating, repetitive motions. * Close visual acuity to prepare and analyze data, view computer monitors and read. May need to view presentation screens and other visual aids in a virtual setting. * Inside environmental conditions with protection from outside elements. Security: Active Federal Civilian Public Trust clearance * U.S. Citizenship or Permanent Resident that has lived in the United States for at least 3 years Federal Civilian Public Trust Consists of a review of up to but not limited to: * Covers 10 year period and in some instances lifetime events * OPM Security Investigations Index (SII) * DOD Defense Central Investigations Index (DCII) * National Agency Check (NAC) records * FBI name check * FBI fingerprint check * Credit report check * Written inquiries to previous employers and references listed on the application for employment * Potential interviews with the subject, spouse, neighbors, supervisor, coworkers * Law enforcement check * Court records check * Education check - Attendance and Degrees Acceptable Credentials Tasks/activities include, but are not limited to: * Creates and maintains POA&M within ServiceNow (SNOW) Continuous Authorization Monitoring (CAM) ensuring proper alignment to relevant NIST security control families and CCI * Drafts and maintains POA&M verbiage aligning with findings and clearly depicting mitigation strategy and timeline as required by the portfolio Information System Owner * Ensures POA&Ms are closed out once overcome by events (OBE), mitigated, or no longer relevant to the system to which they are assigned * Drafts justification verbiage and attends TRM approval board meetings for software and application usage requests; submits requests for TRM entry removal as usage becomes unneeded * Submits and maintains BPE connection requests including information gathering and staffing all required BPE admin team meetings * Catalogs and maintains a complete list of all BPE connections used within the platform and manages removal of connections no longer needed * Maintains and updates security documentation including SIA, ISVMP, PIA, PTA, and Configuration Management Plan artifacts for hosted applications * Reports issues and approaching TRM authorization ends with potential to affect managed applications to the appropriate portfolio Information System Owner * Contributes POA&M status, TRM activity, and BPE connection updates to the monthly RMF, security, and Authorization to Operate (ATO) status report ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)