×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity Analyst II​/ISSO

Job in Marlborough, Middlesex County, Massachusetts, 01752, USA
Listing for: Spectrum Control
Full Time position
Listed on 2026-08-31
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 85000 - 120000 USD Yearly USD 85000.00 120000.00 YEAR
Job Description & How to Apply Below
At Spectrum Control, most departments operate on a 4-day, 10-hour work schedule in exchange for a 3-day weekend. We offer competitive wages and PTO, plus our benefits begin on day 1 of employment. Come join a workforce where we put you first!

POSITION SUMMARY:

The Cybersecurity Analyst II/ISSO protects enterprise systems, networks, and data by monitoring for threats, investigating security events, and managing vulnerability remediation. This role also owns a significant share of the security program's documentation and enablement work — authoring incident response playbooks, maintaining the security knowledgebase, and running the company's cybersecurity awareness training and newsletter. The analyst operates with limited supervision on routine work, escalates complex incidents to senior staff, and mentors Analyst I team members.

COMPENSATION RANGE:
The expected compensation range for this position is $85,000 - $120,000 annually.

KEY RESPONSIBILITIES:

Threat Detection & Monitoring (~20%)Monitor SIEM, EDR, email security, and network security tooling for indicators of compromise

Triage and investigate security alerts; determine scope, severity, and false-positive status

Tune detection rules to reduce alert noise and recommend new detection logic

Conduct basic threat hunting using threat intelligence feeds and indicators of compromise

Review and validate escalations from Analyst I staff

Incident Response & Playbook Development (~20%)Serve as a first- and second-tier responder for security incidents

Author, test, and maintain incident response playbooks for recurring incident types including phishing, ransomware, account compromise, data exfiltration, insider risk, and production system events

Partner with senior security staff, IT, and business owners to validate playbook steps and escalation paths

Contain and remediate endpoint and account compromises

Document incident timelines, root cause, and lessons learned

Feed post-incident findings back into playbooks and detection logic

Participate in an on-call rotation and facilitate tabletop exercises

Vulnerability Management (~20%)Run and interpret vulnerability scans across servers, endpoints, network devices, and cloud workloads

Prioritize findings by exploitability and business impact

Drive remediation with IT and application owners and escalate blocked items

Track remediation SLAs and report on aging and recurring findings

Validate patching and configuration hardening against CIS and vendor baselines

Information System Security Officer (ISSO) (20%)Support implementation and execution of NIST Risk Management Framework (RMF)
Develop, maintain, and review system security documentation including:
System security plans (SSPs), Hardware/software baselines, Configuration diagrams, and RMF policies

Perform continuous monitoring of system configurations, user accounts, privileged access, and audit logs Track, assess, and patch system vulnerabilities and findings using vulnerability managers and STIGSEnsure changes to system hardware, software, architecture, and configurations are evaluated for cybersecurity impact

Assess system compliance with NIST 800-53 Rev5 security controls, organizational policies, and contractual (DD254) requirements

Documentation & Knowledge Ownership (~10%)Own the cybersecurity knowledgebase — create, review, and retire articles covering security processes, tool usage, request workflows, and troubleshooting guidance

Ensure documented processes are accurate, versioned, discoverable, and written for the intended audience

Establish and enforce a review cadence so articles do not go stale

Translate undocumented tribal knowledge into repeatable written process

Coach Analyst I staff on documentation standards

Security Awareness Training & Communications (~10%)Own the enterprise cybersecurity awareness training program including curriculum selection, module assignment, tracking, and completion reporting

Create and publish the recurring cybersecurity newsletter, translating current threats and internal trends into practical guidance for a non-technical audience

Design and run phishing simulation campaigns; analyze results and target follow-up training

Deliver…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary