> Markdown version of [/jobs/ext/3544955-senior-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/3544955-senior-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Analyst - **Company:** Amentum Services, Inc. - **Location:** Columbus, OH, United States (Remote available) - **Experience:** Expert - **Salary:** $110,000.0 - $130,000.0 - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Microsoft Azure, Cyber Security, Information Systems, Identity and Access Management, Information Technology, Crosswalk - **Published:** September 30, 2026 - **Apply:** https://www.columbusjobsite.com/job.asp?id=3412417331&tx=JP5751FFL&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Demonstrated ability to recognize cyber risk in networking, cloud, and endpoint technologies, and in identity and access management, well enough to assess the decisions of engineering and IT teams independently. * Ability to articulate cyber risk to business leadership in decision-ready terms. * Working knowledge of NIST publications and their relevance to cyber risk and compliance. * Strong written and verbal communication, including the ability to explain technical risk to non-technical stakeholders. * Self-starter able to operate autonomously on ambiguous problems with limited direction. * Ability to travel up to 25 percent., * Typically 8 years of hands-on cybersecurity experience, with demonstrated depth in evaluating real technology environments, not solely policy or audit administration with a Bachelor's degree in Computer Science, Information Systems or related field plus; or 4 years with Master's * Demonstrated experience in enterprise risk management and in third-party or vendor cyber risk assessment. * Current Security+ or an equivalent industry certification. (Certification establishes the baseline; demonstrated hands-on capability is weighted more heavily than credentials.) * Must be a U.S. Citizen. * U.S. Remote-Telework role; must reside within the United States to work remotely., The following raise the ceiling for this role. Hands-on depth in the areas below is valued above the number of certifications or degrees held. * Senior certifications such as CISSP or CySA+, and an identity and access credential such as Microsoft SC-300. * Hands-on experience in a Microsoft Azure environment, including Microsoft 365; exposure to Azure Government (GCC High) is strongly preferred. * Direct experience assessing identity and access architectures, including Entra ID, B2B and external identity, conditional access, and privileged access. * Experience in U.S. Federal or Defense Industrial Base (DIB) environments, and familiarity from a risk perspective with CMMC, NIST SP 800-171/172, and DFARS, and with international frameworks such as UK Cyber Essentials, Australian Essential Eight, UK GDPR, and EU NIS2. * Familiarity with multi-framework risk management across standards such as ISO/IEC 27001 and with crosswalk approaches that achieve cohesive risk treatment across frameworks. * Experience improving GR&C operational processes: assessment methodology, intake, and risk reporting. * Bachelor's degree in a related field. A degree is not required and does not substitute for demonstrated hands-on capability; equivalent experience is fully acceptable. ## Description * Conduct cyber risk assessments of activities and operational decisions across the enterprise, identifying risk to the confidentiality, integrity, and availability of enterprise systems and data. * Articulate cyber risk to business and technical leadership in clear, decision-ready terms, framed against the enterprise's risk appetite. * Take lead on cyber risk reviews across a range of assessment types, such as third-party cyber risk assessment, temporary risk acceptance review, and software risk review, and track enterprise artificial intelligence development as it relates to cyber risk. * Work with the Compliance function to ensure that mandatory control interpretations do not leave other cyber risk unaddressed, and that risk treatment is coherent across frameworks. * Evaluate the cyber risk implications of technology decisions, recognizing risk in networking, cloud, endpoint, and identity and access architectures that compliance-only review would not surface. * Articulate when residual cyber risk exceeds the enterprise's appetite and specify the risk reduction required. * Contribute a risk-posture perspective to enterprise scoping and architecture decisions, including the residual risk implications of carved-out certification environments and enclave boundaries. * Improve the operational and procedural aspects of the Cyber GR&C function: assessment methodology, intake, risk articulation standards, evidence handling, and the consistency of risk judgments across the team. * Maintain current knowledge of the cyber risk, threat, technology, and regulatory landscape, and bring that currency into assessments and into the team's collective capability. * Travel up to 25 percent. Perform other position-related duties as assigned. ## Related Videos - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)