> Markdown version of [/jobs/ext/1842175-it-security-analyst](https://www.wearedevelopers.com/jobs/ext/1842175-it-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Analyst - **Company:** Curtiss Wright - **Location:** Cheswick, PA, United States - **Salary:** $59,700.0 - $86,300.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Information Leak Prevention, Data Security, Information Security Management, Software Vulnerability Management, National Industrial Security Program Operating Manual (NISPOM), Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0d62346b369325b7 ## About the Role * Due to DoD requirements, candidates must be US citizens * Must be able to obtain and maintain DOD security clearance * Bachelor's Degree in Cybersecurity or related field and at least 2 years of experience OR 6 years of experience in lieu of a degree * Strong communication skills, analytical thinking, and problem-solving skills * Ability to prioritize tasks and efforts * Ability to analyze risks, review risk mitigations, and determine residual risk * Ability to work within a team environment and convey knowledge and skill to other members of the team in support of information security efforts * Ability to maintain information security certifications commensurate with applicable requirements (e.g. CompTIA Security+, SANS GIAC or ISC^2 CISSP) * Knowledge of the NIST 800-171 and/or NIST 800-53 security control implementation guidance * Experience with maintaining and operating information system security and vulnerability scanning software (e.g. Trellix ePolicy Orchestrator and Endpoint Security, Trellix Enterprise Security Manager, Tenable.sc, Trellix Data Loss Prevention, etc.) is preferred * Experience with DOD Risk Management Framework and the Enterprise Mission Assurance Support Service (eMASS) is a plus ## Description The IT Security Analyst is responsible for supporting the operational security posture for Curtiss-Wright (CW) Information Systems (IS). The IT Security Analyst assists the IT Security Manager in meeting duties and responsibilities related to compliance with internal and external Information Assurance (IA) requirements and standards such as: NIST 800-171, NISPOM, RMF, NIST 800-53 and CMMC., * Maintain situational awareness of current security posture of CW IS and apply guidance where needed * Provide incident response readiness and support across several IS platforms of various mission impact * Assist the IT Security team with managing governance, risk and compliance by monitoring system activity and access controls, reviewing and updating policies, performing and updating risk assessments, and driving resolution of Plan of Action & Milestones (POA&M) items * Perform continuous monitoring and vulnerability management activities such as IS event analysis and vulnerability identification, reporting, and resolution * Evaluate IS change requests and provide professional guidance to the Configuration Control Board * Participate in the architecture of new IS implementation solutions that meet the needs of the business * Assist the IT Security team with supporting third-party auditors from various federal and non-federal organizations * Perform secure data transfer agent activities when required ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)