> Markdown version of [/jobs/ext/2600868-sr-cyber-security-analyst-south-dakota](https://www.wearedevelopers.com/jobs/ext/2600868-sr-cyber-security-analyst-south-dakota). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SR. Cyber Security Analyst - South Dakota - **Company:** P3S Corporation - **Location:** Ellsworth Air Force Base, SD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Configuration Management, Cyber Security, Databases, IBM DB2, Decision Support Systems, Linux, IBM Websphere Application Server, Package Management Systems, Software Vulnerability Management, Automated Information System (AIS), Nutanix, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 8, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ef90f55739e523d7 ## About the Role * Advanced RMF/A&A lifecycle leadership, NIST SP 800-53, DoDI 8510.01, Air Force cybersecurity policy, and DISA STIG implementation/validation. * Advanced eMASS and ITIPS authorization-package management. * Enterprise vulnerability and risk management, mitigation strategy development, POA&M governance, and continuous monitoring. * Risk-informed AO decision support, Mission Impact Assessments, security control assessment findings, and executive briefings. * Working knowledge of Windows/Linux, Active Directory, DB2, IBM WebSphere, Nutanix-based infrastructure, and cross-domain cybersecurity dependencies relevant to FMWF., * Air Force enterprise cybersecurity and Financial Management systems. * AFFSO, SAF/FM, AFIMSC, FM AO/AODR, or comparable DoD authorization environments. * Leadership of multi-system RMF portfolios, authorization decisions, enterprise compliance reporting, and cybersecurity governance forums. ## Description The Sr Cyber Security Analyst IV serves as a senior cybersecurity engineer and RMF lead supporting all systems within the DAF Financial Management AO boundary. The position provides expert advisory support to the FM AO, AODR, Program Offices, system owners, and engineering teams; translates Federal, DoD, and Air Force cybersecurity policy into actionable implementation guidance; leads authorization lifecycle activities; and delivers risk-informed decision support for enterprise FM systems., * Lead and support the full RMF lifecycle, including security control selection, implementation, validation, continuous monitoring, authorization, and authorization sustainment across multiple FM systems. * Provide expert advisory support to the FM AO, AODR, and Program Offices regarding compliant application of Federal, DoD, and Air Force cybersecurity policy; translate policy into actionable enterprise implementation guidance. * Develop, manage, quality-review, and sustain authorization artifacts including SSPs, RARs, POA&Ms, control evidence, assessment artifacts, and continuous-monitoring documentation in eMASS and ITIPS. * Conduct vulnerability assessments, perform risk analysis, design mitigation strategies, and coordinate remediation with system owners and PMOs across the FM portfolio. * Track, analyze, and report enterprise-wide vulnerability trends, remediation status, POA&M closure rates, overdue items, and systemic risks to FM leadership. * Generate comprehensive A&A decision staffing packages with risk analysis, control summaries, mission impact, and formal recommendations supporting ATO, ATO with Conditions, or Denial decisions. * Prepare AO decision-support materials and Mission Impact Assessments and brief the AO, FM leadership, working groups, and governance forums. * Lead or support security control assessments and produce findings reports identifying gaps, weaknesses, risk levels, and recommended remediation strategies. * Maintain or oversee FM systems inventory and boundary documentation, authorization status, key contacts, and ATO expiration data. * Draft or update FM-level cybersecurity policies, SOPs, templates, checklists, guidance, and compliance documentation for Government review. * Support configuration baseline integrity, patch/vulnerability remediation, and implementation tracking for IAVAs, TCNOs, and related security directives. * Coordinate cybersecurity requirements with infrastructure, database, systems administration, configuration-management, and development/test functions and validate security impacts of system changes. * Analyze security events, audit data, vulnerability information, and suspicious activity; support incident analysis, reporting, escalation, and Government investigations. * Prepare annual cybersecurity program reviews, leadership briefings, status reports, metrics, strategic recommendations, and Section 508-compliant deliverables., * Obtain and maintain the Government-required suitability, access, and security determinations applicable to assigned duties and comply with the DD254 and local installation requirements. * Maintain the minimum NACI/Entrance NACI required for personnel using unclassified Government Automated Information Systems (AIS), including email. Personnel with root access to operate, modify, or maintain a Government system must meet the trustworthiness/background-investigation requirement specified by the PWS/DD254. * Complete Air Force-mandated Information Assurance Awareness Training before access to Government computing resources and maintain required DD Form 2875 System Authorization Access Request documentation. * Obtain and properly display required CAC, Restricted Area Badge, contractor identification, and other installation credentials as applicable. * Immediately report known or suspected security violations or incidents and assist Government security-related inquiries or investigations as directed. * Protect Personally Identifiable Information (PII) in accordance with NIST SP 800-122 and comply with the Privacy Act, applicable Air Force security directives, Government-resource restrictions, and consent-to-monitoring requirements. * Complete the required Contractor Employee Non-Disclosure Agreement and use Government-furnished systems and resources for authorized official business only. ## Related Videos - [Data Fabric in Action - How to enhance a Stock Trading App with ML and Data Virtualization](https://www.wearedevelopers.com/videos/253-data-fabric-in-action-how-to-enhance-a-stock-trading-app-with-ml-and-data-virtualization) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)