Security Analyst II

ISSE SERVICES LLC
Clearfield, UT, United States
25 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$75,000.0 - $85,000.0
Working hours
Regular working hours
Job source

Tech stack

CompTIA Security+ Cyber Security Information Systems Information Security Management Systems Development Life Cycle SAP (Applications) Information Security Management System Information Technology Plan of Action and Milestones Vulnerability Analysis

Job description

ISSE Services is a cybersecurity and mission assurance company supporting defense, aerospace, and regulated industry customers. We specialize in Governance, Risk, and Compliance (GRC), cybersecurity engineering, managed security services, and CMMC readiness for organizations handling Controlled Unclassified Information (CUI).

Our mission is to help customers securely enable and accelerate their operations through practical compliance, technical expertise, and mission-focused security solutions.

About the Role

ISSE Services has vast experience maintaining the ATO and coordinating the Prime to ensure continued compliance with the RMF controls. The ATO control baseline (r5 and the SAF/CN control set) has recently been increased to a larger workload with more controls being required than in previous ATO cycles.

The Security Analyst II supports the Information System Security Manager (ISSM) by implementing and managing security controls in accordance with NIST RMF (SP 800-37) and applicable control baselines (e.g., NIST SP 800-53). The Security Analyst II ensures that system security requirements are met during system development, operation, and maintenance, and that risks are identified, documented, and mitigated.

The Security Analyst II is responsible for assisting the ISSM in maintaining RMF documentation such as the System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and continuous monitoring artifacts. They track vulnerabilities, ensure timely remediation, and coordinate with system administrators, engineers, and security teams to implement technical, administrative, and operational controls., * Implement and manage RMF 800-53r5 security controls for assigned information systems in coordination with ISSM

  • Assist ISSM maintain RMF artifacts (SSP, POA&M, SAR, continuous monitoring reports)
  • Support system authorization (ATO) and reauthorization activities
  • Monitor system security posture and ensure compliance with policies and standards
  • Coordinate vulnerability scanning, patching, and remediation efforts
  • Support security audits, inspections, and assessments
  • Ensure security incidents are reported and handled per policy
  • Advise leadership on system risks and mitigation strategies

Requirements

  • Education: Bachelor’s degree in Cybersecurity, Computer Science, IT, or related field (or equivalent experience).
  • Experience: 2-7 years in cybersecurity.
  • Audit/Compliance experience.
  • Practical System Administration experience.
  • Soft Skills: Strong analytical skills, ability to work under pressure, excellent communication skills, and team leadership capabilities.

The ideal candidate must have CompTIA Security+ at least one of the following certifications: GMON, SecurityX / CASP+, CCISO, CCSP, CGRC/CAP, CISSO, Cloud+, GCSA, GSEC, SSCP

Nice to have but not required: CISM, CISSP, CISSP-ISSMP, FITSP-M, GCIA, GCIH, GICSP, GSLC

Benefits & conditions

Why You’ll Love It Here

  • A mission-driven organization where your work directly supports federal programs that make a difference.

  • Competitive salary and performance-based bonuses.

  • Comprehensive health, dental, and vision coverage, company paid life insurance, long-term and short-term disability plus 401(k) with company match.

  • Generous PTO and 11 paid federal holidays.

  • Professional development support, including an annual training and certification budget.

  • A collaborative, respectful culture that values both precision and innovation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

57 sec

Identifying the ideal web applications for HTMX usage

Frederik Pietzko Frederik Pietzko · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:37 min

Developing customized native applications for automotive user interfaces

Stephan Schuster · World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all