> Markdown version of [/jobs/ext/2732551-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/2732551-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** CALIBRE Systems Inc. - **Location:** Weymouth, MA, United States - **Experience:** Expert - **Salary:** $89,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Cyber Security, Information Systems, Databases, Disaster Recovery, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Information Technology, Network Server, Vulnerability Analysis - **Published:** September 5, 2026 - **Apply:** https://www.wayup.com/i-j-Residential-Rehab-Educator-Aspire-Health-Alliance-342855809310339/ ## About the Role · Working knowledge of NIST RMF, eMASS, DISA STIGs/SRGs, ACAS, POA&Ms, and DoD cybersecurity policies. · Ability to analyze vulnerability data, document findings, support risk mitigation, and communicate technical information to Government stakeholders. · Familiarity with cloud security monitoring, SIEM tools, incident response processes, and compliance reporting. Desired Skills and Qualifications: · Master's degree in Information Technology, Cybersecurity, Information Assurance, or a related field. · DoD 8570/8140-aligned certification such as Security+ CE, CySA+, or equivalent · Experience supporting DoD agencies with cybersecurity, information assurance, vulnerability management, or RMF activities. · Active Top Secret clearance · Experience with eMASS or other compliance tracking platforms. · Familiarity with cloud security controls and cloud-based compliance requirements. · Understanding of Zero Trust principles and cybersecurity modernization strategies. Required Experience · Bachelor's degree in Information Technology, Cybersecurity, Information Assurance, or a related field. · Active Secret security clearance. · 5+ years of experience in cybersecurity, RMF support, compliance, or information assurance. · Experience supporting Federal agencies with cybersecurity, information assurance, vulnerability management, or RMF activities. * Qualifications · Working knowledge of NIST RMF, eMASS, DISA STIGs/SRGs, ACAS, POA&Ms, and DoD cybersecurity policies. · Ability to analyze vulnerability data, document findings, support risk mitigation, and communicate technical information to Government stakeholders. · Familiarity with cloud security monitoring, SIEM tools, incident response processes, and compliance reporting. Desired Skills and Qualifications: · Master's degree in Information Technology, Cybersecurity, Information Assurance, or a related field. · DoD 8570/8140-aligned certification such as Security+ CE, CySA+, or equivalent · Experience supporting DoD agencies with cybersecurity, information assurance, vulnerability management, or RMF activities. · Active Top Secret clearance · Experience with eMASS or other compliance tracking platforms. · Familiarity with cloud security controls and cloud-based compliance requirements. · Understanding of Zero Trust principles and cybersecurity modernization strategies. ## Description CALIBRE Systems, Inc., an employee-owned mission focused solutions and digital transformation company, is looking for a highly qualified Journeyman Information Security Analyst to support a DoD client with enterprise cybersecurity for a large program serving military families. This position will be hybrid with some required meetings in Alexandria, VA. The role combines cybersecurity operations, compliance, vulnerability management, incident response, and Risk Management Framework (RMF) activities for Department of Defense cloud and information systems. The analyst will help maintain compliance with DoD, DISA, U.S. Cyber Command, MC&FP, NIST RMF, Zero Trust, STIG/SRG, ACAS, and eMASS requirements while supporting the attainment and sustainment of Government-issued Authorizations to Operate (ATOs). An active TOP Secret clearance is required for this role. Salary range for this position is $89k-$110k, · Support RMF documentation, security control implementation, assessment activities, and ATO sustainment using the DoD enterprise eMASS platform. · Conduct weekly DISA STIG/SRG and ACAS vulnerability assessments, assist with remediation tracking, and prepare raw scan outputs, weekly threat reports, and ACAS roll-up reports. · Maintain and update Plans of Action and Milestones (POA&Ms), collect evidence of completion, and coordinate validation with ISSM, ISSO, and Security Control Assessment teams. · Monitor cybersecurity resources, SIEM-integrated logs, anomaly indicators, account aging, compliance status, WAF/NGFW activity, and GovCloud logs; escalate abnormal findings within required timelines. · Support daily review of the DC3 Vulnerability Disclosure Program portal and assist with creation and mitigation of associated POA&Ms. · Assist with vulnerability assessments and penetration testing for new or modified applications, servers, databases, and infrastructure components before deployment. · Support incident reporting, documentation, and coordination with the Incident Response Team and Tier 2 Cybersecurity Service Provider. · Contribute to weekly cybersecurity activity reporting, including compliance status, vulnerability assessments, incident management, and risk metrics. · Support contingency planning, disaster recovery exercises, SOP audits, and cybersecurity exercise activities as directed. · Access SIPRNet and attend classified briefings at the Government facility in Alexandria, Virginia, as required. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)