> Markdown version of [/jobs/ext/1930431-senior-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/1930431-senior-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Security Analyst - **Company:** Mantech International Corporation - **Location:** Virginia Beach, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Microsoft Windows, Systems Engineering, C Sharp (Programming Language), C++ (Programming Language), Cyber Security, Information Systems, System Configuration, Linux, Network Topologies, Information Systems Security Architecture Professional, Python (Programming Language), Linux System Administration, Log Analysis, Network Diagrams, Package Management Systems, Systems Development Life Cycle, Security Content Automation Protocol, Data Streaming, TypeScript, Information Security Management System, ReactJS, AngularJS, Information Technology, Nessus, Plan of Action and Milestones, Programming Languages - **Published:** August 5, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9074091/senior-cyber-security-analyst ## About the Role MANTECH seeks a motivated, career and customer-oriented Senior Cyber Security Analyst to join our team in Virginia Beach, VA. This is an onsite position., * Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or related field and 8+ years of combined experience in RMF processes and secure system engineering in DoD environments OR High School Diploma and 11 years of combined experience in RMF processes and secure system engineering in DoD environments * Certified Information Systems Security Professional (CISSP) certification * Security+ CE certification with ACAS and eMASS experience * Experience with Linux and/or Windows * Expertise and hands-on experience in applying DISA STIGs * Hands-on experience with eMASS for RMF package management, POA&M maintenance, and risk assessment, * Familiarity with network topology documentation in air-gapped environments * 2+ years executing full SDLC in DoD environments * Experience with the development in low level (machine) to very high level (abstract, goal oriented) programming languages and frameworks, including C/C++/C#, Python, JavaScript, TypeScript and Angular/React * Certified in CompTIA Linux +, Governance, Risk and Compliance (CGRC), CompTIA SecurityX Clearance Requirements: * Must be a US Citizen and hold an active Secret Security Clearance with ability to obtain Top Secret if required. Physical Requirements: * Must be able to remain in a stationary position 50% of the time. * Needs to occasionally move about inside offices, shipboard spaces, or industrial environments to access equipment and systems. * Frequently communicates with co-workers, management, and customers, and must be able to exchange accurate information in these situations. ## Description As a Senior Cyber Security Analyst, you will provide direct support to the Advance Electronic Systems (AES) team and its customers in support of Risk Management Framework (RMF) activities. This role focuses on security control implementation, assessment, continuous monitoring, and RMF compliance, with primary emphasis on Linux systems and supporting knowledge of Windows environments. You will serve as the point of contact for all cybersecurity-related matters, including security control implementation, documentation, and compliance activities., * Prepare for Risk Management Framework (RMF) execution and perform system categorization by conducting comprehensive mission analysis, defining the authorization boundary with detailed network diagrams, hardware/software inventories, and data flow documentation. Determine mission criticality and apply relevant overlays to establish the appropriate security control baseline per NIST SP 800-53 Rev 5 and DoD/Navy policy * Select, tailor, implement, and assess security controls using DISA STIGs (with emphasis on Linux platforms), SRGs, SCAP, ACAS/Nessus vulnerability scans, and NIST SP 800-53A Assessment Procedures. Perform hands-on configuration, hardening, log analysis, and remediation on Linux systems, while applying equivalent controls and STIGs to Windows endpoints. Execute testing, validate configurations and access controls, document implementation status, test results, and evidence in eMASS, and manage POA&M entries with complete risk analysis * Support system authorization by maintaining a complete and accurate RMF package in eMASS, including the SSP, POA&M, and supporting documentation. Coordinate workflow actions for Authorizing Official decision-making * Conduct continuous monitoring by implementing the System Level Continuous Monitoring (SLCM) Strategy, with focus on Linux system logs and security events alongside Windows endpoint monitoring * Conduct Annual Security Reviews (ASRs) and update the System Security Plan (SSP) and POA&M to reflect changes in risk posture * Provide guidance on RMF compliance, risk management, and security strategies across all RMF steps. * Advise leadership on emerging threats, control gaps, and mitigation priorities, particularly for Linux environments * Retire and decommission systems at end-of-life. Execute data sanitization per DoD 5220.22-M, hardware disposition, and documentation closeout ## Related Videos - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)