Cybersecurity Analyst II/ISSO
Job in
Marlborough, Middlesex County, Massachusetts, 01752, USA
Listed on 2026-08-31
Listing for:
Spectrum Control
Full Time
position Listed on 2026-08-31
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
POSITION SUMMARY:
The Cybersecurity Analyst II/ISSO protects enterprise systems, networks, and data by monitoring for threats, investigating security events, and managing vulnerability remediation. This role also owns a significant share of the security program's documentation and enablement work — authoring incident response playbooks, maintaining the security knowledgebase, and running the company's cybersecurity awareness training and newsletter. The analyst operates with limited supervision on routine work, escalates complex incidents to senior staff, and mentors Analyst I team members.
COMPENSATION RANGE:
The expected compensation range for this position is $85,000 - $120,000 annually.
KEY RESPONSIBILITIES:
Threat Detection & Monitoring (~20%)Monitor SIEM, EDR, email security, and network security tooling for indicators of compromise
Triage and investigate security alerts; determine scope, severity, and false-positive status
Tune detection rules to reduce alert noise and recommend new detection logic
Conduct basic threat hunting using threat intelligence feeds and indicators of compromise
Review and validate escalations from Analyst I staff
Incident Response & Playbook Development (~20%)Serve as a first- and second-tier responder for security incidents
Author, test, and maintain incident response playbooks for recurring incident types including phishing, ransomware, account compromise, data exfiltration, insider risk, and production system events
Partner with senior security staff, IT, and business owners to validate playbook steps and escalation paths
Contain and remediate endpoint and account compromises
Document incident timelines, root cause, and lessons learned
Feed post-incident findings back into playbooks and detection logic
Participate in an on-call rotation and facilitate tabletop exercises
Vulnerability Management (~20%)Run and interpret vulnerability scans across servers, endpoints, network devices, and cloud workloads
Prioritize findings by exploitability and business impact
Drive remediation with IT and application owners and escalate blocked items
Track remediation SLAs and report on aging and recurring findings
Validate patching and configuration hardening against CIS and vendor baselines
Information System Security Officer (ISSO) (20%)Support implementation and execution of NIST Risk Management Framework (RMF)
Develop, maintain, and review system security documentation including:
System security plans (SSPs), Hardware/software baselines, Configuration diagrams, and RMF policies
Perform continuous monitoring of system configurations, user accounts, privileged access, and audit logs Track, assess, and patch system vulnerabilities and findings using vulnerability managers and STIGSEnsure changes to system hardware, software, architecture, and configurations are evaluated for cybersecurity impact
Assess system compliance with NIST 800-53 Rev5 security controls, organizational policies, and contractual (DD254) requirements
Documentation & Knowledge Ownership (~10%)Own the cybersecurity knowledgebase — create, review, and retire articles covering security processes, tool usage, request workflows, and troubleshooting guidance
Ensure documented processes are accurate, versioned, discoverable, and written for the intended audience
Establish and enforce a review cadence so articles do not go stale
Translate undocumented tribal knowledge into repeatable written process
Coach Analyst I staff on documentation standards
Security Awareness Training & Communications (~10%)Own the enterprise cybersecurity awareness training program including curriculum selection, module assignment, tracking, and completion reporting
Create and publish the recurring cybersecurity newsletter, translating current threats and internal trends into practical guidance for a non-technical audience
Design and run phishing simulation campaigns; analyze results and target follow-up training
Deliver…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×