> Markdown version of [/jobs/ext/2736554-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/2736554-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst - **Company:** Scientific Research Corporation - **Location:** Philadelphia, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Microsoft Windows, Antivirus Softwares, Configuration Management, Cyber Security, Information Systems, Computer Networks, Linux, Event Logging, Identity and Access Management, Package Development Process, Red Hat Enterprise Linux, Security Content Automation Protocol, SC Clearance, Information Technology, Nessus - **Published:** September 5, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/84910862/1 ## About the Role * Must possess an active Secret clearance at the minimum * A minimum of five (5) years of cybersecurity experience * Must currently hold a DoD 8570-compliant IAT II certification (SSCP or Security+CE with appropriate CE/OS certificate), and IAM II certification (CAP or CASP CE) or be able to obtain within six months; CE/OS certificate may include Windows or Linux * Experience with eMASS and/or Xacta, ACAS/Nessus, SCAP, Benchmarks, STIG Viewer, and POA&Ms * Experience with patching, reviewing system and event logs for operating systems such as Windows and Linux * Must be able to diagnose and solve problems within a computer network * Have knowledge of National Institute of Science and Technology (NIST) and Defense Information Systems Agency (DISA) standards, guidelines, and requirements as related to Cybersecurity and Risk Management * Have experience in reviewing compliance in Microsoft Windows, Red Hat Linux and other operating systems in accordance with DISA and NIST requirements * Have professional communication skills and the ability to express thoughts and ideas clearly and concisely * Must be a team player, dedicated to program support, capable of multitasking and working several complex and diverse tasks with simultaneous or near simultaneous deadlines * Be a self-starter who is accountable and requires minimal direction and supervision * Be open to new and innovative idea Desired Skills * Bachelor's degree in information systems, computer science, or similar * Navy Qualified Validator (NQV) * Experience evaluating DISA STIG configurations * Experience with Windows and Linux patching environments * Experience with eMASS Clearance Information SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL Travel Requirements * Up to 10% travel may be required ## Description The Naval Surface Warfare Center Philadelphia Division (NSWCPD) is a Department of Defense entity responsible for research and development, test and evaluation, engineering and fleet support organization for the Navy's ships, submarines, military watercraft and unmanned vehicles. This requirement is for NSWCPD Code 20 Land Based Test Site Programs, which is responsible for the support of Risk Management Framework (RMF) package development of all NSWCPD Land Based Test Sites. All test site systems must receive and maintain full RMF Authority To Operate (ATO) to ensure Cyber Security and Information Assurance (IA) Hardening of all Land Based Test Site Systems. Systems in scope are both Ashore and Afloat systems within each Land Based Test Site. Supporting the information system owner to complete security assessments, achieve system authorizations, continuous monitoring, and configuration management, through eMASS * Verifying patches and virus definitions are updated on the system using existing automated tools * Adhering to pre-defined configuration management and change management policies for authorizing software prior to its implementation on systems * Verifying mitigation and closure of open vulnerabilities following the NSWC change control process * Assessing NSWC systems in accordance with Navy, NIST, DoD, and DISA guidance * Reporting security incidents in accordance with the Command's Incident Response Plan * Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)