> Markdown version of [/jobs/ext/1403226-cybersecurity-analyst-isso](https://www.wearedevelopers.com/jobs/ext/1403226-cybersecurity-analyst-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst / ISSO - **Company:** Lever, Inc. - **Location:** Stafford, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Cisco PIX, Cisco IOS, Cyber Security, Identity and Access Management, Network Security, Machine Learning, Red Hat Enterprise Linux, Zero Trust Network Access, Systems Architecture, Speech Recognition, SC Clearance, Cyber Warfare, Scap Compliance Checker, Data Pipelines, Plan of Action and Milestones - **Published:** July 23, 2026 - **Apply:** https://jobs.lever.co/sprymethods/f1643ee1-256e-4edb-a21e-615daca5c541/apply ## About the Role * A.I. Risk & Architecture: Experience assessing the risk of Artificial Intelligence (A.I.) and Machine Learning (ML) capabilities, including familiarity with emerging DoD A.I. security guidelines, data pipeline security, and assessing A.I. toolsets within the authorization boundary. * DoD/ DoW Cyber Directives: Proven capability to interpret, analyze, and direct programmatic responses to MFCC (Marine Forces Cyber Command) and DCDC (Department of Defense Cyber Defense Command) TaskOrds, Cyber Tasking Orders (CTOs), and other organizational directives, policies, and messages governing cyber / IT. * Strategic POA&M Management: Expert-level creation, management, and strategic burn-down of complex Plan of Action and Milestones (POA&Ms) across multiple enterprise systems, ensuring alignment with USMC continuous monitoring timelines / requirements. * CND Oversight: Advanced understanding of Computer Network Defense (CND) architectures, including zero-trust principles, network boundary defense, and threat intelligence integration. * RMF Leadership: Deep expertise navigating eMASS and leading systems through the complete Risk Management Framework (RMF) Assess and Authorize (A&A) lifecycles and workflows. * Deep understanding of NIST SP 800-53 security controls, CNSSI 1253, NIST SP 800-161 & NIST SP 800-162, and DoDI 8510.01. * Experience drafting organizational cybersecurity policies, Incident Response Plans, and Continuous Monitoring Strategies. * Advanced proficiency using the DISA STIG Viewer, executing SCAP Compliance Checker (SCC), using eMASSter, and manually validating STIG/SRG requirements on diverse operating systems (Windows, Red Hat Linux, Cisco IOS, Cisco ASA). * Expert level understanding of applying zero-trust methodologies to system design and tracking implementation throughout the system life-cycle., * Experience Level: 4-8 years of progressive experience in DoD cybersecurity, information assurance, or Computer Network Defense (CND). * Security Clearance: Active Secret clearance * DoD 8140/8570.01-M Baseline Certification: IAM Level II or III (e.g., CISSP, CISM, CAP/CGRC) AND highly recommended to hold a CSSP Auditor/Manager baseline. ## Description This role requires a strategic understanding of how emerging technologies (like A.I.) and high-level USMC Cyber Directives impact the acquisition lifecycle and overall enterprise risk posture. What Your Day-To-Day Looks Like (Position Responsibilities): Leading cybersecurity risk management efforts across enterprise systems by assessing AI and machine learning capabilities, overseeing RMF authorization activities, managing POA&M remediation strategies, and ensuring compliance with DoD cybersecurity directives and NIST standards. Responsibilities include evaluating system architectures through a zero-trust lens, interpreting and implementing Cyber Tasking Orders, validating security controls and STIG compliance, developing cybersecurity policies and continuous monitoring strategies, and providing technical leadership to maintain secure, mission-ready environments. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)