> Markdown version of [/jobs/ext/1181400-cybersecurity-analyst-ii](https://www.wearedevelopers.com/jobs/ext/1181400-cybersecurity-analyst-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst II - **Company:** Health, Inc - **Location:** Austin, TX, United States (Remote available) - **Experience:** Experienced - **Salary:** $69,572.0 - $114,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Information Systems Security Architecture Professional, RSA (Cryptosystem), Web Application Security, Software Vulnerability Management, Web Applications, Cloud Platform System, Information Technology, Vulnerability Analysis - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=14a3ee3b89bfb32f ## About the Role * Ability to advise diverse stakeholders on secure architecture, secure application development standards, and cloud security best practices; ability to deliver focused security training. * Ability to prepare audit documentation, assessment reports, Authorization to Operate (ATO) packages, and leadership reporting with clear, concise communication. * Skill in risk analysis and vulnerability management, including validation and prioritization of scan results and tracking remediation to closure. * Skill in conducting security and risk-based needs assessments of automated systems and business initiatives; ability to analyze administrative, technical, and operational controls and supporting evidence. * Knowledge of enterprise Governance, Risk, and Compliance (GRC) platforms such as RSA Archer; skill in maintaining risk records, POA&Ms, exceptions, and continuous monitoring evidence. * Knowledge of NIST SP 800-53 control families, NIST RMF steps, DIR security control standards, and agency CISO policies; skill in applying control requirements to systems and documenting implementation within SSPs. * Knowledge of cloud security posture management (CSPM) concepts and tooling; ability to evaluate cloud configurations for misconfigurations and control gaps across Azure and AWS environments. Registrations, Licensure Requirements or Certifications: Prefer one or more of the following certifications: * CompTIA Security+ * Certified Information Systems Auditor (CISA) * Certified Information Systems Security Professional (CISSP) * Global Information Assurance Certification (GIAC) or similar security certifications. Initial Screening Criteria: Graduation from an accredited four-year college or university with major coursework in information technology security, computer information systems, computer science, management information systems, or a related field is generally preferred. Education and experience may be substituted for one another on a year for year basis. At least 2 years' experience in information security analysis work. Experience developing and implementing information technology (IT) security training and awareness programs, policy, standards, and/or procedures preferred. Experience with cloud security in Azure and/or AWS, including review of security configurations and assessment of web application security risks preferred. ## Description The Cybersecurity Analyst II performs advanced information security analysis with a focus on cloud security, web application protection, and governance, risk, and compliance activities. The position supports both on-premises and cloud environments by evaluating, implementing, and monitoring security controls to prevent unauthorized access, modification, or disclosure of information resources. The analyst conducts security assessments and risk-based needs assessments across assigned systems. Responsibilities include assisting with the development of System Security Plans (SSPs), documenting vulnerabilities and corrective actions, analyzing administrative, technical, and operational controls, and preparing audit documentation, formal reports, and leadership-level reporting. The role also provides advisory services to business partners, offering guidance on secure architecture, secure application development practices, and cloud configuration requirements. The analyst maintains compliance and risk artifacts in a Governance, Risk, and Compliance (GRC) platform, supports Authorization to Operate (ATO) activities, and delivers targeted security training to agency stakeholders. Work is performed under limited supervision with significant latitude for independent judgment. Essential Job Functions (EJFs): Attends work on a regular and predictable schedule in accordance with agency leave policy and performs other duties as assigned. 1. Security and Risk Management Services (30%) * Provides security and risk management services by performing risk identification, assessment, and remediation, as well as regulatory and internal compliance monitoring; uses established standards and processes to adequately protect Health and Human Services (HHS) personnel, facilities, cloud infrastructure, information, and business operations. * Performs cyclical and periodic technology risk assessments of cloud environments such as Microsoft Azure and Amazon Web Services (AWS) and on-premises environments; reviews technology use within business initiatives; conducts web application security analysis, vulnerability analysis, and evaluates emerging threats. * Facilitates risk assessment sessions with Information Owners and Custodians; identifies and documents threats, vulnerabilities, likelihood, impact, and mitigation strategies; records risks, exceptions, and Risk-Based Decisions in a GRC tool; validates vulnerability scan results, prioritizes findings, and tracks remediation. 2. System Security Planning (25%) * Develops, updates, and maintains System Security Plans (SSPs) for systems and applications in alignment with applicable state and federal requirements. * Collaborates with program teams, Information Owners, and Custodians to collect, validate, and document security control implementation evidence. * Ensures Security System Plans align with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, NIST Risk Management Framework (RMF), Department of Information Resources (DIR) standards, and agency CISO policies. 3. Security and Risk-Based Needs Assessments (25%) * Plans and conducts security assessments to evaluate the effectiveness of administrative, technical, and operational security controls across assigned systems; reviews and analyzes supporting documentation and evidence. * Documents assessment results, prepares formal reports, and tracks remediation and corrective actions such as Plans of Action and Milestones (POA&Ms) to completion. * Performs risk-based needs assessments of automated systems to identify information security requirements; evaluates agency systems-including infrastructure, processes, and procedures-with a specific focus on cloud security posture management (CSPM) and web application vulnerabilities to discover compliance needs and gaps. 4. Provides Governance, Risk, and Compliance (GRC) Continuous Monitoring, Advisory, and Training Support (15%) * Maintains security artifacts, risk records, POA&Ms, continuous monitoring evidence, and compliance documentation within a GRC tool such as RSA Archer; supports Authorization to Operate (ATO) activities and ongoing monitoring requirements to ensure systems remain compliant with regulatory and agency security standards. * Prepares documentation, reporting packages, and audit responses for internal reviews, external audits, and leadership inquiries. * Advises management and users regarding enterprise security program functions, including cloud security best practices and secure application development standards; provides targeted training to agency customers within assigned specific security domains. 5. Performs or leads other duties as assigned. (5%), * Candidates for this position will be subject to a pre-employment security review to determine employment eligibility. * This is an onsite position based in Austin, TX and requires five (5) days in the office. * Any employment offer is contingent upon available budgeted funds. The offered salary will be determined in accordance with budgetary limits and the requirements of HHSC Human Resources Manual. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)