Cyber Security Analyst
Listed on 2026-08-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection
PiTech Solutions Inc is pleased to provide a comprehensive assessment of a federal agency's cybersecurity. Our mandate is a team of professionals that support an entire federal agency's technology infrastructure, cybersecurity posture and cloud services.
We will deliver six months of structured, evidence-based assessment work culminating in actionable findings across eight domains — organizational, governance, operational, infrastructure, cybersecurity, contracts and licensing, modernization, and data/AI readiness. Every recommendation is weighted against priorities, cybersecurity, and compliance first, followed by governance accountability, operational performance, technology lifecycle, and cost efficiency.
Job Description:
Cybersecurity Analyst (Federal Assessments Top Secret Clearance)
Position Summary
PiTech Solutions Inc. is seeking a Cybersecurity Analyst to support independent, evidence-based cybersecurity assessments for U.S. federal agencies. This role plans and executes security control assessments, technical testing, and compliance evaluations aligned to federal requirements (e.g., FISMA, NIST, and agency-specific policies). The analyst documents objective evidence, identifies risk and root cause, and produces clear, actionable recommendations for executives and technical teams.
This position requires an active Top Secret (TS) clearance (with eligibility to maintain access as required).
- Assessment planning and scoping: Participate in discovery with agency stakeholders to confirm system boundaries, environments (on-prem/cloud/hybrid), interconnections, data types, and mission priorities; define assessment objectives, methodology, schedule, sampling strategy, and evidence request lists.
- Security control assessment (SCA): Evaluate management, operational, and technical controls against applicable baselines and overlays (e.g., NIST SP 800-53); map implementation statements to objective evidence and document assessment results, rationale, and traceability.
- Risk Management Framework (RMF) support: Assist with RMF activities across the system lifecycle (categorization, selection, implementation validation, assessment, authorization support, and continuous monitoring); review and validate SSPs, SAP/SAR artifacts, POA&Ms, and continuous monitoring strategies.
- Technical validation and testing: Perform hands‑on security testing where authorized, including configuration reviews, vulnerability validation, log review, and control verification across endpoints, servers, network devices, IAM services, cloud resources, and security tooling.
- Vulnerability and configuration assessment: Execute and analyze results from automated scans (credentialed when possible), benchmark configurations (e.g., CIS/STIG guidance as applicable), and identify false positives/negatives; develop prioritized remediation recommendations.
- Cloud security assessment: Assess cloud service configurations and controls (e.g., identity, network segmentation, encryption, logging/monitoring, key management, and shared responsibility considerations) across major CSP platforms and FedRAMP-aligned control expectations.
- Incident readiness and operational security: Evaluate detection and response capabilities (SOC processes, playbooks, alerting, escalation, forensics readiness, and tabletop exercises); assess logging coverage and retention to support investigations and compliance.
- Policy, governance, and program reviews: Assess cybersecurity program documentation, governance, and oversight processes (e.g., risk acceptance, exception handling, asset management, vulnerability management, secure configuration, change control, and third‑party risk).
- Evidence management: Collect, organize, and protect sensitive assessment materials; maintain a defensible evidence trail, including interview notes, screenshots, configuration exports, scan outputs, and log samples in accordance with handling requirements.
- Reporting and briefings: Draft assessment deliverables (findings, risk ratings, root cause, impacts, and recommendations) and present results to technical teams and executive leadership; tailor communications for both technical depth…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).