The Cybersecurity Analyst supports the security, compliance, and maintenance of information systems throughout the Risk Management Framework (RMF) lifecycle, from system preparation through decommissioning. This role ensures alignment with Intelligence Community Directive (ICD), Defense Intelligence Agency (DIA), and Department of Defense (DoD) cybersecurity policies and standards.
The analyst works closely with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), Security Control Assessors (SCAs), Program Managers (PMs), and other stakeholders to execute RMF activities, reduce cybersecurity risk, and improve the overall security posture of supported systems. This position focuses on driving meaningful security outcomes through vulnerability management, continuous monitoring, compliance support, and risk-informed decision-making.
Roles and Responsibilities- Support information systems throughout the RMF lifecycle, ensuring compliance with applicable cybersecurity policies, standards, and regulations.
- Collaborate with ISSMs, ISSOs, SCAs, PMs, and other stakeholders to support security initiatives and compliance efforts.
- Assist stakeholders in understanding cybersecurity risks, vulnerability impacts, and remediation priorities to improve system security posture.
- Provide technical support for continuous monitoring activities, compliance reporting, and audit readiness initiatives.
- Evaluate cybersecurity implications of system modifications, upgrades, and configuration changes.
- Support implementation, assessment, and documentation of security controls.
- Maintain and update cybersecurity documentation, authorization packages, and RMF artifacts.
- Document vulnerabilities, misconfigurations, and security findings clearly to support remediation planning and stakeholder awareness.
- Utilize Xacta or similar Cyber Risk Management platforms to manage risk assessments, security control evidence, compliance status, and POA&M activities.
- Track and manage POA&M items to ensure vulnerabilities identified through scans, assessments, or audits are properly documented, mitigated, and resolved.
- Analyze vulnerability and compliance data to identify trends, recurring issues, and opportunities for security improvements.
- Promote cybersecurity best practices and ensure alignment with organizational and mission objectives.
Knowledge- Knowledge of the Risk Management Framework (RMF), NIST 800-series publications, Federal Information Processing Standards (FIPS), Security Authorization and Assessment (SA&A) processes, continuous monitoring, POA&M management, and vulnerability management.
- Understanding of cybersecurity compliance requirements within DoD, DIA, and Intelligence Community environments.
- Familiarity with cybersecurity risk management platforms such as Xacta and related compliance management tools.
Skills- Strong verbal and written communication skills with the ability to explain technical concepts to both technical and non-technical audiences.
- Experience interpreting vulnerability and compliance reports generated from tools such as Xacta, STIG Viewer, ACAS, Prisma, Splunk, Trellix (HBSS), or similar security platforms.
- Strong analytical, troubleshooting, and problem-solving abilities.
- Ability to identify root causes of security issues and recommend practical remediation strategies.
- Experience working across multiple teams and stakeholders to achieve security and compliance objectives.
- Ability to manage competing priorities while maintaining attention to detail and accuracy.
- Strong organizational skills and ability to maintain comprehensive security documentation.
Required Qualifications- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- Obtain and maintain an IAT Level III certification, or maintain an IAT Level II certification, in accordance with DoD 8570.01-M and DoD Directive 8140 Cyberspace Workforce Management requirements.
- Acceptable certifications include: CompTIA Cybersecurity Analyst (CySA+), CompTIA Security+, EC-Council Certified Network Defender (CND v3), CCNA Security, Global Industrial Cyber Security Professional (GICSP), GIAC Security Essentials (GSEC), Systems Security Certified Practitioner (SSCP)
Clearence- Active Top Secret clearance is required with SCI eligibility and the ability to Pass CI Poly
}