> Markdown version of [/jobs/ext/2732731-cybersecurity-support-specialist](https://www.wearedevelopers.com/jobs/ext/2732731-cybersecurity-support-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Support Specialist - **Company:** The Nook - **Location:** Arlington, United States - **Experience:** Experienced - **Salary:** $90,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Antivirus Softwares, CompTIA Security+, Cyber Security, Information Systems, Linux, Role-Based Access Control, Security Content Automation Protocol, Security Information and Event Management, Software Vulnerability Management, Information Technology, Tenable Nessus, Splunk, ManageEngine, Vulnerability Analysis, User Accounts - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/cybersecurity-support-specialist-nooks-company-9857801 ## About the Role * 2-5 years of experience in cybersecurity or system administration. * DoD 8140.03/8570.01 Information Assurance Technical (IAT) Level II certification (e.g., CompTIA Security+), or the ability to obtain one within six months of hire. * Hands-on experience with DISA STIGs and tools such as the Security Content Automation Protocol (SCAP) Compliance Checker and STIG Viewer. * Familiarity with access control, vulnerability management, and system hardening, plus Active Directory - including Group Policy Object (GPO) and Organizational Unit (OU) structure. * Foundational knowledge of Windows and Linux operating systems, networking, and common IT troubleshooting practices. * Associate's or Bachelor's degree in Cybersecurity, Information Technology, or a related field - or equivalent practical experience. * Strong documentation habits, attention to detail, and clear communication across IT and security functions. Preferred: * Familiarity with monitoring and scanning tools such as Tenable Nessus, ManageEngine, Splunk, antivirus platforms (e.g., ESET, Trellix), and other vulnerability and security information and event management (SIEM) tools. * Prior DoW or cleared-environment exposure. Eligibility & Clearance Candidates must be eligible to work in the United States and capable of maintaining eligibility up to the Top Secret/Sensitive Compartmented Information (TS/SCI) level within 45 days of hire. ## Description Accredited systems generate a constant stream of security work - scans to run, findings to track, documentation to keep current, users to support. As Cybersecurity Support Specialist, you will keep that work moving at a single Nooks site, supporting the security and compliance of classified and unclassified systems alongside the site's Cybersecurity Lead. You will bring two to five years of hands-on practice to a specialist seat, reporting to the Site IT/Cyber Manager as an individual contributor. Our procedures are real but still maturing - audits, incidents, and new system standups will reshuffle your week, and you will step in wherever the site's security posture needs attention without waiting to be asked., Security Monitoring & Vulnerability Management * Conduct vulnerability scanning, patch verification, and security configuration checks under the direction of the site Cybersecurity Lead. * Monitor and audit the security posture of classified and unclassified systems, applying Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs). * Track findings and remediation actions to closure, documented to organizational and Department of Defense (DoD) standards. Compliance Documentation & Support * Maintain cybersecurity documentation - System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), audit logs, and standard operating procedures. * Record compliance actions and evidence so the site is ready for audits and self-inspections at any time. * Keep artifacts organized so the Cybersecurity Lead can hand assessors current documentation on demand. User Support & Access Control * Provide Tier 1 support for cybersecurity-related user requests, escalating issues that need deeper analysis. * Manage user accounts, security groups, and permissions in partnership with the site's IT Support Specialist - you both work in this space, so clean records and communication matter. * Support permissions reviews and the implementation of access control policies, including role-based access control. Incident Response & Security Awareness * Participate in incident response and continuous monitoring - log collection, basic analysis, and security control status reporting. * Reinforce cybersecurity best practices with end users through daily interactions. * Collaborate with IT, personnel security, and physical security teams to keep site operations compliant with DoW requirements. What Success Looks Like in This Role Twelve months in, the site's routine security workload - scans, checks, and documentation upkeep - runs on schedule with little prompting. The SSPs, POA&Ms, and audit artifacts you maintain are current enough to hand straight to an assessor. Tier 1 cybersecurity requests get resolved or escalated cleanly, and account and permissions records stay accurate through every review. Handoffs with the IT Support Specialist are smooth because the shared account work is documented and coordinated. The Cybersecurity Lead trusts your work enough to build audit responses on top of it. Cross-Functional Expectations Inside IT/Cyber, you will work most closely with your site's Cybersecurity Lead and IT Support Specialist, coordinating daily on shared account and access work. You will partner with Security on personnel and physical security touchpoints, and support Operations, specifically the Site Lead, for site activities. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)