> Markdown version of [/jobs/ext/3539523-senior-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/3539523-senior-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Analyst - **Company:** Amentum Services, Inc. - **Location:** Trenton, NJ, United States (Remote available) - **Experience:** Expert - **Salary:** $110,000.0 - $130,000.0 - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Microsoft Azure, Cyber Security, Information Systems, Identity and Access Management, Information Technology, Crosswalk - **Published:** September 30, 2026 - **Apply:** https://www.financialjobbank.com/job.asp?id=3412420661&tx=KP1515FFG&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Demonstrated ability to recognize cyber risk in networking, cloud, and endpoint technologies, and in identity and access management, well enough to assess the decisions of engineering and IT teams independently. * Ability to articulate cyber risk to business leadership in decision-ready terms. * Working knowledge of NIST publications and their relevance to cyber risk and compliance. * Strong written and verbal communication, including the ability to explain technical risk to non-technical stakeholders. * Self-starter able to operate autonomously on ambiguous problems with limited direction. * Ability to travel up to 25 percent., * Typically 8 years of hands-on cybersecurity experience, with demonstrated depth in evaluating real technology environments, not solely policy or audit administration with a Bachelor's degree in Computer Science, Information Systems or related field plus; or 4 years with Master's * Demonstrated experience in enterprise risk management and in third-party or vendor cyber risk assessment. * Current Security+ or an equivalent industry certification. (Certification establishes the baseline; demonstrated hands-on capability is weighted more heavily than credentials.) * Must be a U.S. Citizen. * U.S. Remote-Telework role; must reside within the United States to work remotely., The following raise the ceiling for this role. Hands-on depth in the areas below is valued above the number of certifications or degrees held. * Senior certifications such as CISSP or CySA+, and an identity and access credential such as Microsoft SC-300. * Hands-on experience in a Microsoft Azure environment, including Microsoft 365; exposure to Azure Government (GCC High) is strongly preferred. * Direct experience assessing identity and access architectures, including Entra ID, B2B and external identity, conditional access, and privileged access. * Experience in U.S. Federal or Defense Industrial Base (DIB) environments, and familiarity from a risk perspective with CMMC, NIST SP 800-171/172, and DFARS, and with international frameworks such as UK Cyber Essentials, Australian Essential Eight, UK GDPR, and EU NIS2. * Familiarity with multi-framework risk management across standards such as ISO/IEC 27001 and with crosswalk approaches that achieve cohesive risk treatment across frameworks. * Experience improving GR&C operational processes: assessment methodology, intake, and risk reporting. * Bachelor's degree in a related field. A degree is not required and does not substitute for demonstrated hands-on capability; equivalent experience is fully acceptable. ## Description * Conduct cyber risk assessments of activities and operational decisions across the enterprise, identifying risk to the confidentiality, integrity, and availability of enterprise systems and data. * Articulate cyber risk to business and technical leadership in clear, decision-ready terms, framed against the enterprise's risk appetite. * Take lead on cyber risk reviews across a range of assessment types, such as third-party cyber risk assessment, temporary risk acceptance review, and software risk review, and track enterprise artificial intelligence development as it relates to cyber risk. * Work with the Compliance function to ensure that mandatory control interpretations do not leave other cyber risk unaddressed, and that risk treatment is coherent across frameworks. * Evaluate the cyber risk implications of technology decisions, recognizing risk in networking, cloud, endpoint, and identity and access architectures that compliance-only review would not surface. * Articulate when residual cyber risk exceeds the enterprise's appetite and specify the risk reduction required. * Contribute a risk-posture perspective to enterprise scoping and architecture decisions, including the residual risk implications of carved-out certification environments and enclave boundaries. * Improve the operational and procedural aspects of the Cyber GR&C function: assessment methodology, intake, risk articulation standards, evidence handling, and the consistency of risk judgments across the team. * Maintain current knowledge of the cyber risk, threat, technology, and regulatory landscape, and bring that currency into assessments and into the team's collective capability. * Travel up to 25 percent. Perform other position-related duties as assigned.