> Markdown version of [/jobs/ext/2004772-systems-security-analyst](https://www.wearedevelopers.com/jobs/ext/2004772-systems-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Systems Security Analyst - **Company:** MAGNUS MANAGEMENT GROUP, LLC - **Location:** Santa Rita, United States - **Contract:** Permanent contract - **Skills:** Configuration Management, Information Systems Security Engineering Professional, Log Analysis, Security Content Automation Protocol, Software Vulnerability Management, SC Clearance, Plan of Action and Milestones - **Published:** August 9, 2026 - **Apply:** https://www.wayup.com/i-j-Systems-Security-Analyst-Magnus-Management-Group-LLC-030637514455979/ ## About the Role Must be a US Citizen Must hold Secret Clearance Minimum of five years of RMF experience, including at least one year of specialized experience supporting FRCS RMF and cybersecurity engineering activities At least one current qualifying certification: CCSP, Cloud+, GICSP, GISF, GSEC, or Security+, RCCE Level 1, CISSO, CISSP-ISSEP, CySA+, FITSP-O, GCLD, GCSA, GSNA. ## Description Position Overview We are seeking a Systems Security Analyst to support our client. You will help protect the confidentiality, integrity, and availability of Facility-Related Control Systems by leading security engineering, Risk Management Framework (RMF), vulnerability management, continuous monitoring, and incident response activities. This is a mission-essential, hands-on role for a security professional who can work independently, coordinate across technical and government stakeholders, and turn complex compliance requirements into operational results., Drive the end-to-end RMF lifecycle (Steps 1-6) in accordance with current Department of the Navy and NAVFAC Echelon II guidance; verify artifacts for completeness, quality, and compliance and maintain accurate eMASS packages. Achieve, maintain, and track Authorities to Operate (ATOs) for FRCS; support annual security reviews and prepare Memorandums for Record for approved baseline changes. Develop and maintain security policies, standard operating procedures, and implementation plans mapped to applicable NIST SP 800-53 control families and tailored to the FRCS environment. Execute vulnerability and compliance assessments using approved DoN tools such as ACAS, SCAP, and Evaluate STIG; complete manual STIG/SRG validations and maintain .ckl/.cklb checklists. Prepare Security Center and eMASSter reports for eMASS integration and ensure vulnerability results are accurately uploaded and maintained in VRAM. Sustain system-level continuous monitoring through recurring scans, audit-log analysis, remediation tracking, mitigation, and quarterly POA&M updates. Coordinate and support on-site RMF Step 4 validation, including evidence collection and collaboration with system owners and independent validators. Serve as a technical representative and/or Configuration Management Officer on the Configuration Control Board, providing security-impact analyses and risk assessments for proposed FRCS baseline changes. Support cyber incident response as a member of the MAR Cyber Emergency Response Team, including participation in an on-call rotation and preparation of operational logs and after-action reports. Provide bi-weekly RMF status reports to the ISSM, maintain project records in Maximo and/or eProjects, and contribute to monthly status reporting. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [AI in Regulated Industry - Validating AI-Enabled Products with PLM and Digital Twins](https://www.wearedevelopers.com/videos/2065-ai-in-regulated-industry-validating-ai-enabled-products-with-plm-and-digital-twins) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)