Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+9 more
Job description
Computer World Services (CWS) is seeking an experienced Security Analyst to support enterprise cybersecurity operations within a Federal IT environment. The Security Analyst will be responsible for administering and maintaining security technologies, identifying and mitigating vulnerabilities, supporting vulnerability management initiatives, and serving as a technical advisor to infrastructure and application teams.
The successful candidate will possess strong experience with vulnerability management, firewall administration, security monitoring, and Federal cybersecurity compliance. This individual will work closely with infrastructure engineers, application developers, and security stakeholders to improve the organization’s security posture while ensuring compliance with NIST, FISMA, NIH/HHS, and other Federal security requirements.
Key Tasks & Responsibilities
Essential Duties and Responsibilities
Vulnerability Management
- Serve as the primary administrator for Tenable Security Center (SC) and Nessus vulnerability scanners.
- Perform authenticated and unauthenticated vulnerability scans across enterprise systems.
- Analyze scan results and prioritize remediation activities using CVSS scores, CISA Known Exploited Vulnerabilities (KEV), and organizational risk criteria.
- Produce recurring vulnerability reports for management, system owners, and compliance activities.
- Track remediation progress and validate vulnerability closures.
- Manage vulnerability waivers, risk acceptance documentation, and exception tracking.
- Monitor End-of-Life (EOL), End-of-Support (EOS), and Binding Operational Directive (BOD) vulnerability requirements.
- Coordinate with stakeholders across technical teams to drive timely vulnerability remediation efforts., * Cisco
- Checkpoint
IDS/IPS technologies
Log aggregation systems (Splunk)
File integrity monitoring solutions
Red Hat Linux
Windows workstation and server OS
MacOS
Participate in incident investigations and support cybersecurity response activities.
Assist with security assessments and continuous monitoring activities.
Application & Infrastructure Security
- Perform application vulnerability scanning.
- Coordinate vulnerability remediation with application owners.
- Support troubleshooting for application security issues.
- Partner with the Application Development team to identify security improvements throughout the software lifecycle.
Compliance & Reporting
Support organizational compliance initiatives including:
- NIST 800-53
- FISMA
- NIH/HHS cybersecurity policies
- CISA Binding Operational Directives (BODs)
- Continuous Monitoring (ConMon)
Prepare:
- Executive vulnerability reports
- Compliance dashboards
- Monthly security metrics
- Remediation status reports
Penetration Testing Remediation Support
Serve as the primary coordinator for annual penetration testing activities.
Responsibilities include:
- Coordinating testing schedules
- Supporting external penetration testing teams
- Managing findings
- Tracking remediation efforts
- Validating corrective actions
- Producing final response documentation
Operational Support
Provide day-to-day operational cybersecurity support including:
- Customer requests
- Security consultations
- Incident investigations
- Security engineering support
- Technical documentation
Requirements
- Firewall Management, * NIST 800-53
- NIST Cybersecurity Framework (CSF)
- Risk Management Framework (RMF)
- FISMA
- CISA Binding Operational Directives (BODs)
- Continuous Monitoring (ConMon)
Education & Experience
Education
- Bachelor’s degree in Computer Science, Information Systems, Engineering, or related field. Equivalent experience.
Experience
- 5-8 years of experience in information security, network security, or related fields.
Experience working in Data Center or hybrid infrastructure environments
Certifications
One or more of the following preferred:
-
CompTIA Security+
- Tenable Certified Professional (TCP)
- ITIL certification preferred.
Security Clearance
- Applicants must be able to obtain a Public Trust clearance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Dev Digest 134 - Where pixels sing?
Walking Into The Era of Supply Chain Risks
Best Paying Jobs in Technology