Journeyman Cybersecurity Analyst
GovCIO
Alexandria, VA, United States
11 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$130,000.0
Working hours
Regular working hours
Job source
Tech stack
Audit Trail
Cyber Security
Identity and Access Management
Security Content Automation Protocol
SC Clearance
Infrastructure Automation Frameworks
Nessus
Plan of Action and Milestones
Vulnerability Analysis
Job description
The Journeyman Cybersecurity Analyst will serve as a key technical contributor for system security compliance and risk management. Core responsibilities include:
- Support IA/ISSO artifacts by developing, updating, and maintaining Risk Management Framework (RMF) documentation, System Security Plans (SSP), and Security Assessment Reports (SAR).
- Coordinate vulnerability tickets through tracking, prioritizing, and managing Plan of Action and Milestones (POA&M) items to closure.
- Engage stakeholders for implementation of security controls, collaborating with system owners and engineers to resolve outstanding security findings.
- Monitor compliance metrics across enterprise systems using automated vulnerability scanners and configuration management tools.
- Assess system vulnerabilities by reviewing NessACAS scans, STIG checklists, and Security Content Automation Protocol (SCAP) results.
- Facilitate continuous monitoring activities to ensure systems maintain their Authorization to Operate (ATO) status.
- Analyze audit logs and security alerts to identify potential compliance gaps or unauthorized system modifications.
- Draft technical reports and briefings regarding system risk posture for leadership and external authorization authorities.
Requirements
High School with 6 - 9 years (or commensurate experience), * Certifications: DoD 8570 IAT Level II or higher (e.g., Security+ CE, CySA+, or vendor-specific identity certifications).
- Hands-on experience drafting, managing, and maintaining federal IA/ISSO artifacts within the NIST SP 800-37 RMF pipeline.
- Proven track record tracking vulnerability tickets, managing POA&Ms, and driving technical remediation schedules.
- Strong communication skills required to actively engage technical and non-technical stakeholders for security control implementation.
Clearance Level: Must have an active Secret clearance
Preferred Skills & Experience
- Prior experience supporting U.S. Coast Guard (USCG) or Department of Homeland Security (DHS) identity management programs.
- Familiarity with enterprise tools such as Enterprise Mission Assurance Support Service (eMASS) or Archer.
- Direct experience interpreting ACAS/Nessus vulnerability scans and applying DISA STIGs..
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
17 days ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago