Security Analyst
Computer World Services
Apply to this job|
Computer World Services (CWS) is seeking an experienced Security Analyst to support enterprise cybersecurity operations within a Federal IT environment. The Security Analyst will be responsible for administering and maintaining security technologies, identifying and mitigating vulnerabilities, supporting vulnerability management initiatives, and serving as a technical advisor to infrastructure and application teams.
The successful candidate will possess strong experience with vulnerability management, firewall administration, security monitoring, and Federal cybersecurity compliance. This individual will work closely with infrastructure engineers, application developers, and security stakeholders to improve the organization's security posture while ensuring compliance with NIST, FISMA, NIH/HHS, and other Federal security requirements. |
Key Tasks & Responsibilities
- Serve as the primary administrator for Tenable Security Center (SC) and Nessus vulnerability scanners.
- Perform authenticated and unauthenticated vulnerability scans across enterprise systems.
- Analyze scan results and prioritize remediation activities using CVSS scores, CISA Known Exploited Vulnerabilities (KEV), and organizational risk criteria.
- Produce recurring vulnerability reports for management, system owners, and compliance activities.
- Track remediation progress and validate vulnerability closures.
- Manage vulnerability waivers, risk acceptance documentation, and exception tracking.
- Monitor End-of-Life (EOL), End-of-Support (EOS), and Binding Operational Directive (BOD) vulnerability requirements.
- Coordinate with stakeholders across technical teams to drive timely vulnerability remediation efforts.
- Experience with:
- Firewall Management
- Cisco
- Checkpoint
- IDS/IPS technologies
- Log aggregation systems (Splunk)
- File integrity monitoring solutions
- Red Hat Linux
- Windows workstation and server OS
- MacOS
- Participate in incident investigations and support cybersecurity response activities.
- Assist with security assessments and continuous monitoring activities.
- Perform application vulnerability scanning.
- Coordinate vulnerability remediation with application owners.
- Support troubleshooting for application security issues.
- Partner with the Application Development team to identify security improvements throughout the software lifecycle.
- NIST 800-53
- FISMA
- NIH/HHS cybersecurity policies
- CISA Binding Operational Directives (BODs)
- Continuous Monitoring (ConMon)
- Executive vulnerability reports
- Compliance dashboards
- Monthly security metrics
- Remediation status reports
- Coordinating testing schedules
- Supporting external penetration testing teams
- Managing findings
- Tracking remediation efforts
- Validating corrective actions
- Producing final response documentation
- Customer requests
- Security consultations
- Incident investigations
- Security engineering support
- Technical documentation
- NIST 800-53
- NIST Cybersecurity Framework (CSF)
- Risk Management Framework (RMF)
- FISMA
- CISA Binding Operational Directives (BODs)
- Continuous Monitoring (ConMon)
|
Essential Duties and Responsibilities Vulnerability Management
Security Operations
Application & Infrastructure Security
Compliance & Reporting Support organizational compliance initiatives including: Prepare:
Penetration Testing Remediation Support Serve as the primary coordinator for annual penetration testing activities. Responsibilities include:
Operational Support Provide day-to-day operational cybersecurity support including:
Security Frameworks Working knowledge of:
|
Education & Experience
- Bachelor’s degree in Computer Science, Information Systems, Engineering, or related field. Equivalent experience.
- 5–8 years of experience in information security, network security, or related fields. Experience working in Data Center or hybrid infrastructure environments
Education
Experience
Certifications
- CompTIA Security+
- Tenable Certified Professional (TCP)
- ITIL certification preferred.
One or more of the following preferred:
Security Clearance
- Applicants must be able to obtain a Public Trust clearance
Summary
Manage vulnerabilities, security operations, compliance, and support cybersecurity initiatives.
Job title
Security Analyst
Experience level
5-8 years
Minimum experience
5+ years exp
Industry
it services
Location requirements
Morrisville, NC; remote work not specified
Salary
Not specified
Management role
No
Required skills
Preferred skills
Specializations
Structured locations inferred from the posting.
Morrisville, NC, USA