> Markdown version of [/jobs/ext/1490227-cybersecurity-analyst-ii](https://www.wearedevelopers.com/jobs/ext/1490227-cybersecurity-analyst-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst II - **Company:** Xsite Llc - **Location:** San Diego, CA, United States - **Experience:** Experienced - **Salary:** $110,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Proxy Servers, Application Firewall, Software System Penetration Testing, Communications Protocols, Cyber Security, Linux, Systems Development Life Cycle, Red Hat Enterprise Linux, Security Software, System Testing, Systems Integration, Virtualization Technology, Information Technology, Devsecops, Vulnerability Analysis - **Published:** July 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=bafab0cce38aa3cf ## About the Role The ideal candidate is a self-starter with strong RMF, Navy A&A, and DoD cybersecurity experience who can work independently, coordinate with technical teams, develop mitigation strategies, and communicate cybersecurity risks clearly to both technical and non-technical stakeholders., * Minimum of 4 years of experience in cybersecurity, engineering, test and evaluation, Assessment and Authorization, or a related field * Bachelor's degree from an accredited university in a technical, engineering, cybersecurity, computer science, information technology, management, or related discipline * Active TS/SCI clearance with no Foreign Exception Package requirements * Minimum of 4 years of experience working with information technology systems for a DoD or government agency * Minimum of 3 years of experience leading Navy RMF projects, including A&A activities for systems up to the TS/SCI level * Experience preparing, developing, and maintaining RMF artifacts, packages, and deliverables * Experience implementing security controls and policies * Experience performing cybersecurity compliance testing using industry-standard tools * Experience performing vulnerability analysis and remediation for networks, systems, and communications protocols * Experience using eMASS, including Security Plan development and hands-on package processing through workflows * Experience assisting with security policy development, evaluating assessment documentation, and developing written security risks, mitigations, and recommendations * Experience with operating systems, platforms, and technologies such as Windows, Linux, networking, virtualization, or containers * Experience developing and maintaining system artifacts such as Boundary Diagrams and Data Flow Diagrams * Strong verbal and written communication skills * Ability to work independently, identify problems, develop analysis and solutions, and communicate results to technical and non-technical audiences * DoD 8140 qualified, including relevant education, training, and certification; equivalent to former DoD 8570 IAT Level II at a minimum Desired Qualifications * Experience with DoD Security Technical Implementation Guides and Evaluate-STIG * Experience with cybersecurity tools such as ACAS * Experience integrating security into DevSecOps pipelines * Experience implementing automation methodologies and processes * Experience deploying, implementing, maintaining, and integrating cybersecurity tools and applications aligned to the current threat landscape * Experience analyzing cybersecurity risks and opportunities at tactical and strategic levels * Experience with network engineering functions involving Windows, Linux, virtual operating systems, security tools, platforms, and technologies * Experience with network and web application firewalls, web proxies, intrusion prevention systems, vulnerability scanners, and penetration testing tools * Experience developing and maintaining cyber schedule, performance, and quality metrics within the systems development lifecycle or acquisition lifecycle * Experience with Navy initiatives and PMW 160 systems, including CANES, PAS, ACS, or ADNS * Master's degree in engineering, computer science, cybersecurity, or an equivalent technical discipline * Operating system certifications such as Windows, Red Hat, or Linux * Familiarity with OCF platforms ## Description * Prepare, develop, and maintain Risk Management Framework artifacts, packages, and deliverables supporting system validation and Authorization to Operate activities * Support Assessment and Authorization documentation planning, development, and maintenance * Perform risk and vulnerability assessments across network, system, and application environments * Coordinate day-to-day cybersecurity activities with program technical leads to identify cyber risks, interpret applicable policies, and develop mitigation plans * Maintain RMF documentation for system baseline variants that have achieved ATO * Support security control analysis using National Institute of Standards and Technology controls and related DoD cybersecurity requirements * Develop and deliver cybersecurity status updates and presentations to senior stakeholders * Analyze expected system, mission, and workload impacts related to cybersecurity findings and control implementation * Work independently to identify issues, develop solutions, communicate results, and lead client task execution from inception through completion, XSITE supports mission-focused government and defense programs with practical, reliable, and security-conscious technical services. We value professionalism, accountability, clear communication, and the ability to deliver high-quality work in support of critical customer missions. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Exploring the Power of gRPC-Gateway for Writing RESTful Services](https://www.wearedevelopers.com/videos/2072-exploring-the-power-of-grpc-gateway-for-writing-restful-services) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)