CybersecurityJobs.io
← Back to all jobs

Job Description

TIAG is seeking a full-time Cybersecurity Analyst for a 100% onsite role in Arlington, VA. The position requires an active Secret Clearance to start work, and the analyst will support security operations, risk management, compliance activities, and incident response tasks.

Location and Employment Details

  • Work model: 100% onsite
  • Location: Arlington, VA
  • Employment type: Full-time
  • Salary: USD 90,000 to 110,000 per year

Role Summary

The Cybersecurity Analyst will continuously support the protection of information systems by monitoring for threats, performing risk and vulnerability analyses, ensuring compliance with Security Technical Implementation Guides (STIGs), and participating in Assessment and Authorization (A&A) efforts under the Risk Management Framework (RMF).

Responsibilities

  • Continuously monitors information systems for security threats, vulnerabilities, and breaches, using security tools to analyze alerts and take appropriate action.
  • Conducts regular risk assessments and vulnerability analyses to identify potential security weaknesses and recommends remediation strategies.
  • Uses DISA STIG Viewer to assess, document, and track system compliance with STIGs, including checklist reviews, recording findings, and generating compliance reports.
  • Supports the Assessment and Authorization (A&A) process within the Risk Management Framework (RMF) for multifaceted systems, networks, and enclaves.
  • Assists with risk mitigation through the Plan of Action and Milestones (POA&Ms) process, verifying that internal IT support actions address identified risks.
  • Assists with the development and implementation of information assurance policies and procedures to ensure compliance with organizational and regulatory requirements.
  • Supports incident response activities, including investigating security incidents, documenting findings, and coordinating remediation with relevant teams.
  • Maintains accurate documentation of security incidents, assessments, and compliance activities for audit and reporting purposes.
  • Participates in internal and external audits to assess compliance with security policies and regulatory requirements, providing recommendations for improvement.
  • Works closely with IT staff and other departments to ensure security measures are integrated into system development and operational processes.

Required Qualifications

  • Education: Associate’s degree in computer science or a related field
  • Experience: 2 years of professional experience in information security, risk management, or a related field (including internships or coursework)
  • Basic knowledge of security tools, network security principles, and vulnerability assessment methodologies
  • Working knowledge of U.S. Government security policy, including Department of Defense and appropriate civil agencies such as NIST, plus commercial “best practices”
  • Working knowledge of standard information security products, including firewalls, intrusion detection systems, anti-virus systems, vulnerability testing, and security analysis tools
  • Familiarity with STIG Viewer
  • Exposure to RMF and the A&A process
  • Exposure to a Governance, Risk and Compliance (GRC) tool such as eMASS (preferred), CSAM, or XACTA
  • Exposure to cloud computing implementation and maintenance, preferably with AWS
  • Strong analytical and problem-solving skills, with the ability to assess complex security issues and propose solutions
  • Excellent verbal and written communication skills, including the ability to explain technical concepts to non-technical stakeholders
  • Ability to work effectively independently and as part of a team in a fast-paced environment
  • Clearance: Active Secret Clearance or current interim
  • IAT level: IAT Level I certification
  • Certifications: CompTIA A+, Network+, CCNA (Security+ satisfies the requirement)
  • Additional computing environment certification (examples: Server+, Linux+, AWS Certified Solution Architect, or equivalent)

Preferred Tools and Technical Areas

  • Working experience with the DoD’s Assured Compliance Assessment Solution (ACAS) tool is preferred
  • Familiarity with cloud environments, including AWS

Technologies

  • DISA STIG Viewer; Security Technical Implementation Guides (STIGs)
  • Assessment and Authorization (A&A); Risk Management Framework (RMF)
  • Plan of Action and Milestones (POA&Ms)
  • DoD’s Assured Compliance Assessment Solution (ACAS)
  • NIST
  • Firewalls; intrusion detection systems; anti-virus systems; vulnerability testing; security analysis tools
  • Governance, Risk and Compliance (GRC) tools: eMASS, CSAM, XACTA
  • Cloud computing: AWS
  • CompTIA A+, Network+, CCNA, Security+
  • Server+, Linux+, AWS Certified Solution Architect

Similar Jobs