> Markdown version of [/jobs/ext/3052673-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/3052673-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - **Company:** Concept Plus - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Agile Methodology, Cloud Computing, Cloud Computing Security, Database Security, Information Systems Security Architecture Professional, SonarQube, Tripwire, Transport Layer Security, Information Technology, Nessus, Checkmarx, Devsecops, Vulnerability Analysis - **Published:** September 24, 2026 - **Apply:** https://www.builtincolorado.com/auth/login?destination=/job/cyber-analyst/11346091 ## About the Role * US Citizen with active DoD Secret Clearance (or ability to obtain one) * Bachelor's Degree in an IT related field * 8+ years of experience as Cyber Analyst * 5+ years' experience with ATO procurement in Cloud Environment * 5+ years in DoD Environment * 5+ Years Experience with the Risk Management Framework Process * 5+ Years Experience operating the Enterprise Mission Assurance Support Service Application (eMASS) Preferred Qualifications * DOD/Government contracting experience, Government IT systems experience. * Able to work independently and report to a blended Cyber Team ISSM * Good documentation skills * Confident communicator with excellent verbal and written skills ## Description Concept Plus is seeking a highly capable, self-driven Cybersecurity Analyst to support a critical software modernization initiative for our client. This position plays a key role in analyzing mission-focused requirements, streamlining processes, and enhancing decision-making for operations. As the strategic link between operational objectives and technology solutions, the Cybersecurity Analyst will translate complex business needs into actionable insights and support the successful execution of priorities while ensuring alignment with client compliance standards. This role operates within a collaborative Agile and DevSecOps framework to ensure secure, timely, and iterative delivery of capabilities. The ideal candidate thrives in a fast-paced, evolving environment and brings a deep understanding of both business processes and technological integration. What you'll do * Lead and maintain the full RMF/ATO lifecycle, managing security authorization packages and updating SSPs, POA&Ms, risk assessments, and continuous monitoring artifacts. * Ensure system confidentiality, integrity, and availability through compliance with NIST 800-53, DoDI 8500.01, DoDI 8510.01, and related DoD cybersecurity policies. * Support Agile/DevSecOps deployments, integrating cybersecurity requirements into sprints, CI/CD pipelines, release schedules, and system design reviews. * Perform vulnerability scanning, assessment, and remediation-using Nessus, eMASS, SonarQube, Checkmarx, Trivy, Dependency Track-and ensure compliance with DISA STIGs. * Perform cloud-focused vulnerability scanning, assessment, and remediation using Nessus, eMASS, SonarQube, Checkmarx ensuring compliance with cloud security baselines. * Provide security engineering support, including secure architecture input, SSO/SSL integration, secure configuration guidance, and API/cloud security reinforcement. * Collaborate with technical teams, ISSMs, and AO representatives to support audits, inspections, security reviews, and risk mitigation activities. * Track, report, and respond to cybersecurity incidents, ensuring timely coordination and recovery actions. * Develop and maintain key cybersecurity documentation, including ISAs, MOAs, SoD matrices, architecture diagrams, and application/database security artifacts. * Monitor project progress and deliver clear, actionable cybersecurity reports and risk insights to leadership and government stakeholders. * Communicate effectively with internal teams, customers, and stakeholders in a clear, concise, and professional manner. ## Related Videos - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Automated Code Quality Checks with Custom SonarQube Rules](https://www.wearedevelopers.com/videos/428-automated-code-quality-checks-with-custom-sonarqube-rules) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Practical tips for keeping your C# code base clean](https://www.wearedevelopers.com/videos/100149-practical-tips-for-keeping-your-c-code-base-clean) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)