> Markdown version of [/jobs/ext/1477741-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/1477741-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - **Company:** Serco - **Location:** Orlando, FL, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Linux, Identity and Access Management, Python (Programming Language), Log Analysis, Public Key Infrastructure, Windows PowerShell, Zero Trust Network Access, Software Vulnerability Management, Scripting, Information Technology, Patch Management, CIS Benchmarks, Splunk, Vulnerability Analysis - **Published:** July 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9062989/cybersecurity-analyst ## About the Role * Active DoD Secret clearance required at time of hire. * A Bachelor's degree in Computer Science or related field and 2 years of Information Systems Administrator or Cyber-Security experience. * DoD 8570 IAT Level II or III certification (Security+, CySA+, CISSP, or equivalent) * Working knowledge of NIST SP 800-53, RMF, and Assessment & Authorization (A&A) processes. * Familiarity with STIGs, CIS benchmarks, and secure configuration management. * Strong written communication skills for security documentation (SSPs, POA&Ms, risk assessments). Additional desired experience and skills: * Demonstrated work experience as an ISSO * CISSP, CISM, or any higher tier cybersecurity certification. * Experience integrating IAM platforms with PKI/CAC/PIV authentication * Scripting/automation experience (PowerShell, Python) for identity workflow automation. * Experience administering and/or securing Linux operating systems in enterprise environments, including system hardening, log analysis and vulnerability remediation, and troubleshooting * Experience with eMASS. ## Description Serco is seeking a Cybersecurity Analyst II to support cybersecurity operations within the Distributed Mission Operations Network (DMON) in Orlando, Florida. This is a hands-on, operations-focused role responsible for monitoring, analyzing, and improving the security posture of enterprise systems. The Cybersecurity Analyst II will work daily with security tools such as Splunk, ACAS, and STIG compliance reports, identifying vulnerabilities and delivering clear, actionable remediation guidance to technical teams. In this role, you will: * Review and validate system compliance with DISA STIGs, identifying gaps and recommending corrective actions for misconfigurations and settings. * Oversee vulnerability and patch management activities including ACAS scans, system alerts, and patch mitigations. * Monitor and analyze security events and logs using Splunk, identifying anomalies and potential threats * Conduct security control implementation and testing for identity systems in support of Risk Management Framework (RMF) Assessment & Authorization (A&A) packages. * Support vulnerability remediation, patch management, and secure configuration baselines (STIGs/CIS benchmarks) for IAM infrastructure. * Partner with application owners and engineering teams to embed zero trust and least-privilege principles into identity workflows. * Serve as the ISSO of record for identity management systems, maintaining continuous authorization to operate (ATO) status. * Conduct and document risk assessments, POA&Ms, and continuous monitoring activities for assigned systems. * Coordinate with the ISSM, AO, and assessment teams during A&A activities, audits, and inspections (NIST SP 800-53, RMF, FedRAMP as applicable). * Monitor and report on security events, incidents, and access anomalies related to identity and access systems; support incident response as needed. * Maintain audit-ready documentation for access reviews, certification campaigns, and compliance evidence collection. * Ensure identity-related controls align with applicable frameworks (NIST 800-53, NIST 800-63, ICD 503, DoD RMF, or agency-specific requirements). * Brief leadership and stakeholders on identity security posture, risk, and remediation status. ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)