> Markdown version of [/jobs/ext/1926172-usaf-jr-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/1926172-usaf-jr-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # USAF - Jr. Cybersecurity Analyst - **Company:** cFocus Software Incorporated - **Location:** Box Elder, SD, United States - **Experience:** Starter - **Contract:** Internship / Graduate position - **Skills:** Cyber Security, Information Systems, Decision Support Systems, Identity and Access Management, SAP Sales and Distribution, Information Technology, Software Version Control, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** http://cfocussoftware.applytojob.com/apply/jobs/details/hnP9GBxRuy ## About the Role * Active TS/SCI SSBI clearance * B.S. Computer Science, Information Technology, or a related field * 10+ years of RMF/Cybersecurity experience * Foundational experience or education in cybersecurity, information assurance, RMF, security compliance, information systems, or a closely related discipline. * Working knowledge of the RMF and Assessment and Authorization lifecycle, including security controls, implementation evidence, risk assessment, authorization artifacts, and continuous monitoring. * Ability to develop and maintain SSPs, RARs, POA&Ms, assessment findings, inventories, and related authorization documentation with senior guidance. * Ability to learn and use eMASS and ITIPS and to maintain accurate data across multiple systems and recurring reporting cycles. * Basic understanding of vulnerability assessment, risk analysis, remediation tracking, residual risk, and POA&M lifecycle management. * Strong analytical, technical writing, documentation, quality-control, organization, and attention-to-detail skills. * Ability to communicate professionally with system owners, security personnel, engineers, program offices, and Government stakeholders. * Ability to manage multiple assignments and deadlines, protect sensitive information, and escalate discrepancies or risks promptly. * One to three years of relevant cybersecurity, information assurance, compliance, vulnerability-management, audit, or federal IT experience; internships and military experience may be considered. * A current credential satisfying the applicable IAM Level II and DoD 8140 722-Intermediate qualification requirements. * Coursework or hands-on exposure to NIST SP 800-53, DoD RMF, eMASS, vulnerability scanning, POA&M tracking, control assessment, and technical documentation ## Description cFocus Software seeks a Jr. Cybersecurity Analyst to join our program supporting the United States Air Force. This position is onsite with the onsite location being in Ellsworth, South Dakota. This position requires a TS/SCI SSBI clearance., * Support the full RMF lifecycle, including security control selection, implementation tracking, evidence collection, validation support, authorization, and continuous monitoring. * Assist with interpretation of federal, DoD, and Air Force cybersecurity policies and help translate requirements into system-level implementation actions. * Develop, update, organize, and maintain authorization artifacts for multiple systems, including SSPs, RARs, POA&Ms, control evidence, inventories, diagrams, and supporting records. * Enter, validate, reconcile, and maintain cybersecurity and authorization data in eMASS and ITIPS. * Review security-control implementation statements and evidence for completeness, consistency, currency, and traceability; identify gaps for senior review. * Support vulnerability assessments, analyze findings, document risk information, and assist in developing practical mitigation and remediation strategies. * Track vulnerabilities, POA&M milestones, overdue actions, closure evidence, authorization status, and ATO expiration dates across assigned systems. * Coordinate with system owners, ISSOs, engineers, program offices, and other stakeholders to collect artifacts, clarify discrepancies, and advance remediation actions. * Assist with security-control assessment findings reports that document gaps, weaknesses, risk levels, and recommended remediation strategies. * Support preparation of A&A decision staff packages, including control summaries, risk analysis, mission-impact information, and recommendations for ATO, ATO with Conditions, or Denial. * Help prepare POA&M status reports, escalation reports, FM systems inventory/boundary updates, cybersecurity policy and guidance updates, and leadership briefing materials. * Compile metrics and trend data for vulnerabilities, remediation progress, POA&M closure, artifact currency, authorization status, and other QASP-aligned measures. * Participate in status meetings, technical reviews, governance forums, and AO decision support activities; record actions and maintain supporting documentation. * Apply documentation governance, quality-control, naming, version-control, and records-management practices to all assigned work products. * Support COOP, contingency, incident, and mission-continuity activities when requested by the PMO. ## Related Videos - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)