Journeyman Cybersecurity Analyst

GovCIO
Alexandria, VA, United States
11 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$130,000.0
Working hours
Regular working hours
Job source

Tech stack

Audit Trail Cyber Security Identity and Access Management Security Content Automation Protocol SC Clearance Infrastructure Automation Frameworks Nessus Plan of Action and Milestones Vulnerability Analysis

Job description

The Journeyman Cybersecurity Analyst will serve as a key technical contributor for system security compliance and risk management. Core responsibilities include:

  • Support IA/ISSO artifacts by developing, updating, and maintaining Risk Management Framework (RMF) documentation, System Security Plans (SSP), and Security Assessment Reports (SAR).
  • Coordinate vulnerability tickets through tracking, prioritizing, and managing Plan of Action and Milestones (POA&M) items to closure.
  • Engage stakeholders for implementation of security controls, collaborating with system owners and engineers to resolve outstanding security findings.
  • Monitor compliance metrics across enterprise systems using automated vulnerability scanners and configuration management tools.
  • Assess system vulnerabilities by reviewing NessACAS scans, STIG checklists, and Security Content Automation Protocol (SCAP) results.
  • Facilitate continuous monitoring activities to ensure systems maintain their Authorization to Operate (ATO) status.
  • Analyze audit logs and security alerts to identify potential compliance gaps or unauthorized system modifications.
  • Draft technical reports and briefings regarding system risk posture for leadership and external authorization authorities.

Requirements

High School with 6 - 9 years (or commensurate experience), * Certifications: DoD 8570 IAT Level II or higher (e.g., Security+ CE, CySA+, or vendor-specific identity certifications).

  • Hands-on experience drafting, managing, and maintaining federal IA/ISSO artifacts within the NIST SP 800-37 RMF pipeline.
  • Proven track record tracking vulnerability tickets, managing POA&Ms, and driving technical remediation schedules.
  • Strong communication skills required to actively engage technical and non-technical stakeholders for security control implementation.

Clearance Level: Must have an active Secret clearance

Preferred Skills & Experience

  • Prior experience supporting U.S. Coast Guard (USCG) or Department of Homeland Security (DHS) identity management programs.
  • Familiarity with enterprise tools such as Enterprise Mission Assurance Support Service (eMASS) or Archer.
  • Direct experience interpreting ACAS/Nessus vulnerability scans and applying DISA STIGs..

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski · World Congress 2026 Europe

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:23 min

Utilizing event sourcing for complete system auditability

Jan Steffen · LIVE

Videos

See all

Related articles

See all