Information Security Analyst II

Fairfax County
Fairfax, VA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$83,010.0 - $138,350.0
Working hours
Regular working hours

Tech stack

Application Firewall Software System Penetration Testing Cyber Security Databases Information Leak Prevention Identity and Access Management Information Sciences Intrusion Detection and Prevention Virtual Private Networks (VPN) Network Security Network Architecture Open Web Application Security
+11 more
PCI Data Security Standards Cloud Services Security Information and Event Management Software Vulnerability Management Enterprise Software Applications Malware Firewalls (Computer Science) Information Technology Cybercrime CIS Benchmarks Vulnerability Analysis

Job description

Acts as an Information Security Analyst within the Information Security Office (ISO), supporting cybersecurity, privacy, and technology risk management across the enterprise. This role focuses on evaluating cyber threats, responding to security incidents, supporting agency inquiries, and contributing to the implementation, governance, and operation of countywide cybersecurity controls. The position directly supports the Policy & Compliance unit within ISO.

Responsibilities may include:

  • Develops and maintains information security policies, standards, guidelines, and procedures to meet federal, state, and county regulatory requirements.
  • Supports internal and external audits, assessments, and compliance reviews for security and privacy obligations.
  • Manages data preservation and collection requests related to legal matters, Virginia Freedom of Information Act (VFOIA) requests, internal investigations, forensic activities, and other eDiscovery processes.
  • Conducts security outreach, delivering awareness training, and assists agencies in interpreting county information security policies.
  • Investigates cybersecurity incidents and responds to alerts from SIEM systems, vulnerability scans, endpoint tools, and penetration testing reports.
  • Implements, administers, and supports security technologies such as endpoint protection, data loss prevention, intrusion detection/prevention systems, application firewalls, vulnerability management platforms, and forensic utilities used by the ISO.
  • Coordinates daily with DIT divisions, agency information security coordinators, IT analysts, and external partners regarding cybersecurity and compliance matters.
  • Serves as a technical and operational advisor on cybersecurity issues, compliance questions, and policy interpretation.
  • Stays current with cybersecurity, privacy, and regulatory trends and pursuing relevant professional certifications.
  • Supports emergency IT events and participating in county Emergency Operations Center activations as needed.
  • Performs other duties as assigned.

Requirements

Any combination of education, experience, and training equivalent to the following: (Click on the aforementioned link to learn how Fairfax County interprets equivalencies for ā€œAny combination, experience, and training equivalent toā€)

Graduation from an accredited four-year college or university with a bachelor’s degree in a computer or information science discipline, IT/cyber security, network or IT systems administration, engineering; or a bachelor’s degree in a business or related field that has been supplemented by at least 18 credit hours of intermediate computer science coursework; plus one year of experience in information security systems, network security, or cyber security. NECESSARY SPECIAL REQUIREMENTS: The appointee to this position will be required to complete a criminal background check to the satisfaction of the employer., + Experience implementing, assessing, or maintaining compliance with IT and privacy regulations or standards such as HIPAA, PCIDSS, CJIS, Virginia privacy requirements, federal PII protections, and institutional standards such as the NIST Cybersecurity Framework, NIST 80053/171, ISO 27000 series, OWASP, or SANS CIS Controls.

  • Experience working with and understanding of security and network architecture, identity and access management, operating systems, cloud services, databases, and modern enterprise technologies.
  • Experience with technologies including malware analysis tools, application and network firewalls, VPN solutions, DLP, identity management platforms, SIEM solutions, and intrusion detection/prevention systems.
  • Demonstrated experience in policy development, security governance, audit support, and agency consulting.
  • Experience applying strong analytical, communication, and collaboration skills in a cybersecurity, compliance, or technical consulting environment.

PHYSICAL REQUIREMENTS: Work is generally sedentary, performed in a normal office environment. All duties performed with or without reasonable accommodations.

Benefits & conditions

$83,009.89 - $138,349.74 Annually medical insurance, dental insurance, vision insurance, child care, retirement plan United States, Virginia, Fairfax Jul 04, 2026

About the company

Fairfax County is home to a highly diverse population, with a significant number of residents speaking languages other than English at home (including Spanish, Asian/Pacific Islander, Indo-European, and many others.) We encourage candidates who are bilingual in English and another language to apply for this opportunity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· WWC 2022

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 Ā· LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg Ā· LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa Ā· LIVE

1:27 min

Differences between autonomous AI agents and traditional malware

Michele Zuccala Michele Zuccala +4 Ā· WWC Europe 2026

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira Ā· Coffee With Developers

Videos

See all

Related articles

See all