> Markdown version of [/jobs/ext/623239-systems-security-analyst](https://www.wearedevelopers.com/jobs/ext/623239-systems-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Systems Security Analyst - **Company:** ADG Tech Consulting, LLC. - **Location:** Vienna, VA, United States - **Salary:** $110,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Excel, JIRA, Decision Support Systems, Software Vulnerability Management, Information Security Management System, Cloud Platform System, Generative AI, Nessus, CIS Benchmarks, Devsecops, Servicenow - **Published:** June 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fcfe234883152f48 ## About the Role Do you have experience in Vulnerability management?, * Extensive knowledge of federal cybersecurity governance, risk management, and continuous monitoring processes, including RMF, NIST SP 800-53, NIST CSF, A&A/C&A, POA&M management, and control validation * Proficient in interpreting and applying security hardening standards and compliance baselines (DISA STIGs, CIS Benchmarks, CVEs), and assessing technical findings against organizational security requirements * Skilled in vulnerability management workflows, including Tenable/Nessus scan analysis, validation of findings, identification of false positives, and translating vulnerabilities into remediation or POA&M actions * Experienced in weakness and POA&M remediation through review of SSPs, assessment results, scans, remediation artifacts, and risk analysis in accordance with NIST and federal standards * Capable of updating and maintaining SSP documentation for enterprise and cloud environments, including control tailoring, inheritance documentation, and alignment with RMF, FedRAMP, and federal requirements * Proficient in managing vulnerability and POA&M workflows across CSAM/GRC, WTT/ServiceNow, Jira, and Excel, ensuring data alignment, traceability, and closure readiness * Able to participate in security audits and assessments, interpret findings, and coordinate remediation and evidence collection for compliance and operational requirements * Strong documentation skills, translating complex workflows into clear process diagrams, SOPs, and management-ready summaries for cross-functional teams * Experienced in leveraging Generative AI tools to enhance cybersecurity workflows, research, documentation, and decision support, with careful attention to information sensitivity and validation * Active CISSP certification desired, but not required ## Description * Serve as the security technical SME, collaborating with the delivery team project manager and leading a security team of approximately five members * Act as the security technical SME in interactions with government project customers, ISSOs, and ISMs * Define, implement, and manage security team processes and procedures, ensuring team understanding and compliance * Oversee technical aspects of handling identified security weaknesses and POA&Ms from intake through remediation * Support the development team in executing and enhancing the DevSecOps process, aligning with the customer's "security to the left" requirement ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)