Cyber Security Analyst II
Listed on 2026-08-23
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, Security Management & Operations
Job Objective
The Cyber Security Analyst II is the senior technical practitioner on a small, high-impact security team supporting a Defense Industrial Base (DIB) environment handling controlled data. This role is the hands-on owner of our Microsoft security stack and the primary author of the policies, procedures, and evidence artifacts required to sustain our CMMC Level 2 posture under NIST SP 800-171. The analyst works directly with the Information & Cyber Security Manager to mature the program, own cross-functional processes, and mentor a junior analyst.
Responsibilities- Microsoft Security Operations:
Shared ownership of day-to-day administration and tuning of Microsoft Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Entra (Conditional Access, PIM, Identity Protection), Intune (compliance policies, configuration profiles, update rings, app protection), and Purview (DLP, Insider Risk, Information Protection). - Policy and Procedure Authorship:
Draft, maintain, and operationalize written policies and procedures mapped to NIST SP 800-171 Rev. 2 and CMMC Level 2 practices. Translate control language into runbooks, checklists, and evidence artifacts that an assessor can verify. - Cross-Functional Process Ownership:
Partner with HR, IT, and Facility Security to develop and improve the end-to-end joiner/mover/leaver process, quarterly access reviews, privileged access management, and onboarding/offboarding of authorized users. - Vulnerability and Patch Management:
Run the recurring vulnerability management cycle (Defender Vulnerability Management, Nessus, or equivalent): triage, prioritize, track SLAs, and report on remediation against a defined framework. - Incident Response:
Act as tier-2 responder for Defender and Entra alerts; investigate, contain, and document incidents; lead post-incident reviews; maintain and exercise the incident response plan. - Evidence and Audit Support:
Collect and maintain evidence for internal self-assessments and customer audits. Maintain the System Security Plan (SSP) and POA&M alongside the Security Manager. - Security Awareness and Training:
Execute and measure the monthly phishing simulation program and deliver targeted training for elevated-risk roles. - Mentoring:
Provide technical direction and review for the Cyber Security Analyst I and serve as the escalation point for their work. - Other Duties:
Other duties as assigned.
The Cyber Security Analyst II is the senior technical practitioner on a small, high-impact security team supporting a Defense Industrial Base (DIB) environment handling controlled data. This role is the hands-on owner of our Microsoft security stack and the primary author of the policies, procedures, and evidence artifacts required to sustain our CMMC Level 2 posture under NIST SP 800-171. The analyst works directly with the Information & Cyber Security Manager to mature the program, own cross-functional processes, and mentor a junior analyst.
Responsibilities- Microsoft Security Operations:
Shared ownership of day-to-day administration and tuning of Microsoft Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Entra (Conditional Access, PIM, Identity Protection), Intune (compliance policies, configuration profiles, update rings, app protection), and Purview (DLP, Insider Risk, Information Protection). - Policy and Procedure Authorship:
Draft, maintain, and operationalize written policies and procedures mapped to NIST SP 800-171 Rev. 2 and CMMC Level 2 practices. Translate control language into runbooks, checklists, and evidence artifacts that an assessor can verify. - Cross-Functional Process Ownership:
Partner with HR, IT, and Facility Security to develop and improve the end-to-end joiner/mover/leaver process, quarterly access reviews, privileged access management, and onboarding/offboarding of authorized users. - Vulnerability and Patch Management:
Run the recurring vulnerability management cycle (Defender Vulnerability Management, Nessus, or equivalent): triage, prioritize, track SLAs, and report on remediation against a defined framework. - Incident Response:
Act as tier-2 responder for Defender and Entra…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).