Cyber Security Analyst
Listed on 2026-05-30
-
IT/Tech
Cybersecurity, Information Security, IT Support
Job Details
- Location:
Dayton, OH 45433 - Position Type:
Full Time - Education Level: 4 Year Degree
- Travel Percentage:
None - Job Shift: Day
- Job Category:
Information Technology - Position Title:
Cyber Security Analyst IV (RMF / Vulnerability Management / Compliance Support) - Program Information:
- Location:
Wright-Patterson Air Force Base - Employment Type:
Full-Time - Work Schedule:
Onsite Support - Clearance Requirement:
Active Secret Clearance or ability to obtain and maintain favorable Tier 3/Tier 5 eligibility - Citizenship Requirement: U.S. Citizenship Required
- Certification Requirement:
Must meet DoD 8140/8570 IAM or IAT baseline certification requirements within 6 months of hire
- Location:
The Cyber Security Analyst IV provides advanced cybersecurity engineering, RMF compliance, vulnerability management, continuous monitoring, and audit readiness support for Air Force Financial Management systems and enterprise infrastructure environments. This position supports the implementation and sustainment of Risk Management Framework (RMF) activities in accordance with DoDI 8510.01, NIST SP 800-53 Rev 5, DISA STIG requirements, and Air Force cybersecurity policies and enterprise security controls.
The Analyst works closely with ISSMs, ISSOs, System Administrators, Database Administrators, Configuration Managers, and Government stakeholders to maintain compliant, secure, and operational systems across the enterprise environment.
- Support the full RMF lifecycle for assigned systems and applications.
- Develop, maintain, and update RMF documentation including:
- System Security Plans (SSPs)
- Risk Assessment Reports (RARs)
- Security Control Traceability Matrices (SCTMs)
- Plans of Action & Milestones (POA&Ms)
- Continuous Monitoring documentation
- Authorization and accreditation artifacts
- Maintain and manage cybersecurity packages within eMASS and related RMF tracking systems.
- Conduct vulnerability assessments using approved enterprise vulnerability management tools.
- Analyze vulnerability scan results and coordinate remediation activities with system administrators and engineering teams.
- Support DISA STIG implementation, validation, and compliance efforts.
- Assist with ACAS/Nessus vulnerability scanning activities and remediation tracking.
- Review security event logs, audit logs, and security alerts for anomalous or suspicious activity.
- Support cybersecurity incident analysis, reporting, documentation, and coordination activities in accordance with established procedures.
- Support continuous monitoring initiatives and cybersecurity compliance reporting.
- Assist with cybersecurity inspections, audits, CCRI preparation, and remediation activities.
- Coordinate cybersecurity requirements with government stakeholders, engineers, and support teams.
- Support secure system configuration management and baseline compliance activities.
- Develop cybersecurity status reports, risk summaries, and compliance documentation for leadership review.
- Assist with implementation and validation of security controls in accordance with RMF requirements.
- Utilize scripting and automation tools where appropriate to support compliance validation, reporting, and remediation tracking.
- RMF / Compliance:
- Risk Management Framework (RMF)
- NIST SP 800-53 Rev 5
- DoDI 8510.01
- DISA STIG implementation and validation
- Continuous Monitoring (Con Mon)
- POA&M management
- Security control assessment support
- Audit and compliance reporting
- Security & Vulnerability Management Tools:
- eMASS
- ACAS/Nessus
- Tenable.io
- Qualys
- Splunk
- QRadar
- Solar Winds SEM
- Endpoint & Infrastructure Security:
- Trellix/HBSS
- Crowd Strike Falcon
- Microsoft Defender
- McAfee Endpoint Security
- Operating Systems & Enterprise Platforms:
- Windows Server
- Linux
- VMware
- Citrix
- Active Directory
- Azure Active Directory
- DB2
- IBM Web Sphere
- Scripting / Automation:
Experience with one or more of Power Shell, Python, Bash.
- Bachelor’s degree in Cybersecurity, Information Assurance, Information Technology, Computer Science, Engineering, or related field.
- Equivalent combination of education, military training, certifications, and directly related experience may be considered.
- 7–10+ years of cybersecurity or information…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).