Senior Cyber Security Analyst
Job Description
TrellisWare Technologies is hiring a Senior Cyber Security Analyst to help strengthen the organization’s cybersecurity program across governance and compliance. In this onsite role in San Diego, CA, you will work alongside IT and Engineering teams to define security requirements, validate control effectiveness, and ensure that policies, procedures, and evidence align with day-to-day operational reality in both cloud and on-premises environments.
Key Responsibilities
- Provide governance oversight for cybersecurity operations, including vulnerability result validation and incident documentation.
- Develop, maintain, and update security policies and procedures to align with regulatory and operational requirements.
- Evaluate security controls, identify compliance gaps, and coordinate corrective actions with IT and Engineering to improve the organization’s risk posture.
- Support audit readiness activities, including evidence validation, traceability, organization, and direct support during formal assessments.
- Track audit findings and remediation progress through structured action plans and closure.
- Participate in risk assessments and deliver risk-based recommendations to leadership.
- Support access control governance, including least privilege and separation of duties.
- Maintain accurate documentation that reflects system configurations, ownership, and control implementation.
- Ensure policies, procedures, and evidence accurately reflect operational practices and implemented controls.
- Coordinate with IT, Engineering, Program Management, and Security leadership to ensure security initiatives are executed effectively.
- Review and validate vulnerability and configuration assessment results to ensure findings are accurate, risk ranked, and mapped to applicable compliance controls.
- Leverage ISSM-aligned experience to support governance, audit preparation, and remediation tracking.
- Support security awareness and training efforts aligned with organizational policies and procedures.
- Perform other duties as assigned.
Requirements
- Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, or related field required.
- Minimum of four (4) years of experience in a combination of risk management, information security, IT, and Cloud work.
- CompTIA Security+ CE or ability to obtain within 6 months of start date.
- Security qualifications are a bonus, including CISSP and CISM.
- Demonstrated knowledge of RMF, NIST, NISPOM, system audits, vulnerability scanning, and DCSA security package development.
- Experience working with NIST-based frameworks and supporting control implementation.
- Working knowledge of security technologies sufficient to assess control effectiveness, interpret findings, and validate compliance evidence.
- Ability to review, assess, and communicate vulnerability findings and remediation recommendations.
- Strong collaboration and interpersonal skills.
- Strong initiative, proactive work ethic, and prioritization skills.
- Trustable judgment and analytical problem-solving skills.
- Effective execution and decision making; champions change and promotes innovation.
- Strong written and verbal communication skills.
- Ability to obtain and maintain an active Secret Clearance, which requires U.S. citizenship.
- Active or recent (within 2 years) Security Clearance is a plus.
Preferred Experience
- Experience supporting CMMC readiness or formal audits.
- Prior experience in an ISSM or equivalent security governance role.
- Experience presenting risk, findings, or security posture to leadership.
Technologies
- CompTIA Security+ CE
- CISSP
- CISM
- RMF
- NIST
- NISPOM
- DCSA security package
Compensation & Location
- Location: San Diego, CA (onsite)
- Pay range: USD 120,000 - 150,000 per year
Security Clearance and Screening Notes
Many TrellisWare positions require a security clearance or the ability to obtain one. Security clearances may be granted only to U.S. citizens. Applicants accepting a conditional offer of employment may be subject to government security investigations and must meet eligibility requirements for access to classified information.
Additional Disclosures
The information provided above is not intended to be an exhaustive list of responsibilities, duties, or skills required for the position. The company may change, assign, or reassign duties and responsibilities at any time. As part of onboarding, background checks may be conducted where legally permitted and appropriate for the role, in accordance with applicable laws, regulations, and privacy requirements.