> Markdown version of [/jobs/ext/2243149-hybrid-security-analyst](https://www.wearedevelopers.com/jobs/ext/2243149-hybrid-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # hybrid Security Analyst - **Company:** Motion Recruitment Partners LLC. - **Location:** Herndon, VA, United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Java (Programming Language), Amazon Web Services, Automation of Tests, Bash Shell, Cloud Computing, Cloud Computing Security, Information Systems, Continuous Integration, Data Systems, Python (Programming Language), Windows Servers, Windows PowerShell, Red Hat Enterprise Linux, Data Streaming, Software Vulnerability Management, Scripting, Enterprise Software Applications, Cloud Platform System, Containerization, Tenable Nessus, Service Stack, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 26, 2026 - **Apply:** https://www.dice.com/job-detail/7f3bf8f1-82a6-4626-9d65-dcd50ec13955 ## About the Role * Deep understanding and documentation of information system specifications and security controls (logical/physical diagrams, data flow) * Application of enterprise security frameworks, including FISMA and NIST SP 800, especially for cloud environments * Knowledge of Risk-Based Vulnerability Framework and vulnerability prioritization/remediation * Ability to create automation scripts to minimize manual workload (Python, Bash, Java, PowerShell) * Experience analyzing container vulnerabilities and remediation paths (OS and App level) * Familiarity with current FedRAMP, DoD, and NIST controls, including vulnerability management Desired Skills & Experience * Experience creating automation scripts (Python, Bash, Java, PowerShell) * Knowledge of container scanning tools, CI/CD pipelines, AWS ECR, Container Image Mirroring * Understanding attack vectors and vulnerability exploitability in complex environments * Strong knowledge of Federal/DoD policies and risk methodologies: FedRAMP, NIST SPs, RMF overlays * Hands-on experience with DISA STIGs and SRGs, CNSSI, NIST RMF * Experience drafting/executing security documentation, ATO packages, POA&Ms, policies ## Description Our client is a software company based in Herndon, VA that provides secure cloud enterprise software and data solutions for the US government, defense, and intelligence community. They are hiring for a hybrid Security Analyst (3 days on-site) to maintain cybersecurity and regulatory compliance within their cloud enterprise environments using FedRAMP. The technology stack includes Red Hat Linux, Windows Servers, containerization, and automation. This is an opportunity to build secure cloud environments for government and defense clients. You'll work with advanced technologies, support critical compliance initiatives, and collaborate with teams. They're looking for someone with experience in federal compliance, automation scripting, and vulnerability management in cloud environments., * Creating, updating, and maintaining FedRAMP-required security documentation and compliance artifacts * Assisting with continuous compliance monitoring, including POA&M management and corrective actions * Advising stakeholders on evolving government and cloud security policies and requirements * Identifying, prioritizing, and remediating system vulnerabilities across cloud and enterprise environments * Automating cybersecurity processes with scripting (Python, Bash, PowerShell, etc.) * Collaborating with Cloud Operations and cybersecurity teams to ensure ongoing compliance and security maturity ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From Messy Queries to Scalable Systems - How Data Engineering actually works](https://www.wearedevelopers.com/videos/100203-from-messy-queries-to-scalable-systems-how-data-engineering-actually-works) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [The Data Mesh as the end of the Datalake as we know it](https://www.wearedevelopers.com/videos/156-the-data-mesh-as-the-end-of-the-datalake-as-we-know-it) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)