> Markdown version of [/jobs/ext/3388357-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/3388357-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - **Company:** AGENSYS CORP - **Location:** Washington, VA, United States - **Experience:** Experienced - **Salary:** $113,961.0 - $120,244.0 - **Contract:** Permanent contract - **Skills:** Xacta, CompTIA Security+, Cyber Security, Nessus, Plan of Action and Milestones - **Published:** September 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d9e3c79e570c8999 ## About the Role Agensys is seeking an experienced Cyber Security Impact Assessment (SIA) professional to support a government customer onsite at the Pentagon. The position will support Secure Technical Implementation Guide (STIG) hardening. The role requires strong initiative, organization, communication, customer service, and the ability to operate in a fast-paced environment., * Bachelor's degree or equivalent work experience and certifications. * Current DoD 8570 IAT II certification, including GSEC, Security+, SCNP, or SSCP. * 8-10 years of cybersecurity experience. * Familiarity with the DoD STIG process. * Excellent verbal and written communication skills. * Familiarity with ACAS, eMASS, and XACTA. Desired Qualifications: * Nessus experience. * Systems administration experience. * Experience with CCRI scoring. * Security Control Knowledge and Self-Assessment experience. * Experience obtaining an ATO and taking a system through the full RMF process. ## Description * Run and review Evaluate STIG scans and manually validate STIG checklists. * Analyze vulnerability scans and STIG results to identify critical open vulnerabilities requiring remediation. * Work with system owners and work centers to close, mitigate, or document vulnerabilities through POA&Ms. * Identify risks and impacts and recommend appropriate mitigation strategies. * Provide remediation recommendations based on DoW and Air Force guidance and directives. * Validate system hardware/software inventories against system assets. * Create and maintain SOPs and Work Instructions. * Create and track POA&Ms throughout the System Impact Assessment lifecycle. * Create Remedy tickets to track STIG implementation. * Complete monthly application STIG status reports and POA&M updates. * Complete and validate STIG/SRG checklists for RMF on a quarterly basis. * Provide management status reports and document system changes. * Develop and maintain POA&Ms and support remediation activities. * Support continuous monitoring and POA&M activities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What The Hack is Web App Sec?](https://www.wearedevelopers.com/videos/1343-what-the-hack-is-web-app-sec) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Outsmarting the System: What Game Cheaters Can Teach Us About Cyber Security](https://www.wearedevelopers.com/videos/1396-outsmarting-the-system-what-game-cheaters-can-teach-us-about-cyber-security) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)