Cybersecurity Analyst
GovernmentJobs.com
Cybersecurity Analyst
The Cybersecurity Analyst supports the county's security posture by performing vulnerability assessments, owning the vulnerability management program, leading Microsoft Purview data classification operations, and contributing to compliance activities aligned to the NIST Cybersecurity Framework (CSF). This is an early career security analyst position in an expanding cybersecurity operation. The analyst will own defined program areas within vulnerability management and data classification, draft cyber security policy and standards documentation, and manage the operational components of the county's cybersecurity awareness training program in coordination with the ITS training team. The role reports to the network security administrator and works across ITS teams and county departments to identify, assess, and remediate security risks to county systems and data.
Essential duties and responsibilities include:
- Own the vulnerability management program lifecycle — define scan schedules and SLA thresholds, conduct regular vulnerability scans across county infrastructure including servers, endpoints, network devices, and cloud-hosted services, track remediation trending over time, and produce actionable risk-ranked findings reports for ITS leadership.
- Lead Microsoft Purview onboarding for county departments including departmental collaboration, sensitivity label taxonomy design, content classification rule maintenance, and exception adjudication. Ensure county data classification standards are enforced consistently across Microsoft 365, SharePoint, Azure, and on-premises repositories.
- Support compliance and data classification activities under HIPAA, CJIS Security Policy, and applicable state and federal data privacy requirements by mapping technical controls to framework requirements and documenting compliance status.
- Draft cybersecurity policies, standards, and procedures grounded in the NIST Cybersecurity Framework for review by the Network Security Administrator, including documentation covering asset management, access control, and incident detection categories.
- Monitor security alerts from existing tools (endpoint protection, email filtering, firewall logs) and triage potential incidents, escalating confirmed threats per established procedures.
- Coordinate patch management activities with infrastructure and applications teams to ensure timely remediation of known vulnerabilities, tracking patch compliance against defined SLAs.
- Support ITS in conducting risk assessments for new technology procurements and system changes using ITS security and risk assessment rubrics.
- Manage the compliance components of the county's mandatory cybersecurity awareness training program in coordination with the ITS training team, including phishing simulation campaign execution, compliance tracking, automated notifications, and credential suspension workflows for overdue participants. Produce and deliver quarterly metrics reports to ITS leadership on training completion rates, simulation results, and program effectiveness.
- Participate in incident response activities including detection, containment, documentation, and post-incident review. Contribute to the development of incident response playbooks as the county builds its response capability.
- Assist in updating documentation on security controls, vulnerability management metrics, and compliance posture for reporting to ITS leadership and county stakeholders.
- Research emerging threats, vulnerabilities, and attack techniques relevant to local government environments.
- Assist with identity and access management reviews, including periodic access certifications and privileged account audits across county systems.
Required knowledge, skills, and abilities include:
- Working knowledge of vulnerability scanning tools (e.g., Nessus, Microsoft Defender Vulnerability Management, Qualys or similar) and the ability to interpret scan results and prioritize remediation based on risk.
- Familiarity with the NIST Cybersecurity Framework (CSF) and the ability to map organizational practices to CSF categories and subcategories.
- Understanding of data classification concepts and applied classification and data loss prevention frameworks.
- Practical experience with Microsoft Purview Information Protection, sensitivity labels, or comparable data classification tooling and in onboarding businesses (e.g., teams, offices, departments) with onboarding and utilizing Purview including cloud (MS SharePoint and Azure) and on-prem repositories.
- Knowledge of common network protocols, operating systems for Microsoft (Windows Server, Windows 10/11), and Active Directory/Entra ID administration sufficient to understand security implications.
- Familiarity with HIPAA Security Rule requirements.
- Ability to produce clear, concise written reports and briefings that communicate technical findings to non-technical audiences, including department heads and elected officials.
- Ability to work across teams and organizational boundaries, coordinating remediation activities with staff who do not report to ITS.
- Working understanding of common attack vectors, the MITRE ATT&CK framework, and how threat intelligence applies to vulnerability prioritization.
- Ability to manage competing priorities and maintain documentation discipline in an environment where processes are being established for the first time.
Required qualifications include:
- Bachelor's degree in cybersecurity, information technology, computer science, or a related field. An equivalent combination of education and directly relevant experience will be considered.
- Minimum 3 years of experience in information security, vulnerability management, IT audit, or a related discipline. Public sector experience is preferred but not required.
- At least one active industry certification: CompTIA Security+, Microsoft Security Operations Analyst, or GIAC GSEC, or equivalent.
- Experience with Microsoft Purview, Microsoft Defender for Endpoint, or Microsoft 365 security and compliance tools.
- Familiarity with SIEM platforms (e.g., Microsoft Sentinel, Splunk, Elastic) and security log analysis.
Preferred qualifications include:
- Experience with NIST SP 800-53 controls, CIS Controls v8, or NIST SP 800-171.
- ISACA CISM, ISACA CCOA, CompTIA CySA +, or GIAC GCIH certification.
- Experience supporting HIPAA or CJIS compliance programs.
- Experience developing or contributing to cybersecurity policies, standards, or governance documentation.
Physical demands include:
Work is performed primarily in an office environment with standard business hours. Occasional evening or weekend work may be required during security incidents or planned maintenance windows. This position may require on-call availability on a rotating basis as the county's monitoring capability matures. Some travel between county facilities may be required.
AI and Emerging Technology Competency
Montgomery County ITS is actively adopting generative AI and automation tools to improve operational efficiency. The Cybersecurity Analyst is expected to develop competency with AI-assisted security tools, including AI-driven threat detection, automated vulnerability prioritization, and AI-supported compliance documentation. The analyst should approach these tools with practical curiosity and ability test and operate tools within established security boundaries to ensure the safety of county data and operating systems.
Equal Employment Opportunity
Montgomery County is an equal opportunity employer committed to creating a diverse and inclusive workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic.
- ...We are looking for a driven and commercially minded Cybersecurity Consultant to join our team. In this senior role, you will combine deep technical and strategic expertise with a strong client-facing instinct - owning a portfolio of consulting engagements while actively...SuggestedTemporary workRemote workFlexible hours
- A leading healthcare provider in King of Prussia is seeking an Application Analyst Intern. The role offers an opportunity to engage in meaningful projects, develop technical skills, and collaborate with teams. Candidates should be pursuing a Bachelor's degree in a relevant...SuggestedInternshipWork at office
- A leading healthcare provider in Pennsylvania is seeking an Application Analyst Intern to join their Corporate Information Services team. This role offers hands-on experience in healthcare technology solutions, aiming to improve patient care and safety. Candidates should...SuggestedInternship
- ...Sr. Information Security Analyst – Cloud & AI Security One of the nation's largest and most respected providers of hospital and... ...Analyst – Cloud & AI Security. As a key member of our collaborative Cybersecurity team, the Senior Information Security Analyst will play a...SuggestedFor contractors
- ...Information Security Analyst Internship One of the nation's largest and most respected providers of hospital and healthcare services, Universal Health Services, Inc. (UHS) has built an impressive record of achievement and performance. Growing steadily since its inception...SuggestedInternshipJanuary startWork at officeLocal area
- ...Information Security Analyst Job Classification: Full-time/Exempt Department: Information Technology Reports To: Cybersecurity Director Location: Audubon, PA About Us: At Client, we move with a sense of urgency to deliver innovations that improve the...Full time
- ...healthcare quality and safety, improve patient care, and engage patients and their families in their healthcare. As a Application Analyst Intern you will have the opportunity to work on real-time and meaningful projects, develop your technical skills, collaborate and...InternshipJanuary startWork at officeLocal area
- ...Application Analyst Intern The Corporate Information Services team at Universal Health Services (UHS) is looking for motivated professionals to join our cutting edge team and implement technology solutions to improve healthcare quality and safety, improve patient care...InternshipWork at office
- ...Secret security clearance with ability to obtain SCI Eligibility and Polygraph. This position will perform duties as a Classified Cybersecurity Information Systems Security Officer (ISSO) for systems located at the LM Space facility in Valley Forge PA. The work that...Full timeWork at officeRemote workRelocationFlexible hoursShift work
$113.9k - $200.91k
...security clearance with ability to obtain SCI Eligibility and Polygraph. This position will perform duties as a Classified Cybersecurity Information Systems Security Officer (ISSO) for systems located at the LM Space facility in Valley Forge PA. The work that Cybersecurity...Full timeTemporary workWork experience placementWork at officeFlexible hours- ...IT Security Analyst Come and Save Lives with Us! SERB is a fast-growing specialty pharmaceutical company that equips healthcare... ...Broad Overview We are looking for a detail-oriented IT security (cybersecurity) analyst to be responsible for desktop, mobile and network...For contractorsWork at officeImmediate startWork from homeWorldwide3 days per week
- ...Flexible Work Experience: Hybrid The Lead Information Security Analyst The Lead Information Security Analyst plays an important... ...phishing training program Lead or support the supply chain cybersecurity risk program including compliance with CIP-013 Review contract...Contract workWork experience placementWork at officeFlexible hours
- Job Title Job Locations: Alpharetta, GA; Charlotte, NC; Chicago, IL; Conshohocken, PA; Dallas, TX; Denver, CO; Fargo, ND; Garden City, NY; Houston, TX; Lenexa, KS; Lubbock, TX; Morristown, NJ; Mt Juliet, TN; New York, NY; Purchase, NY; Topeka, KS Required Skills ...
$123.5k - $217.7k
Job Description The coolest jobs on this planet ... or any other ... are with Lockheed Martin Space. At the dawn of a new space age, Lockheed Martin Space is a pioneer, partner, innovator, and builder. Our amazing people are on a mission to make a difference in the...Full timeTemporary workWork experience placementWork at officeFlexible hours- ...Application Support Analyst Position Summary The Application Support Analyst is responsible for supporting, maintaining, and optimizing business‑critical applications used across a multi‑residential property management portfolio. This role serves as a key liaison between...
- ...additional information visit . The Corporate Information Services department is seeking a dynamic and talented Associate Application Analyst - BH Business Systems. The Associate Application Analyst - BH Business Systems works with facility users, vendors, and...TraineeshipWork experience placementLocal areaFlexible hours
- David's Bridal is seeking a Senior Network Engineer to oversee enterprise network and security infrastructure. This critical role involves designing, implementing, and optimizing network systems across 190+ stores and corporate headquarters. The successful candidate will...Remote job
- ...Sr. Application Analyst-Workday Join a dynamic organization driven by our passion for healthcare. UHS is seeking talented individuals who are eager to contribute their expertise and pursue rewarding careers. As a leader in acute care and behavioral health, UHS provides...
- ...For additional information visit . The Corporate Information Services Department is seeking a dynamic and talented Application Analyst I-Surgical Services. Working as a member of the Clinical Documentation team, the Application Analyst I-Surgical Services participates...Local areaFlexible hours
$45 - $50 per hour
...talent irrespective of race, color, religion, gender, or any other protected status. Job Details : • Position: Applications Analyst • Location: 367 S Gulph Road, King of Prussia, PA 19406 (open to remote work arrangement) • Facility: UHS of Delaware, Inc...Hourly payDaily paidFull timeRemote workShift work- ...Associate Application Analyst - BH Business Systems The Corporate Information Services department is seeking a dynamic and talented Associate Application Analyst - BH Business Systems. The Associate Application Analyst – BH Business Systems works with facility users...TraineeshipWork experience placementFlexible hours
$65k - $80k
...Application Support Analyst Position Summary The Application Support Analyst is responsible for supporting, maintaining, and optimizing business‑critical applications used across a multi‑residential property management portfolio. This role serves as a key liaison...Temporary work- ...Application Analyst (Clinical Systems) Internship The Corporate Information Services team at Universal Health Services, Inc. (UHS) is looking for motivated professionals to join our cutting edge team and implement technology solutions to improve healthcare quality and...InternshipWork at office
- ...Application Analyst I-Pharmacy The Corporate Information Services Department is seeking a dynamic and talented Application Analyst I-Pharmacy. The Application Analyst I-Pharmacy working as a member of the Pharmacy IS application team, the application analyst I will...Flexible hours
- A leading IT staffing firm in King of Prussia seeks a candidate with application integration expertise and strong database knowledge to fill a key role. The ideal candidate will have a Bachelor's Degree in Computer Science and over 5 years of experience, along with a solid...
- A leading healthcare provider in King of Prussia, PA is seeking an Associate Application Analyst in Health Information Management to support the implementation of various applications in a multi-entity environment. The role requires a college degree in HIM or related fields...
- CLA is a top 10 national professional services firm where our purpose is to create opportunities every day, for our clients, our people, and our communities through industry-focused wealth advisory, digital, audit, tax, consulting, and outsourcing services. Even with...Flexible hoursNight shift
$59.58k - $66.15k
Implementation Specialist Conshohocken, Pennsylvania, United States Onbe, a fast-growing FinTech, bringing innovation to a rapidly growing global marketplace, stands for "on behalf." Because that's exactly how we work: on behalf of our clients, as their comprehensive...2 days per week- ...Senior Vulnerability Management Analyst The Senior Vulnerability Management Analyst blends technical and security expertise, collaborating with SMEs to harden and define approved security configurations for various platforms, both on-prem and in the cloud, with the...Work experience placement
- ...interface between users and IT project Adherence to documented procedural standards Escalate issues which cannot be resolved by the Analyst, in a timely manner Have a strong Customer Focus in order to provide a professional support service to both internal and external...Flexible hoursShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Analyst. Be the first to apply!
- cybersecurity software engineer Norristown, PA
- cybersecurity rmf analyst
- comptia cybersecurity analyst
- junior cyber security consultant
- cyber-security operations specialist
- microsoft cybersecurity analyst
- junior cyber security specialist
- cyber security consultant
- cyber security specialist
- cybersecurity analyst remote

