Cyber Security Analyst II; Developer
Listed on 2026-07-18
-
IT/Tech
Cybersecurity, Network Security, Information Security
Benefits include paid holidays, paid time off, 401K with employer match, dental, vision, health insurance plans, as well as life and disability benefits.
Position OverviewThe Cyber Security Analyst II (Developer) supports cybersecurity operations through vulnerability management, security monitoring, compliance assessment, and the development of custom tools, automation, and dashboards. Using platforms such as ACAS, eMASS, HBSS/ESS, Microsoft 365 Defender, and SIEM technologies, this role develops and sustains solutions that support scan operations, threat detection, reporting, quarantine workflows, and risk management. The position also maintains an IT Common Operational Picture (COP) to provide near real-time cybersecurity visibility and collaborates with technical teams and leadership to improve automation, operational efficiency, and security posture.
MajorActivities
- Conduct vulnerability scans of IT assets as requested from tickets or as directed by the Cybersecurity Manager.
- Apply knowledge of monitoring, analyzing, detecting, and responding to Cyber events and incidents within information systems and networks.
- Advise on an integrated, dynamic Cyber defense and leverage Cybersecurity solutions to deliver Cybersecurity operational services, including intrusion detection and prevention, situational awareness of network intrusions, security events, data spillage, and incident response actions.
- Assess IT assets for Cybersecurity compliance in accordance with DISA STIG requirements.
- Develop POA&Ms to track overdue vulnerabilities, STIG deviations, and approved risk‑based remediation actions.
- Review and investigate security alerts and incidents from Microsoft 365 Defender and other Cybersecurity monitoring platforms.
- Utilize eMASS to maintain and update POA&M status.
- Review device compliance status from HBSS/ESS.
- Work with NEC Operations team members to remediate and mitigate security vulnerabilities.
- Review the latest Cybersecurity intelligence information and provide recommendations to improve the Cybersecurity posture.
- Develop, maintain, and enhance locally created Cyber tools and automation supporting ACAS/Tenable scan execution, scan scheduling, vulnerability analysis, reporting, remediation tracking, and automated analysis of scan results.
- Develop and maintain toolsets that support quarantine recommendations, workflow actions, or system isolation processes based on scan results, approved business rules, and Cybersecurity Manager direction.
- Develop scripts, queries, dashboards, automated reports, and visualizations that support vulnerability management, compliance visibility, operational decision‑making, and key Cybersecurity metrics.
- Develop and sustain an IT Common Operational Picture (COP) for use by the IT Monitoring team, Cyber team, and leadership, integrating approved Cybersecurity and IT operations data sources.
- Assist in defining technical requirements, data sources, business rules, workflows, and acceptance criteria for locally developed Cyber tools.
- Maintain source code, scripts, configuration files, technical documentation, user guides, and standard operating procedures for locally developed tools; troubleshoot, debug, test, and validate Cyber tools and automation workflows to ensure accuracy, reliability, security, and compliance.
- Coordinate with Cyber analysts, system administrators, network administrators, database administrators, and monitoring teams to improve automation, operational visibility, Cybersecurity processes, and workflow optimization.
- Perform other duties as appropriate and as assigned.
- Ability to accurately and efficiently analyze log files, firewall logs, IDS logs, endpoint security alerts, and vulnerability scan data to identify possible threats to network security and support incident response actions.
- Working knowledge of Host Based Security Systems, Endpoint Security Solutions, ACAS vulnerability scanning software, Security Information and Event Management analysis, and Information Assurance Vulnerability Alert management.
- Ability to develop scripts, tools, dashboards, or automation to support Cybersecurity operations, vulnerability management,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).