> Markdown version of [/jobs/ext/2461462-jr-cyber-security-analyst-south-dakota](https://www.wearedevelopers.com/jobs/ext/2461462-jr-cyber-security-analyst-south-dakota). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Jr. Cyber Security Analyst - South Dakota - **Company:** P3S Corporation - **Location:** Ellsworth Air Force Base, SD, United States - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Active Directory, Audit Trail, Cyber Security, Decision Support Systems, Linux, Security Information and Event Management, Automated Information System (AIS), Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 8, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=38db7a5f20c97985 ## About the Role * RMF and A&A fundamentals; NIST SP 800-53; DoDI 8510.01; Air Force cybersecurity policy; DISA STIG concepts. * eMASS and ITIPS authorization-artifact management. * Vulnerability assessment, risk analysis, mitigation planning, POA&M management, and continuous monitoring. * Familiarity with approved vulnerability/security monitoring tools such as ACAS/Nessus and comparable enterprise tools. * Working knowledge of Windows/Linux, Active Directory, enterprise infrastructure, and configuration-baseline concepts., * Federal, DoD, or Air Force cybersecurity/RMF support. * Air Force Financial Management, AFFSO, SAF/FM, AFIMSC, or comparable enterprise program environments. * Experience preparing cybersecurity compliance reports, assessment findings, risk summaries, and authorization documentation. ## Description The Jr. Cyber Security Analyst supports enterprise cybersecurity engineering and Risk Management Framework (RMF) lifecycle activities for Department of the Air Force Financial Management systems within the FM Authorizing Official (AO) boundary. Working with senior cybersecurity analysts, ISSOs/ISSMs, system owners, Program Management Offices, engineers, and Government stakeholders, the analyst supports authorization artifacts, vulnerability and risk management, continuous monitoring, remediation tracking, and risk-informed decision support., * Assist with the full RMF lifecycle, including security control selection, implementation, validation, continuous monitoring, and authorization sustainment for assigned FM systems. * Develop, update, and maintain authorization artifacts such as System Security Plans (SSPs), Risk Assessment Reports (RARs), Plans of Action & Milestones (POA&Ms), control documentation, and continuous-monitoring records in eMASS and ITIPS. * Support vulnerability assessments, risk analysis, and development of mitigation strategies; coordinate and track remediation with system owners, PMOs, system administrators, and engineering teams. * Track and report vulnerability trends, remediation status, POA&M closure progress, overdue items, and risk trends for leadership review. * Assist in preparing complete A&A decision staffing packages containing risk analysis, control summaries, mission impact, and recommendations supporting ATO, ATO with Conditions, or Denial decisions. * Support security control assessments and prepare findings documenting gaps, weaknesses, associated risk levels, and recommended remediation strategies. * Maintain FM system inventory/boundary information, including points of contact, authorization status, and ATO expiration information. * Assist with cybersecurity policy, SOP, template, checklist, status-report, briefing, and presentation updates for Government review. * Support DISA STIG implementation/validation, vulnerability-remediation coordination, configuration-baseline compliance, and applicable IAVA/TCNO/security-directive tracking. * Review security alerts, audit logs, vulnerability data, and system events; support cybersecurity incident reporting, documentation, escalation, and investigation support. * Facilitate communication among system owners, security personnel, PMOs, and the FM AO/AODR to resolve information-assurance issues and support governance forums. * Prepare accurate, timely, controlled, and Section 508-compliant cybersecurity documentation and deliverables., * Obtain and maintain the Government-required suitability, access, and security determinations applicable to assigned duties and comply with the DD254 and local installation requirements. * Maintain the minimum NACI/Entrance NACI required for personnel using unclassified Government Automated Information Systems (AIS), including email. Personnel with root access to operate, modify, or maintain a Government system must meet the trustworthiness/background-investigation requirement specified by the PWS/DD254. * Complete Air Force-mandated Information Assurance Awareness Training before access to Government computing resources and maintain required DD Form 2875 System Authorization Access Request documentation. * Obtain and properly display required CAC, Restricted Area Badge, contractor identification, and other installation credentials as applicable. * Immediately report known or suspected security violations or incidents and assist Government security-related inquiries or investigations as directed. * Protect Personally Identifiable Information (PII) in accordance with NIST SP 800-122 and comply with the Privacy Act, applicable Air Force security directives, Government-resource restrictions, and consent-to-monitoring requirements. * Complete the required Contractor Employee Non-Disclosure Agreement and use Government-furnished systems and resources for authorized official business only. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Software Developer Salary in South Africa](https://www.wearedevelopers.com/magazine/232-software-developer-salary-in-south-africa) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Frontend Developer Salary in South Africa](https://www.wearedevelopers.com/magazine/234-frontend-developer-salary-in-south-africa) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)