Position Description & QualificationsSerco is seeking a Cybersecurity Analyst II to support cybersecurity operations within the SATCOM programsin Orlando, Florida.
This is a hands-on, operations-focused role responsible for monitoring, analyzing, and improving the security posture of enterprise systems. The Cybersecurity Analyst II will work daily with security tools such as Splunk, ACAS, and STIG compliance reports, identifying vulnerabilities and delivering clear, actionable remediation guidance to technical teams.
In this role, you will:
- Review and validate system compliance with DISA STIGs, identifying gaps and recommending corrective actions for misconfigurations and settings.
- Oversee vulnerability and patch management activities including ACAS scans, system alerts, and patch mitigations.
- Monitor and analyze security events and logs using Splunk, identifying anomalies and potential threats
- Conduct security control implementation and testing for identity systems in support of Risk Management Framework (RMF) Assessment & Authorization (A&A) packages.
- Support vulnerability remediation, patch management, and secure configuration baselines (STIGs/CIS benchmarks) for IAM infrastructure.
- Partner with application owners and engineering teams to embed zero trust and least-privilege principles into identity workflows.
- Serve as the ISSO of record for identity management systems, maintaining continuous authorization to operate (ATO) status.
- Conduct and document risk assessments, POA&Ms, and continuous monitoring activities for assigned systems.
- Coordinate with the ISSM, AO, and assessment teams during A&A activities, audits, and inspections (NIST SP 800-53, RMF, FedRAMP as applicable).
- Monitor and report on security events, incidents, and access anomalies related to identity and access systems; support incident response as needed.
- Maintain audit-ready documentation for access reviews, certification campaigns, and compliance evidence collection.
- Ensure identity-related controls align with applicable frameworks (NIST 800-53, NIST 800-63, ICD 503, DoD RMF, or agency-specific requirements).
- Brief leadership and stakeholders on identity security posture, risk, and remediation status.
To be successful in this role, you will have:
- Active DoD Secret clearance required at time of hire.
- A Bachelor's degree in Computer Science or related field and 2 years of Information Systems Administrator or Cyber-Security experience.
- DoD 8570 IAT Level II or III certification (Security+, CySA+, CISSP, or equivalent)
- Working knowledge of NIST SP 800-53, RMF, and Assessment & Authorization (A&A) processes.
- Familiarity with STIGs, CIS benchmarks, and secure configuration management.
- Strong written communication skills for security documentation (SSPs, POA&Ms, risk assessments).
Additional desired experience and skills:
- Demonstrated work experience as an ISSO
- CISSP, CISM, or any higher tier cybersecurity certification.
- Experience integrating IAM platforms with PKI/CAC/PIV authentication
- Scripting/automation experience (PowerShell, Python) for identity workflow automation.
- Experience administering and/or securing Linux operating systems in enterprise environments, including system hardening, log analysis and vulnerability remediation, and troubleshooting
- Experience with eMASS.
Pay TransparencyOur Total Rewards package includes competitive pay, performance-based incentives, and benefits that promote well-being and work-life balance-so you can thrive both professionally and personally. Eligible employees also gain access to a wide range of benefits from comprehensive health coverage and health savings accounts to retirement plans, life and disability insurance, and time-off programs that support work-life balance. Program availability may vary based on factors such as contract type, location, hire date, and applicable collective bargaining agreements.
Salary range: The range for this position can be found at the top of this posting. This range is provided as a general guideline and represents a good faith estimate across all experience levels. Actual base salary will be determined by a variety of factors, including but not limited to, the scope of the role, relevant experience, job-related knowledge, education and training, key skills, and geographic market considerations. For roles available in multiple states, the range may vary to reflect differences in local labor markets. In addition to base salary, eligible positions may include other forms of compensation such as annual bonuses or long-term incentive opportunities.Benefits - Comprehensible benefits for full-time employees (part-time employees receive a limited package tailored to their role):
- Medical, dental, and vision insurance
- Robust vacation and sick leave benefits, and flexible work arrangements where permitted by role or contract
- 401(k) plan that includes employer matching funds
- Tuition reimbursement program
- Life insurance and disability coverage
- Optional coverages that can be purchased, including pet insurance, home and auto insurance, additional life and accident insurance, critical illness insurance, group legal, ID theft protection
- Birth, adoption, parental leave benefits
- Employee Assistance Plan
To review all Serco benefits please visit: https://careers.serco-na.com/us/en/about-us.
Serco complies with all applicable state and local leave laws, including providing time off under the Colorado Healthy Families and Workplaces Act for eligible Colorado residents, in alignment with our policies and benefit plans. The application window for this position is for no more than 60 days. We encourage candidates to apply promptly after the posting date, as the position may close earlier if filled or if the application volume exceeds expectations. Please submit applications exclusively through Serco's external (or internal) career site. If an applicant has any concerns with job posting compliance, please send an email to: [redacted].