> Markdown version of [/jobs/ext/1450357-isso-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/1450357-isso-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSO / Cybersecurity Analyst - **Company:** Farfield Systems - **Location:** United States - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cloud Computing, Cyber Security, Information Systems, Log Analysis, Azure Active Directory, Security Information and Event Management, Software Vulnerability Management, Okta, Microsoft InTune, Azure Security Center, Palo Alto Networks, Tenable Nessus, Splunk, Qualys, Servicenow, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 26, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=aa2fa7e48abd3276 ## About the Role * U.S. citizenship required + Eligible for and capable of obtaining a Tier 4 High-Risk Public Trust background investigation; suitability adjudication must be completed before being granted privileged or administrative system access + Hands-on experience supporting ISSO functions, RMF activities, or cybersecurity operations in a federal IT environment + Working familiarity with: CSAM (GRC/authorization-package platform), Splunk (SIEM/log analytics), ServiceNow ITSM modules, Tenable Nessus or Qualys vulnerability scanners, Microsoft Defender for Endpoint/Identity/Cloud/M365, Microsoft Intune and BigFix, Microsoft Azure and M365 security and compliance centers, Microsoft Entra ID, Okta, Palo Alto Panorama, and Zscaler administration consoles + Experience creating and managing POA&Ms, supporting vulnerability management workflows, and preparing cybersecurity documentation in a federal GRC platform + Ability to meet defined response and deliverable timelines in a fast-paced, audit-sensitive environment + Strong attention to detail and commitment to accurate, complete recordkeeping ## Description Working under the direction of the Lead and Senior ISSOs, you will perform the practical, outcome-driven cybersecurity work that keeps DFC's 32 information systems authorized and operationally secure. Your responsibilities will span the ISSO support spectrum: creating and updating POA&M entries in CSAM after finding identification; preparing Security Impact Assessments for standard and significant system changes; supporting continuous monitoring activities; producing vulnerability assessment data from Tenable Nessus or Qualys; contributing to audit and assessment evidence packages; documenting corrective actions and RCA findings; and supporting incident response by providing affected-system context from CSAM to incident responders. You will work within defined SLA timelines and contribute to the team's quality-first delivery culture. This is a full-time, direct-support role - not a coordination function. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)