Cybersecurity Analyst - DoD RMF
Acas And Compliance Monitoring
Cybersecurity Tools
Data Security
Endpoint Security
Facilities Management
Information Security
InfoSec
Management
Project Management
Risk Management
Rmf
Security
Security Compliance
Security Information And Event Management
Security Operations
Security Standards
Security Testing
Tenable
Vulnerability Management
Job Description
Support continuous cybersecurity monitoring, vulnerability management, and RMF compliance for a large-scale DoD environment.
Responsibilities
- Monitor enterprise cybersecurity posture using ACAS, Tenable Security Center, Trellix ePO, Microsoft Defender for Endpoint, SIEM platforms, and centralized enterprise logging solutions
- Analyze security events using centralized logging and correlation platforms including ELK Stack, SYSLOG, SIEM, and ELICSAR
- Develop recurring cybersecurity metrics, dashboards, executive reports, and vulnerability trend analysis
- Monitor compliance status and verify remediation of cybersecurity findings
- Track zero-day vulnerabilities, CVEs, IAVMs, and emerging threats
- Prioritize remediation activities based on organizational risk
- Create operational reporting that supports cybersecurity leadership and RMF requirements
- Perform enterprise vulnerability assessments using ACAS, Nessus, Nessus Agents, Nessus Network Monitor, and related tooling
- Differentiate vulnerability findings from policy compliance findings
- Validate remediation actions and verify closure; identify false positives and coordinate with system owners to resolve findings
- Support continuous vulnerability management processes
- Assist with security baseline reviews and configuration compliance assessments
- Support RMF lifecycle activities using eMASS
- Assist with maintaining Authorization to Operate (ATO) documentation
- Support cybersecurity inspections and audits
- Monitor compliance with NIST 800-53, DISA STIGs, Security Technical Implementation Guides, and DoD cybersecurity policies
- Monitor enterprise IDS/IPS, firewalls, routers, switches, and endpoint security solutions; correlate host-based and network-based security events
- Analyze network traffic and SYSLOG events to identify Indicators of Compromise (IOCs)
- Support implementation of defensive cyber operations; participate in threat hunting and security investigations
- Assist with deployment and maintenance of enterprise cybersecurity tools
- Perform incident detection, triage, containment, eradication, and recovery; investigate alerts and conduct root cause analysis
- Collect digital evidence, document incident timelines and remediation activities, and coordinate with government cyber organizations and external incident response teams
- Develop incident reports and lessons learned
Requirements
- Active DoD Secret Security Clearance
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related discipline
- Minimum 5 years supporting DoD enterprise cybersecurity operations, vulnerability management, security monitoring, and reporting
- DoD 8570/8140 IAT Level III Certification (CASP+, CISSP, or equivalent)
- Experience supporting Risk Management Framework (RMF) processes and cybersecurity compliance
- Experience producing cybersecurity reports, vulnerability assessments, compliance metrics, and executive reporting
- Strong understanding of enterprise security architecture, endpoint security, network security, and incident response
Technologies
- ACAS, Tenable Security Center, Trellix ePO
- Microsoft Defender for Endpoint (MDE)
- SIEM platforms, centralized logging solutions, ELK Stack, SYSLOG, ELICSAR
- eMASS
- Nessus, Nessus Agents, Nessus Network Monitor
- ESS / HBSS
- IDS / IPS
- Firewalls, routers, switches, NIDS / NIPS
Location
- 2580 E HWY 98, Tyndall AFB, FL 32403 (On-Site)
- M-F; in person
Employment Type
- Full Time/Perm
Pay
- $100,000.00 - $140,000.00 per year
Relocation
- Candidates willing to relocate within 2-4 weeks from offer will be considered
- Relocate before starting work (Tyndall AFB, FL 32403 required)
Available Shifts
- 11:00 PM – 9:00 AM (overnight shift)
- 2:00 PM – 12:00 AM (Midnight)
- 7:00 AM – 5:00 PM (must be able to support this shift to cover others; not your regular shift)
Benefits
- 401(k) and 401(k) matching
- Dental insurance
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Retirement plan
- Vision insurance
Application Questions
- Describe your experience with eMASS (Enterprise Mission Assurance Support Services)
- What is your annual compensation target (range determined by years of experience, education level, and expertise)?
- Do you have experience with ELICSAR (Enterprise Logging Ingest & Cyber Situational Awareness Refinery)?
- What is the difference between host-based security and Network level security?
- Do you have experience with Tenable Nessus Network Monitor and Tenable Nessus Agents?
- What is port scanning?