> Markdown version of [/jobs/ext/1812716-cyber-security-analyst-iii-isse](https://www.wearedevelopers.com/jobs/ext/1812716-cyber-security-analyst-iii-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst III (ISSE) - **Company:** Scientific Research Corporation - **Location:** Virginia Beach, VA, United States - **Experience:** Experienced - **Salary:** $119,100.0 - **Contract:** Permanent contract - **Skills:** Xacta, JavaScript (Programming Language), PHP (Programming Language), Microsoft Windows, Antivirus Softwares, Apache HTTP Server, Apache Tomcat, Bash Shell, Unix, Configuration Management, Cyber Security, Information Systems, Continuous Integration, Elasticsearch, VMware ESX Servers, Web Servers, Network Topologies, Internet Information Services (IIS), Networking Hardware, WildFly (JBoss AS), Python (Programming Language), PostgreSQL, MariaDB, McAfee VirusScan, Microsoft SQL Server, MongoDB, MySQL, Nginx, Windows PowerShell, Red Hat Enterprise Linux, Reverse Engineering, Security Content Automation Protocol, SonarQube, SQL Databases, Data Streaming, Scripting, Containerization, Nessus, Bitbucket, Splunk, Docker, Jenkins, Artifactory - **Published:** July 3, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17470900?backUrl=%2Fcareer%2F17470900%2FCyber-Security-Analyst-Iii-Isse-Virginia-Virginia-Beach ## About the Role * Must possess an active Top Secret/SCI clearance w/CI Poly (or willing to sit for CI Poly) * Must be able to be appointed ISSE for NCS systems within 6-months of employment * Experience in validation of POA&Ms, ACAC/Nessus, Jfrog Xray, SCAP, DISA STIGs and general RMF artifacts * Experience in applying STIG and security control hardening along with reverse engineering potential systematic operational functionality breaks with potential compensating risk management approaches * 2-5 years of cybersecurity experience * Experience with Risk Management Framework (RMF) processes * Have developed communication skills and the ability to express thoughts and ideas clearly and concisely * Must be a team player, dedicated to program support, capable of multitasking and working several complex and diverse tasks with simultaneous or near simultaneous deadlines * Be a self-starter who is accountable and requires minimal direction and supervision * Be open to new and innovative ideas Desired Skills * Proficiency in a scripting language such as JavaScript, PHP, Python, Bash, Powershell, etc. * Proven experience with container technologies (e.g., Docker, Podmon, Kubernettes) * Familiarity with the CI/CD tools such as BitBucket, Jenkins, SonarQube, Artifactory, and JFrog Xray * Experience developing custom automation scripts, specifically within a containerized CI/CD pipeline * Experience with Amazon EKS or other container orchestration platforms * Knowledge of data flows and the ability to work up readable network topology and data flow diagrams * Experience with the following systems/platforms/tools: XACTA, XACTA 360 (preferred), eMASS, HBSS, ACAS, Nessus, SPLUNK * Experience with NAVINTEL IA and NSA Enterprise Services, like Continuous Monitoring * Knowledge of the following web servers: Apache Web Server, Apache Tomcat, Red Hat JBOSS, nginx, MS IIS * Knowledge of VMWare ESXi * Knowledge of configuration of the following SQL databases: MS SQL, PostgreSQL, MongoDB, MariaDB, MySQL, Elasticsearch * Extensive training or experience with Windows and UNIX based Information Systems standards with a working knowledge of networking devices Clearance Information SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL with CI POLY ELIGIBILITY Travel Requirements * 10% travel ## Description As a Carry-on Special Technologies Engineering and Integration (STEI) Information Systems Security Engineer (ISSE), this position is responsible for supporting the Information System Owner to complete security assessment, continuous monitoring, and configuration management responsibilities., Developing and updating assessment and authorization documentation (Body of Evidence) for management and continuous monitoring of information systems * Performing ongoing compliance assessments using tools, such as Assured Compliance Assessment Solution (ACAS), Secure Content Automation Protocol (SCAP), and McAfee Virus Scan Enterprise, while reviewing, documenting, and maintaining all results * Verifying patches and virus definitions to the systems using existing automated tools * Adhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systems * Performing security audits to track multiple events including any signs of inappropriate or unusual activity, intrusion events, data transfers, etc. * Performing security assessments of NCS Family of Systems in accordance with NIST, Navy, NSA and NAVINTEL IA guidance * Working with system engineers to take corrective action to resolve identified problems * Performing Site Based Security Assessments (SBSAs) of systems and recommending authorization to the Designated Authorizing Official (DAO) as a certified trusted agent * Reporting security incidents in accordance with the command incident response plan * Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices ## Related Videos - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Post-Quantum Cryptography: Preparing for Q-Day](https://www.wearedevelopers.com/videos/100179-post-quantum-cryptography-preparing-for-q-day) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Streaming AI Responses in Real-Time with SSE in Next.js & NestJS](https://www.wearedevelopers.com/videos/1630-streaming-ai-responses-in-real-time-with-sse-in-next-js-nestjs) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)