> Markdown version of [/jobs/ext/2124340-journeyman-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/2124340-journeyman-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Journeyman Cybersecurity Analyst - **Company:** GovCIO - **Location:** Alexandria, VA, United States - **Experience:** Expert - **Salary:** $130,000.0 - **Contract:** Permanent contract - **Skills:** Audit Trail, Cyber Security, Identity and Access Management, Security Content Automation Protocol, SC Clearance, Infrastructure Automation Frameworks, Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 19, 2026 - **Apply:** https://www.dice.com/job-detail/b0d5fd85-6a6d-401a-bf98-d8d23baeba01 ## About the Role High School with 6 - 9 years (or commensurate experience), * Certifications: DoD 8570 IAT Level II or higher (e.g., Security+ CE, CySA+, or vendor-specific identity certifications). * Hands-on experience drafting, managing, and maintaining federal IA/ISSO artifacts within the NIST SP 800-37 RMF pipeline. * Proven track record tracking vulnerability tickets, managing POA&Ms, and driving technical remediation schedules. * Strong communication skills required to actively engage technical and non-technical stakeholders for security control implementation. Clearance Level: Must have an active Secret clearance Preferred Skills & Experience * Prior experience supporting U.S. Coast Guard (USCG) or Department of Homeland Security (DHS) identity management programs. * Familiarity with enterprise tools such as Enterprise Mission Assurance Support Service (eMASS) or Archer. * Direct experience interpreting ACAS/Nessus vulnerability scans and applying DISA STIGs.. ## Description The Journeyman Cybersecurity Analyst will serve as a key technical contributor for system security compliance and risk management. Core responsibilities include: * Support IA/ISSO artifacts by developing, updating, and maintaining Risk Management Framework (RMF) documentation, System Security Plans (SSP), and Security Assessment Reports (SAR). * Coordinate vulnerability tickets through tracking, prioritizing, and managing Plan of Action and Milestones (POA&M) items to closure. * Engage stakeholders for implementation of security controls, collaborating with system owners and engineers to resolve outstanding security findings. * Monitor compliance metrics across enterprise systems using automated vulnerability scanners and configuration management tools. * Assess system vulnerabilities by reviewing NessACAS scans, STIG checklists, and Security Content Automation Protocol (SCAP) results. * Facilitate continuous monitoring activities to ensure systems maintain their Authorization to Operate (ATO) status. * Analyze audit logs and security alerts to identify potential compliance gaps or unauthorized system modifications. * Draft technical reports and briefings regarding system risk posture for leadership and external authorization authorities. ## Related Videos - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [How One Developer Built the Back Office for 10 Million Companies](https://www.wearedevelopers.com/videos/100082-how-one-developer-built-the-back-office-for-10-million-companies) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)