> Markdown version of [/jobs/ext/1953853-cybersecurity-analyst-level-2-or-3](https://www.wearedevelopers.com/jobs/ext/1953853-cybersecurity-analyst-level-2-or-3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - Level 2 or 3 - **Company:** Northrop Grumman - **Location:** Boulder, CO, United States - **Experience:** Experienced - **Salary:** $91,800.0 - $137,600.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Security Information and Event Management, National Industrial Security Program Operating Manual (NISPOM), Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 6, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9080864/cybersecurity-analyst-level-2-or-3 ## About the Role * Bachelor's degree with 2 years of relevant experience; Master's degree with 0 years of relevant experience. An additional 4 years of relevant experience may be considered in lieu of a degree. * Active Top Secret clearance required at time of application and ability to obtain SCI * DoD 8570-M/DoD 8140 IAT Level II or higher certification, * Bachelor's degree with 5 years of relevant experience; Master's degree with 3 years of relevant experience; PhD with 0 years of relevant experience. An additional 4 years of relevant experience may be considered in lieu of a degree. * Active Top Secret clearance required at time of application and ability to obtain SCI * DoD 8570-M/DoD 8140 IAT Level II or higher certification, * Familiarity with Risk Management Framework * Familiarity with DISA STIGs * Familiarity with ACAS * Familiarity with SIEM Management ## Description * Perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy. This is achieved through passive evaluations such as compliance audits and active evaluations such as vulnerability assessments. * Establishes strict program control processes to ensure mitigation of risks and supports obtaining certification and accreditation of systems. Includes support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction and release, emerging technology research inspections and periodic audits. * Assist in the implementation of the required government policy (i.e., NISPOM, DCID 6-3), make recommendations on process tailoring, participate in and document process activities. * Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards. * Support the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results and preparation of required reports. * Document the results of Certification and Accreditation activities and technical or coordination activity and prepare the system Security Plans and update the Plan of Actions and Milestones POA&M. Periodically conduct a complete review of each system's audits and monitor corrective actions until all actions are closed. *Please be aware that this position is contingent upon capturing program award(s) and obtaining and maintaining associated business and/or customer funding. Furthermore, this position is contingent upon the candidate obtaining final clearances and program access(es) within a reasonable period of time as determined by the company. Continued employment thereafter will be subject to maintenance at the level of clearance and program access required for the position in the future* ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Beyond the Numbers: Engineering Recruiting Excellence Through Quality, Data, and Team Empowerment](https://www.wearedevelopers.com/videos/1491-beyond-the-numbers-engineering-recruiting-excellence-through-quality-data-and-team-empowerment) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)