> Markdown version of [/jobs/ext/2727841-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/2727841-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - **Company:** General Dynamics Corp - **Location:** Colorado Springs, CO, United States - **Experience:** Experienced - **Salary:** $125,275.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Computer-Aided Audit Tools, Static Program Analysis, CompTIA Security+, Cyber Security, Dynamic Program Analysis, Network Topologies, Identity and Access Management, Systems Analysis, Networking Hardware, Internet Security, Machine Learning, Network Configuration and Change Management, Red Hat Enterprise Linux, Fortify (Software), Security Content Automation Protocol, SonarQube, System Testing, Virtual Environment, National Industrial Security Program Operating Manual (NISPOM), Plan of Action and Milestones, Vulnerability Analysis, User Accounts - **Published:** September 5, 2026 - **Apply:** https://www.careerbuilder.com/job-details/26-205-c2bmc-cyber-a-a-engr-colorado-springs-co--599f5a35-b514-4055-86ff-7631cc7fb852 ## About the Role Bachelor's degree in Engineering, or a related Science or Mathematics field, plus a minimum of 5 years of relevant experience; or Master's degree plus a minimum of 3 years of relevant experience., * 3+ years of related experience and/or post-secondary degree in a relevant discipline. * Active TS/SCI clearance required. * IAT Level II/IAM Level I DoD 8570 certification (e.g., Security+ CE or equivalent). * Strong security engineering skills with knowledge of cybersecurity technology and DoD/Federal policies (e.g., DoDI 8500.01, NIST SP 800-53)., * Proficiency in Enterprise Mission Assurance Support Service (eMASS). * In-depth understanding of the RMF Cybersecurity Lifecycle, including controls, overlays, requirements generation, architecture design, audit tools, and compliance assessments. * Knowledge of Software Assurance (SwA) tools for static and dynamic code analysis (e.g., Fortify, SonarQube). Preferred Qualifications * Experience with Windows and Red Hat Enterprise Linux (RHEL) system administration. * Background in working within virtual environments, dockers, and containers. * Proficiency in administering ACAS and Endpoint Security Solutions (ESS). * Experience using ConfigOS for system hardening. * Experience working with or familiarity with Al/ML models is preferred. * Identifies opportunities to apply Al for continuous improvement and innovation. Join our team to enhance the cybersecurity posture of mission-critical systems and make a significant impact. Apply today!, Analysis Skills, Architectural Design, Auditing, CompTIA Security+, Computer Security, Continuous Improvement, Customer Support/Service, Detail Oriented, DoD Directive 8140, DoD Directive 8570, Documentation, Documentation Plan, Dynamic Analysis, Endpoint Security, Engineering, Environmental Compliance, Government Policies, IAM - Information Assurance Management, Internet Security, Maintain Compliance, Mathematics, Microsoft Windows Operating System, Network Configuration Management, Network Performance/Analysis, Network System Hardware, Network Topology, Policy Implementation, Process Improvement, Red Hat Linux Operating System, Regulatory Compliance, Risk Management, Risk Management Framework (RMF), Sensitive Compartmented Information (SCI), System Validation, Systems Administration/Management, Systems Analysis, Test Plan/Schedule, Testing, Top Secret Clearance, U.S. National Institute of Standards and Technology (NIST), United States Department of Defense (DoD), User Account Administration ## Description We are seeking a detail-oriented Cybersecurity Analyst to support critical cybersecurity initiatives. This position involves managing user accounts, conducting system assessments, performing Security Technical Implementation Guide (STIG) assessments, and supporting Risk Management Framework (RMF) activities. The ideal candidate will possess strong technical expertise in cybersecurity practices, compliance audits, and risk mitigation processes within DoD environments., * Manage and track DD Form 2875 user account forms and training for privileged and non-privileged accounts, including annual account validations and coordination with system administrators for account creation, modification, and removal. * Assess systems and networks in virtual environments for compliance with configurations, policies, and standards using tools like STIG Viewer, SCAP, and ACAS. * Perform Security Technical Implementation Guide (STIG) assessments and hardening for Windows, Red Hat Enterprise Linux (RHEL), and networking equipment using ConfigOS. * Develop test plans and document expected outcomes of STIG checks. * Update RMF documentation to ensure non-compliance issues are tracked and remediated. * Implement government cybersecurity policies (e.g., NISPOM, NIST, DoD) and recommend process improvements. * Conduct compliance audits, vulnerability assessments, and periodic reviews of systems to validate cybersecurity controls. * Prepare and maintain RMF artifacts, including Test Results (TR), Authorization Boundary Diagrams (ABD), Network Topologies, Ports, Protocols, and Services Management documentation, and Plan of Actions and Milestones (POA&M). ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Automated Code Quality Checks with Custom SonarQube Rules](https://www.wearedevelopers.com/videos/428-automated-code-quality-checks-with-custom-sonarqube-rules) - [How To Test A Ball of Mud](https://www.wearedevelopers.com/videos/173-how-to-test-a-ball-of-mud) - [Full-stack role-based authorization in 45 minutes](https://www.wearedevelopers.com/videos/312-full-stack-role-based-authorization-in-45-minutes) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Practical tips for keeping your C# code base clean](https://www.wearedevelopers.com/videos/100149-practical-tips-for-keeping-your-c-code-base-clean) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)