Smiths Machine

Cyber Security Analyst II

Smiths Machine$98K — $147K *
Technical Services
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or equivalent experience.
  • 3-5 years of hands-on Cyber security experience, with at least 2 years managing Microsoft 365 technologies.
  • Experience in drafting security policies and procedures.
  • Familiarity with NIST SP 800-171 Rev. 2 and CMMC Level 2 requirements.
  • Strong written communication skills for producing technical documentation for varied audiences.
  • U.S. Citizenship required.
  • Microsoft certifications in relevant security areas are preferred.

Responsibilities

  • Administer and tune Microsoft security tools including Defender, Entra ID, and Intune.
  • Draft and operationalize policies and procedures aligned with NIST SP 800-171.
  • Collaborate with HR and IT to enhance security processes related to user management.
  • Oversee the vulnerability management cycle, reporting on remediation efforts.
  • Respond to security incidents, documenting findings and leading reviews.
  • Maintain evidence for audits and manage the System Security Plan along with the Security Manager.
  • Execute monthly phishing simulations and provide targeted security training.
  • Mentor junior analysts, guiding their work and technical development.

Benefits

  • Excellent training and opportunities for career growth.
  • Inclusive environment with strong leadership support.
  • Flexibility in choosing from a wide range of lifestyle benefits.
  • Comprehensive health and wellbeing support for employees and families.
  • Competitive retirement plan with company match.
Full Job Description
Job Description

Job Objective

The Cyber Security Analyst II is the senior technical practitioner on a small, high-impact security team supporting a Defense Industrial Base (DIB) environment handling controlled data. This role is the hands-on owner of our Microsoft security stack and the primary author of the policies, procedures, and evidence artifacts required to sustain our CMMC Level 2 posture under NIST SP 800-171. The analyst works directly with the Information & Cyber Security Manager to mature the program, own cross-functional processes, and mentor a junior analyst.

Responsibilities

Essential functions - job duties to include but are not limited to; other duties as assigned.
  • Microsoft Security Operations: Shared ownership of day-to-day administration and tuning of Microsoft Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Entra ID (Conditional Access, PIM, Identity Protection), Intune (compliance policies, configuration profiles, update rings, app protection), and Purview (DLP, Insider Risk, Information Protection).
  • Policy and Procedure Authorship: Draft, maintain, and operationalize written policies and procedures mapped to NIST SP 800-171 Rev. 2 and CMMC Level 2 practices. Translate control language into runbooks, checklists, and evidence artifacts that an assessor can verify.
  • Cross-Functional Process Ownership: Partner with HR, IT, and Facility Security to develop and improve the end-to-end joiner/mover/leaver process, quarterly access reviews, privileged access management, and onboarding/offboarding of authorized users.
  • Vulnerability and Patch Management: Run the recurring vulnerability management cycle (Defender Vulnerability Management, Nessus, or equivalent): triage, prioritize, track SLAs, and report on remediation against a defined framework.
  • Incident Response: Act as tier-2 responder for Defender and Entra alerts; investigate, contain, and document incidents; lead post-incident reviews; maintain and exercise the incident response plan.
  • Evidence and Audit Support: Collect and maintain evidence for internal self-assessments and customer audits. Maintain the System Security Plan (SSP) and POA&M alongside the Security Manager.
  • Security Awareness and Training: Execute and measure the monthly phishing simulation program and deliver targeted training for elevated-risk roles.
  • Mentoring: Provide technical direction and review for the Cyber Security Analyst I and serve as the escalation point for their work.
  • Other Duties: Other duties as assigned.


Qualifications

Education Requirements

Required Education and Experience:
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field OR equivalent combination of certifications and hands-on experience.

Preferred Education and Experience:

Years of Experience:
  • 3-5 years of hands-on Cyber security experience, at least 2 of which include direct administration of Microsoft 365 / Entra ID / Intune / Defender in a production environment.
  • Demonstrable experience authoring security policies and procedures.
  • Working knowledge of NIST SP 800-171 Rev. 2 and/or CMMC Level 2; understands control mapping, procedure development, and evidence production.


Additional Qualifications:
  • U.S. Citizenship required.
  • Strong written communication - will produce documents read by executives, auditors, and government customers.
  • Prior experience in a DIB / defense contractor / cleared facility environment.
  • Experience with Microsoft GCC or GCC High tenants.
  • Experience with a SIEM (Sentinel, Splunk, Google SecOps/Chronicle, or similar) including log source onboarding and rule tuning.
  • Microsoft certifications: SC-200, SC-300, SC-400, MS-500, AZ-500.
  • CMMC Registered Practitioner (RP) or Certified CMMC Professional (CCP).

Technical Knowledge, Skills and Abilities:
  • Microsoft Defender suite (Endpoint, Office 365, Cloud Apps)
  • Entra ID
  • Intune
  • Purview
  • NIST SP 800-171 Rev. 2
  • CMMC Level 2
  • vulnerability management tools (Nessus or equivalent)
  • SIEM platforms, incident response


Additional Information

We offer...

Join us and we'll help build your career, with excellent training and opportunities for career growth across the business, both locally and globally. You'll experience an inclusive environment, with strong leadership and a focus on safety and wellbeing. You'll also have the flexibility to choose from a wide range of benefits to suit your lifestyle, offering you and your family support from a health and wellbeing, financial and lifestyle perspective.

Join us and work for a world-leader, with the benefits and training to reward your dedication and skills. Be part of a team where we are making the world a safer place.

The total compensation for this position ranges from $98,311 - $147,468/yr (Salary to be determined by the education, experience, knowledge, skills, & abilities of the applicant and the alignment with the internal team & market data). This role offers a competitive Business Profit Plan. This position includes a competitive benefits package. The comprehensive benefits package includes medical, dental & vision insurance; 401(k) with company match; paid time off; and other benefits. For details, please visit the Rewards & Benefits tab on our main careers page at Careers / Smiths Detection.

About Smiths Machine

Smiths Machine is a manufacturing company that specializes in precision machining and assembly services. The company was founded in 1980 and is headquartered in Indianapolis, Indiana. Smiths Machine has a team of experienced machinists and technicians who use state-of-the-art equipment to produce high-quality parts and components for various industries, including aerospace, defense, medical, and transportation. The company's services include CNC machining, turning, milling, grinding, and assembly. Smiths Machine is committed to providing its customers with high-quality products and services and has a reputation for delivering on-time and on-budget.
Learn more about Smiths Machine
Size
15,050 employees
Industry
NASDAQ

Similar Jobs

More Jobs at Smiths Machine

More Technical Services Jobs

Find similar Cyber Security Analyst II jobs: