> Markdown version of [/jobs/ext/739471-cyber-analyst](https://www.wearedevelopers.com/jobs/ext/739471-cyber-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Analyst - **Company:** Peraton Inc - **Location:** Lorton, VA, United States (Remote available) - **Salary:** $112,000.0 - $179,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Agile Methodology, Amazon Web Services, Burp Suite, Cloud Computing, Static Program Analysis, Cyber Security, Databases, Linux, SonarQube, Checkmarx, Devsecops, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3693fe3465f7c519 ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, What you'll need: * Education: 8 years with a BS/BA, 6 years with a MS/MA or 12 years of experience in lieu of a degree * Proven experience in cybersecurity roles such as Cybersecurity Analyst, Cybersecurity Engineer, ISSO, ISSM, or related positions. * Strong knowledge of the DoD Risk Management Framework (RMF), NIST 800-53 controls, STIGs, SRGs, and system accreditation processes. * Experience supporting Authority to Operate (ATO) efforts, including development and management of RMF artifacts. * Hands-on experience with STIG assessments, ACAS vulnerability scanning and reporting, POA&M management, SSP development, PPSM, CONOPS, and eMASS. * Working knowledge of AWS and cloud computing environments. * Certifications: One or more of the following certifications: CISSP (preferred), CASP+, Security+, CEH, CISA, SSCP, or GSEC. * Clearance: Active Secret * The candidate must be local to the Washington DC Metro area ## Description Peraton is looking to hire a Cyber Analyst in the Washington DC Metro area. This role will be a remote position. At times the role will also require travel to the Quantico client site when necessary. What you'll do: * Lead and execute RMF compliance activities in accordance with DoD and NIST requirements, supporting system accreditation and ATO efforts. * Conduct STIG and SRG assessments across Windows, Linux, database, cloud, and application environments using tools such as SCC and STIG Viewer. * Manage STIG matrices, Security Configuration Guides (SCGs), and compliance documentation. * Analyze vulnerability scan results, develop and maintain POA&Ms, and track remediation activities to closure. * Perform static and dynamic application security testing and source code analysis using tools such as Checkmarx, SonarQube, Burp Suite, and X-Ray. * Investigate, prioritize, and resolve security findings identified through vulnerability scans, assessments, and continuous monitoring activities. * Collaborate with engineering, operations, and development teams to implement effective security controls and remediation strategies. * Create, maintain, and manage cybersecurity artifacts, including SSPs, POA&Ms, and supporting documentation within eMASS. * Support cybersecurity audits, inspections, security assessments, and compliance reviews. * Ensure adherence to cybersecurity best practices, DoD requirements, and evolving security standards throughout the system lifecycle. * Contribute to security governance, continuous monitoring, and continuous improvement initiatives within an Agile/DevSecOps environment. * Communicate effectively with technical and non-technical stakeholders to support mission and compliance objectives. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Automated Code Quality Checks with Custom SonarQube Rules](https://www.wearedevelopers.com/videos/428-automated-code-quality-checks-with-custom-sonarqube-rules) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Automated MS SQL Server database deployments with dacpacs and Azure DevOps](https://www.wearedevelopers.com/videos/334-automated-ms-sql-server-database-deployments-with-dacpacs-and-azure-devops) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)