> Markdown version of [/jobs/ext/3038403-security-analyst-mid](https://www.wearedevelopers.com/jobs/ext/3038403-security-analyst-mid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - Mid - **Company:** Seneca Resources - **Location:** Arlington, VA, United States - **Experience:** Experienced - **Salary:** $110,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Configuration Management, Cyber Security, Information Systems, System Configuration, Security Content Automation Protocol, Software Vulnerability Management, Infrastructure Automation Frameworks - **Published:** September 23, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9184892/security-analyst-mid ## About the Role * Active Secret federal security clearance * Strong knowledge of NIST security standards, especially RMF (Risk Management Framework) and NIST SP 800-128 * Extensive experience working with DISA STIGs, configuration management tools, and related security frameworks (SCAP, PowerSTIG, Chef InSpec, OpenSCAP) * Proven ability to pull, interpret, and update STIGs across Windows and multiple OS environments * Experience with system hardening, vulnerability mitigation, and continuous monitoring * On-site availability five days a week at DEA HQ in Arlington, VA * No recent drug use (at least three years, including marijuana) ## Description Join a dynamic team supporting a high-profile federal client as a Security Analyst - Jr. with a focus on cybersecurity, configuration management, and security technical implementation. You will be critical in maintaining secure system configurations, supporting DISA STIGs, and leveraging frameworks like NIST and RMF to reduce vulnerabilities and strengthen security postures. This role offers the opportunity to work directly on-site at DEA headquarters, ensuring compliance with federal security standards and enhancing your expertise in cybersecurity operations., * Implementing and maintaining secure configurations for multiple information systems in accordance with NIST 800-128, DISA STIGs, and related security standards. * Conducting configuration management activities, including pulling and updating STIG settings across Windows and various operating systems. * Supporting system hardening, vulnerability mitigation, and continuous security monitoring. * Collaborating with cross-functional teams to ensure security controls are appropriately applied and documented. * Assisting in audits and security assessments aligned with federal cybersecurity guidelines. * Updating and reviewing system registries and configuration settings regularly to remain compliant with new and existing STIGs. * Participating in policy development and security documentation efforts. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fake or News: Translating Dog Barks, Notepad Gets an Upgrade and Michelin-Star Robots - Paul Tregoing](https://www.wearedevelopers.com/videos/1802-fake-or-news-translating-dog-barks-notepad-gets-an-upgrade-and-michelin-star-robots-paul-tregoing) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 176: Expensive Agents, Taking Over VSCode and Safer Vibe Coding](https://www.wearedevelopers.com/magazine/603-dev-digest-176-expensive-agents-taking-over-vscode-and-safer-vibe-coding) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)