> Markdown version of [/jobs/ext/2742438-senior-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/2742438-senior-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Analyst - **Company:** Tlingit Haida Tribal Business Corporation - **Location:** Falls Church, VA, United States - **Experience:** Expert - **Salary:** $91,000.0 - $124,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Microsoft Azure, Cloud Computing Security, Configuration Management, Cyber Security, Information Systems, Computer Literacy, Data Governance, Multi-Factor Authentication, Identity and Access Management, IT Management, Virtual Private Networks (VPN), Network Security, Windows Servers, Network Architecture, Open Source Technology, Role-Based Access Control, Cloud Services, Phishing, Security Information and Event Management, TCP/IP, Virtual Local Area Networks, Virtualization Technology, Software Vulnerability Management, Firewalls (Computer Science), Information Technology, Patch Management, Vulnerability Analysis - **Published:** September 6, 2026 - **Apply:** https://www.careerjet.com/job/us2852cf4b3136b9e6f5d1b822cd63d4a4/eaa ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; equivalent education, certifications, training, and experience may be considered. * 7+ years of cybersecurity, information security, information assurance, risk management, or related IT security experience, including 3+ years in a senior-level cybersecurity role within a complex enterprise environment. * Strong knowledge of NIST SP 800-171, CMMC, and federal/DoD contractor cybersecurity requirements, including protection of CUI and FCI. * Experience with SSPs, POA&Ms, security controls, compliance evidence, risk assessments, audits, and CMMC readiness/assessments. * Experience with vulnerability management, including scanning, analysis, prioritization, remediation, and validation. * Hands-on experience with SIEM, EDR, endpoint security, firewalls, identity/security monitoring tools, and cybersecurity incident response. * Experience securing Microsoft 365/GCC High, Azure, Entra ID, and Active Directory, including MFA, Conditional Access, RBAC, privileged access, and identity security. * Working knowledge of Windows Server, endpoint technologies, network infrastructure, TCP/IP, VLANs, firewalls, VPNs, virtualization, cloud services, and network security. * Experience with endpoint protection, EDR, encryption, system hardening, secure configurations, access controls, patch management, and configuration management. * Experience conducting cybersecurity risk assessments, control gap analyses, security reviews, and risk mitigation activities. * Ability to translate technical and regulatory requirements into practical security controls, procedures, technical requirements, and remediation plans. * Experience with vendor/third-party risk management, cybersecurity policies and procedures, incident response planning, and security documentation. * Strong analytical, investigative, problem-solving, communication, and organizational skills, with the ability to manage multiple cybersecurity priorities. * Ability to work independently and collaborate effectively with IT teams, leadership, business units, vendors, auditors, assessors, and other stakeholders. * Ability to provide senior-level technical guidance and mentoring to IT and cybersecurity personnel. * Ability to support after-hours incident response or emergency cybersecurity activities as required. * Must be legally authorized to work in the United States and meet all applicable U.S. Government/DoD background, eligibility, and security requirements. * Must possess or be able to obtain and maintain an active U.S. Government security clearance at the level required for assigned contracts. Physical Demands & Work Environment * Ability to work in an office environment with prolonged periods of sitting and computer use. * Ability to travel domestically up to 20% as business needs require. * Ability to lift up to 25 pounds occasionally. ## Description This role works collaboratively with IT leadership, systems administrators, business units, compliance personnel, vendors, auditors, and other stakeholders, the Senior Cybersecurity Analyst will help establish and maintain a risk-based, defense-in-depth cybersecurity program that supports organizational operations, contractual obligations, regulatory requirements, and the protection of critical information assets. The position requires a combination of strong technical cybersecurity expertise, analytical and investigative capabilities, regulatory and compliance knowledge, documentation skills, and the ability to communicate cybersecurity risk effectively to both technical and non-technical audiences. What You'll Be Doing * Monitor, investigate, and respond to cybersecurity alerts, incidents, vulnerabilities, and threats across enterprise, endpoint, cloud, network, and application environments. * Support compliance with NIST SP 800-171, CMMC, and applicable federal/DoD cybersecurity requirements, including protection of CUI and FCI. * Implement, assess, document, and continuously monitor cybersecurity controls and maintain SSPs, POA&Ms, policies, procedures, and compliance evidence. * Conduct cybersecurity risk assessments, vulnerability assessments, and security reviews; prioritize findings and coordinate remediation efforts. * Support internal and external audits, CMMC assessments, customer reviews, and other cybersecurity compliance activities. * Analyze security logs, alerts, and threat intelligence using tools such as SIEM, EDR, Microsoft 365, Azure, Entra ID, firewalls, and endpoint security platforms. * Participate in incident response activities, including investigation, containment, remediation, recovery, documentation, and post-incident reviews. * Assess and improve security configurations, system hardening, patch management, endpoint protection, network security, cloud security, and data protection controls. * Support identity and access management, including MFA, Conditional Access, privileged access, least privilege, RBAC, and periodic access reviews. * Evaluate security posture across Microsoft 365, GCC High, Azure, Entra ID, Active Directory, and other enterprise platforms. * Support third-party/vendor risk management, technology security reviews, change management, and cybersecurity assessments for new systems and services. * Develop cybersecurity metrics, dashboards, risk registers, vulnerability reports, and compliance reporting for leadership. * Develop and maintain cybersecurity policies, standards, procedures, incident response plans, and security documentation. * Support security awareness programs, phishing simulations, cybersecurity training, and organization-wide security initiatives. * Provide cybersecurity guidance to employees, IT teams, leadership, vendors, auditors, and assessors. * Stay current on emerging threats, vulnerabilities, regulations, cybersecurity frameworks, and industry best practices. * Serve as a senior cybersecurity resource and escalation point for complex security, risk, compliance, and incident response matters; mentor junior team members as appropriate. * Participate in after-hours incident response or emergency cybersecurity support as required. * Perform other cybersecurity, information assurance, risk management, and compliance duties as assigned., MANTECH seeks a motivated, career- and customer-oriented SME Open-Source Intel Analyst to join our team in Sterling, VA. This is currently a hybrid position with 2 days onsite/week… + 1 day ago, Overview: GovCIO is currently hiring for a Senior Process Analyst with advanced expertise in enterprise strategy, data governance, and technology alignment to lead strategic supp… + 1 day ago + ## Related Videos - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)