> Markdown version of [/jobs/ext/2178258-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/2178258-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - **Company:** SHR CONSULTING GROUP, LLC - **Location:** Arlington, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Excel, Microsoft Windows, Cyber Security, Computer Engineering, System Configuration, Javaserver Pages, Lookup Table, System Center Configuration Manager, Windows Servers, Pivot Tables, Windows PowerShell, Red Hat Enterprise Linux, Security Content Automation Protocol, Microsoft SharePoint, Software Vulnerability Management, Firewalls (Computer Science), SC Clearance, Tanium Platform Expertise, Information Technology, CIS Benchmarks, Splunk, Vulnerability Analysis - **Published:** August 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9111644/cybersecurity-analyst ## About the Role * Demonstrated ability and experience in daily operations and maintenance of large, complex IT projects and IT staff similar in size and scope to this order * Three (3) or more years of experience securing operating systems against DISA STIGs and configuring/maintaining host firewalls; experience hardening Windows Server and Red Hat Linux platforms required. * Working knowledge of the DoD IAVM program, the DISA Vulnerability Management System (VMS), and the Continuous Monitoring Risk Scoring (CMRS) system. * Knowledge of DoD vulnerability scanning standards and tools, defense-in-depth concepts, and incident response, auditing, and CNDSP practices. * Hands-on experience with cyber tools, including HBSS/ESS, ACAS (Tenable), Splunk, and Tanium. * Experience supporting RMF (NIST SP 800-37), NIST SP 800-53R control documentation and validation, and accreditation programs such as FISMA, OMB, DoD IG inspections, and ACA. * Experience deploying patches and hot fixes against required deadlines using MECM, Group Policy, PowerShell, Red Hat Satellite/YUM, or Tanium. * For the Senior variant: 5+ years of experience and ACAS administrator certification/experience are strongly preferred. * Strong analytical, written, and verbal communication skills with the ability to brief technical risk to Government leadership. Education * Bachelor's degree in Computer Engineering, Computer Information Systems, Telecommunications, Management Information Systems, Cybersecurity, or a related field; or equivalent combination of education and three (3)+ recent years of documented relevant experience. Certification Requirements * Must meet DoD 8570.01-M / DoD 8140 IAT Level II baseline certification requirements prior to start (e.g., Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, or equivalent). Computing Environment certification appropriate to the role is also required. Security Clearance * Active Secret clearance required at minimum. U.S. citizenship required. ## Description We are a rapidly growing organization seeking experienced Cybersecurity Analysts to support cyber compliance, technical security assessments, vulnerability management, cyber hardening, and Risk Management Framework (RMF) activities for a large enterprise Department of Defense environment. Multiple openings are available at Senior and Intermediate levels., * Perform technical cybersecurity assessments of enterprise Windows, Red Hat Linux, workstation, server, application, network, and supporting infrastructure environments. * Analyze and validate findings from ACAS, HBSS/ESS, Trellix, Axonius, Evaluate-STIG, Splunk, Tanium, SCAP, STIG Viewer, and other approved Enterprise Security Services (ESS) tools. * Assess systems against DISA STIGs, IAVM notices, DoD cyber tasking, and approved security baselines; identify vulnerabilities, configuration deviations, missing patches, security-tool coverage gaps, and asset discrepancies. * Coordinate with system administrators, engineers, system owners, and platform teams to implement and validate patches, Group Policy changes, certificate updates, endpoint-security changes, and secure-configuration remediations. * Drive assigned systems toward compliance with DISA STIGs, IAVMs, applicable DoD orders, and organizational remediation timelines. * Develop, maintain, and track Plans of Action and Milestones (POA&Ms) for unresolved vulnerabilities and compliance deviations, including technical details, risk impact, mitigation actions, responsible parties, milestones, and planned completion dates. * Support RMF activities in accordance with DoDI 8510.01 and NIST guidance, including eMASS updates, control implementation statements, evidence collection, security-control validation, assessment artifacts, risk records, and authorization-package support. * Validate security controls against NIST SP 800-53 requirements and document results in eMASS, SharePoint, or other approved repositories. * Support CCORI, CORA, CSSP, and Cyber Hardening Mission activities through pre-assessment validation, checklist management, evidence preparation, corrective-action tracking, remediation coordination, and closure verification. * Monitor approved DoD, DISA, JSP, and organizational channels for IAVMs, cyber orders, security directives, and other tasking; disseminate actions to responsible teams and track execution through closure. * Provide DTO support by reviewing, analyzing, coordinating, tracking, and validating closure of DISA Task Orders, including required security configuration changes, firewall-rule updates, ports/protocols/services changes, vulnerability mitigations, technical documentation, validation testing, and completion evidence in accordance with established DoD, DISA, JSP, and program procedures. * Maintain and validate required security-tool coverage across managed assets, ensuring ESS/HBSS, ACAS, Splunk, Tanium, and other required tools are installed, properly configured, communicating with management consoles, and tracked to resolution when reporting issues occur. * Support patch and hot-fix deployment across multiple operating-system platforms using MECM, Group Policy, PowerShell, Tanium, Red Hat Satellite Server, YUM, or equivalent enterprise-management tools. * Develop cyber-compliance metrics, remediation trackers, dashboards, and executive-ready reports for monthly program reviews and leadership briefings. * Apply advanced Microsoft Excel skills-including formulas, pivot tables, XLOOKUP/VLOOKUP, conditional logic, data reconciliation, charts, and trend analysis-to evaluate vulnerability trends, compliance posture, risk scores, overdue actions, and remediation performance. * Brief technical teams, program management, and Government leadership on technical findings, enterprise risk, compliance trends, remediation status, and decisions required. * Support Systems Security Reviews, independent control testing, audit preparation, inspection response, and continuous-monitoring activities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Is it still C#? Practical systems programming with .NET (war stories included)](https://www.wearedevelopers.com/videos/100138-is-it-still-c-practical-systems-programming-with-net-war-stories-included) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Graphs and RAGs Everywhere... But What Are They? - Andreas Kollegger - Neo4j](https://www.wearedevelopers.com/videos/1311-graphs-and-rags-everywhere-but-what-are-they-andreas-kollegger-neo4j) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)