> Markdown version of [/jobs/ext/542626-senior-cybersecurity-analyst-issm-hybrid](https://www.wearedevelopers.com/jobs/ext/542626-senior-cybersecurity-analyst-issm-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Analyst (ISSM) - Hybrid - **Company:** Optimized Technical Solutions - **Location:** San Antonio, TX, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** JIRA, Cloud Computing, Cyber Security, Desktop Computing, Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, Open Source Technology, SonarQube, Information Technology, Free and Open-Source Software, Checkmarx, Vulnerability Analysis - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=311f2bdc921359e6 ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, * Bachelor's degree in Cybersecurity, Information Technology (IT), or a related field OR equivalent experience. * Information Assurance Manager (IAM) Level III Certification (Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GIAC Security Leadership Certification (GSLC), or equivalent). * 15+ years of experience in DoD cybersecurity operations. * Proficiency with SonarQube, Dependency-Track, ACAS, and STIG compliance. * Experience with eMASS, RMF, and cybersecurity compliance in DoD or federal agencies. Work Environment Office environment. Requires ability to provide clear, concise, accurate and timely communication, both verbally and in writing (100%). Requires ability to interact professionally with co-workers, management, and client (100%). Occasional business travel may be required. Only requested and approved expenses will be covered by OTS. ## Description OTS is seeking a Senior Cybersecurity Analyst (Information System Security Manager - ISSM) to oversee Risk Management Framework (RMF) accreditation, Federal Information Security Modernization Act (FISMA) compliance, and security control implementation. This role requires hands-on experience with cybersecurity automation tools and compliance enforcement across Cloud One programs. The hybrid role allows flexibility to work remotely but requires on-site presence at any approved SIPR facility as needed., * Security Documentation: Responsible for the creation, maintenance, and management of all cybersecurity documentation, ensuring accuracy, completeness, and compliance with Department of Defense (DoD) and federal standards. * Code Scans: Accountable for the completion and accuracy of static and dynamic code scans using tools such as Checkmarx and SonarQube, ensuring all findings are addressed and documented. * Open-Source Library Scans: Accountable for conducting and reporting on open-source software library scans using tools like Dependency-Track, ensuring all vulnerabilities are tracked and mitigated. * Cybersecurity and Authorization to Operate (ATO): Responsible and accountable for all aspects of cybersecurity posture and the successful completion of the ATO process, ensuring systems meet all compliance requirements for operation. * Assured Compliance Assessment Solution (ACAS) Scans: Responsible and accountable for scheduling, conducting, and reporting on ACAS vulnerability scans, and for the timely remediation of findings. * C5ISR Interrogator Reporter: Responsible and accountable for managing and reporting through the Command, Control, Communications, Computers, Combat Systems, Intelligence, Surveillance, and Reconnaissance (C5ISR) Interrogator system, ensuring accurate and timely submission of required cybersecurity data. * Enterprise Mission Assurance Support Service (eMASS) and Plan of Action and Milestones (POA&M): Responsible and accountable for maintaining all eMASS records, including the creation and management of POA&M items to track and resolve security weaknesses. * STIG Checks: Perform Security Technical Implementation Guide (STIG) checks and collaborate on security control mitigations. * JIRA Workflow Support: Provide JIRA workflow support, reviewing tickets and ensuring Information Assurance (IA) requirements are met. * Continuous Monitoring: Support continuous cybersecurity monitoring and vulnerability tracking for mission applications. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Automated Code Quality Checks with Custom SonarQube Rules](https://www.wearedevelopers.com/videos/428-automated-code-quality-checks-with-custom-sonarqube-rules) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Practical tips for keeping your C# code base clean](https://www.wearedevelopers.com/videos/100149-practical-tips-for-keeping-your-c-code-base-clean) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)