Cyber Security Analyst
Pitech Solutions, Inc.
PiTech Solutions Inc is pleased to provide a comprehensive assessment of a federal agency's cybersecurity. Our mandate is a team of professionals that support an entire federal agency's technology infrastructure, cybersecurity posture and cloud services. We will deliver six months of structured, evidence-based assessment work culminating in actionable findings across eight domains — organizational, governance, operational, infrastructure, cybersecurity, contracts and licensing, modernization, and data/AI readiness. Every recommendation is weighted against priorities, cybersecurity, and compliance first, followed by governance accountability, operational performance, technology lifecycle, and cost efficiency. Job Description: Cybersecurity Analyst (Federal Assessments Top Secret Clearance) Position Summary PiTech Solutions Inc. is seeking a Cybersecurity Analyst to support independent, evidence-based cybersecurity assessments for U.S. federal agencies. This role plans and executes security control assessments, technical testing, and compliance evaluations aligned to federal requirements (e.g., FISMA, NIST, and agency-specific policies). The analyst documents objective evidence, identifies risk and root cause, and produces clear, actionable recommendations for executives and technical teams. This position requires an active Top Secret (TS) clearance (with eligibility to maintain access as required). Key Responsibilities Assessment planning and scoping: Participate in discovery with agency stakeholders to confirm system boundaries, environments (on-prem/cloud/hybrid), interconnections, data types, and mission priorities; define assessment objectives, methodology, schedule, sampling strategy, and evidence request lists. Security control assessment (SCA): Evaluate management, operational, and technical controls against applicable baselines and overlays (e.g., NIST SP 800-53); map implementation statements to objective evidence and document assessment results, rationale, and traceability. Risk Management Framework (RMF) support: Assist with RMF activities across the system lifecycle (categorization, selection, implementation validation, assessment, authorization support, and continuous monitoring); review and validate SSPs, SAP/SAR artifacts, POA&Ms, and continuous monitoring strategies. Technical validation and testing: Perform hands‑on security testing where authorized, including configuration reviews, vulnerability validation, log review, and control verification across endpoints, servers, network devices, IAM services, cloud resources, and security tooling. Vulnerability and configuration assessment: Execute and analyze results from automated scans (credentialed when possible), benchmark configurations (e.g., CIS/STIG guidance as applicable), and identify false positives/negatives; develop prioritized remediation recommendations. Cloud security assessment: Assess cloud service configurations and controls (e.g., identity, network segmentation, encryption, logging/monitoring, key management, and shared responsibility considerations) across major CSP platforms and FedRAMP-aligned control expectations. Incident readiness and operational security: Evaluate detection and response capabilities (SOC processes, playbooks, alerting, escalation, forensics readiness, and tabletop exercises); assess logging coverage and retention to support investigations and compliance. Policy, governance, and program reviews: Assess cybersecurity program documentation, governance, and oversight processes (e.g., risk acceptance, exception handling, asset management, vulnerability management, secure configuration, change control, and third‑party risk). Evidence management: Collect, organize, and protect sensitive assessment materials; maintain a defensible evidence trail, including interview notes, screenshots, configuration exports, scan outputs, and log samples in accordance with handling requirements. Reporting and briefings: Draft assessment deliverables (findings, risk ratings, root cause, impacts, and recommendations) and present results to technical teams and executive leadership; tailor communications for both technical depth and leadership decision‑making. Remediation support and verification: Collaborate with system owners and engineers to validate remediation plans, track POA&Ms, and confirm corrective actions through re‑testing and evidence review. Stakeholder coordination: Work effectively with federal personnel, contractors, and third parties; facilitate interviews and working sessions; provide clear status updates and elevate blockers in a timely manner. Quality and compliance: Follow internal assessment standards, templates, and QA processes to ensure consistency, accuracy, and alignment with contract requirements and federal audit expectations. Required Qualifications Active Top Secret (TS) clearance (and ability to meet ongoing access eligibility requirements). Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field, or equivalent relevant experience. Demonstrated experience conducting cybersecurity assessments, audits, or security control assessments in federal or regulated environments, including 7+ years of related cybersecurity experience (or 5+ years with a Master’s degree). Working knowledge of federal cybersecurity requirements and assessment approaches (e.g., FISMA; NIST SP 800-53 control assessments; RMF concepts and artifacts such as SSP, SAP/SAR, and POA&M). Hands‑on technical capability to review configurations and validate controls across common enterprise technologies (Windows/Linux, Active Directory/Azure AD or equivalent IAM, network fundamentals, endpoint security, vulnerability management, and logging/monitoring). Strong written communication skills, including ability to produce clear findings, objective evidence narratives, and executive‑ready summaries. Strong verbal communication and interviewing skills; comfortable working with stakeholders from engineers to senior leaders. Ability to lead assessment workstreams with minimal oversight, including mentoring junior assessors, coordinating evidence requests, and driving deliverable quality. Ability to manage multiple tasks, meet deadlines, and work independently with minimal supervision. Desired Qualifications Industry certifications such as Security+, CySA+, SSCP, CISSP, CISM, CISA, CCSP, or equivalent. Experience supporting ATO packages and authorization activities, including coordination with Authorizing Officials (AOs) and SCA teams. Familiarity with FedRAMP requirements and control expectations for cloud services. Experience with DISA STIGs and security technical implementation guidance; familiarity with benchmark tooling and configuration baselines. Experience with vulnerability scanning and security tools (e.g., Tenable/Nessus, Qualys, Rapid7; endpoint security; SIEM platforms such as Splunk, Sentinel, or Elastic). Basic scripting/automation experience (e.g., PowerShell, Python) for evidence collection, analysis, or reporting efficiency. Experience supporting Zero Trust initiatives (e.g., identity‑centric security, MFA/conditional access, segmentation, device compliance, and continuous verification) aligned to federal guidance. Experience performing tabletop exercises, incident response assessments, or log management maturity reviews. Tools & Technologies (Representative) GRC and assessment artifacts: SSP/SAP/SAR/POA&M documentation, evidence trackers, control matrices, and risk registers Vulnerability and configuration assessment: credentialed scanning, secure configuration benchmarks, patch/vulnerability remediation workflows Identity and access management: RBAC, MFA, privileged access management concepts, account lifecycle processes Logging and monitoring: SIEM queries, log source onboarding validation, alert triage concepts, retention/immutability considerations Cloud platforms: configuration review concepts for major CSP services (networking, IAM, encryption, logging, resource governance) Collaboration and documentation: Microsoft 365, Word/Excel/PowerPoint, SharePoint/Teams, ticketing systems, and secure file handling Security Requirements This position requires an active Top Secret (TS) clearance and strict adherence to all applicable security requirements, including need-to-know access, approved information system use, and proper handling of sensitive and classified information. Candidate must be able to maintain clearance eligibility and comply with agency and contract‑specific security policies. Work may be performed on‑site at federal facilities and/or in secure environments as required by the agency. Occasional travel may be required for on‑site interviews, evidence collection, and briefings. The role may involve working with time‑sensitive deliverables during assessment fieldwork and reporting cycles. Work shall be performed primarily onsite in NW, Washington, DC 20573. We recognize that select analytical activities (e.g., drafting, synthesis, and report development) may be performed offsite when coordinated with the COR; however, quoters shall assume the engagement requires substantial onsite presence to support interviews, workflow observation, and stakeholder engagement Period of Performance 6 months PiTech Solutions Inc. is an equal opportunity employer. Employment decisions are based on qualifications, merit, and business needs. #J-18808-Ljbffr Pitech Solutions, Inc.
- ...About the role We are seeking a dedicated and skilled Cyber Security Analyst to join our team in support of a critical federal government mission. As a Cyber Security Analyst, you will play a pivotal role in protecting mission-critical systems, identifying vulnerabilities...SuggestedPermanent employmentFull time
- ...The Cyber Security Analyst (Senior) provides expert-level cybersecurity support for Navy systems, ensuring compliance with DoD and Department of the Navy security requirements. This role leads Risk Management Framework (RMF) activities, supports system authorization...SuggestedFull time
- ...As a Cybersecurity Analyst, you will implement and maintain information technology security systems in support of the Airports Authority’s Information Security Program... ...technologies and processes to prevent, detect, and manage cyber threats; identify, monitor, assess, and counter...SuggestedWork at officeRemote workFlexible hours
- ...and maintain servers continuously to meet security compliance standards. Ensure that the Red... ..., and implement network systems. Perform cyber investigations and analysis. Research and... ...Microsoft Certified: Security Operations Analyst Associate (SC-200) Microsoft Certified:...SuggestedFull time
- ...Cyber Security AnalystblueStone Recruiting is a national search firm with a focus of placing top Cyber Security talent from the Analyst level to CISO with prestigious organizations nationwideOur client seeking a Cyber Security Operations Analyst to support an operations...SuggestedWork experience placement
$75 per hour
...Join to apply for the Cyber Security Legislative Analyst role at Cape Fox Shared Services ( A Cape Fox Company ) Kwaan Tech is seeking a highly qualified Cyber Security Legislative Analyst to provide part-time (approximately 40 hours per month, hours may vary) Cyber Security...Hourly payPart timeWork at office- ...Cyber Security AnalystLocation: Washington, DC (Remote)Duration: 6+ months of contract with possibility of extensionJob DescriptionPurpose: To ensure that applications are protected and from inappropriate access, disclosure and/or damage. To advocate for and execute the...Contract workImmediate startRemote work
$120k - $130k
...TechFlow Inc. is seeking a Cyber Security Analyst II to support a mission‑critical DOD platform that enables collection, analysis, and secure exchange of data from Transportation Security Equipment. In this role, you will help protect the confidentiality, integrity, and...Temporary workImmediate startRemote work- ...Cyber Security AnalystR&P is seeking a Cyber Security Analyst to support the fleet modernization efforts of our Navy Program Office client.ResponsibilitiesProvide expertise in cyber security engineering, Navy Risk Management Framework (RMF) process, and validation, and...Work experience placementWork at office
- ...MORE! Position Summary The Cybersecurity Analyst is responsible for safeguarding, monitoring... ...advancing the organization’s security posture across complex hybrid environments... ...systems against sophisticated and evolving cyber threats. The Cybersecurity Analyst partners...Full timeLocal areaDay shift
- ...Trinity Cyber is a leading developer and provider of advanced cybersecurity technologies... ...sessions and automatically remove them. As a secure edge, our platform identifies and... ...Description: As a Resident Threat Operations Analyst, you will be Trinity Cyber’s embedded technical...Local area
- ...The Johns Hopkins University Applied Physics Laboratory (APL) is seeking a Cyber and Information Systems Security Analyst to design and operate national security systems within classified environments. You will join a team of cybersecurity specialists dedicated to supporting...
- ...Mid-Level Cybersecurity Analyst/Engineer Technomics is a growing employee‑owned decision... ...RMF guidelines including categorization, security planning, POA&M updates, review test results... ...work; experience evaluating the cyber compliance of a system against current RMF...Work at office
$119k - $193k
...Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic... ...responsibilities, and the most important security and risk trends and their business and... ...methods; deep knowledge and expertise in cyber risk quantification; and deep experience...For contractors- ...The Carlyle Group seeks a Senior Auditor in Internal Audit – Cyber and Technology to lead audits focused on technology and cyber risk within a global asset manager. You will execute all audit phases, interact with Cybersecurity and front/middle/back office, and apply AI...
- ...A leading social media company in Washington, DC is seeking a Cybersecurity Strategy Senior Analyst. This role focuses on developing and executing strategic initiatives that enhance cybersecurity operations. The ideal candidate should have a strong understanding of cybersecurity...
$142.79k - $172.5k
...Job Overview Cyber Security Analyst at GDIT. Build and protect classified and unclassified systems for a major Intelligence Community Agency, ensuring threat mitigation and compliance with policies. Responsibilities Gather and handle forensic evidence in accordance with...Temporary workMonday to FridayShift work- ...Senior Cyber Security Analyst The client is looking for a Senior Cyber Security Analyst to provide 24x7 cybersecurity monitoring services for Joint Service Provider networks. This includes performing real-time cyber threat intelligence analysis, correlating actionable...Work experience placementShift workDay shiftAfternoon shift
- ...Cyber Security Analyst L3 The purpose of this role is to handle escalated alerts, investigate incidents and perform vulnerability scans to ensure compliance with organizational standards and reduce security risks. Areas of responsibility: Monitoring and Incident...Contract work
- ...Senior Cyber Security Analyst Location: Washington, DC Summary The intent of this job description is to provide a representative summary of the major duties, locations, and responsibilities performed by incumbent(s) in this job. Incumbent(s) may not be required to perform...Contract workWork at office
- ...JCD Staffing is seeking a Senior Cybersecurity Supply Chain Risk Management Analyst in Washington, DC, to support federal cybersecurity initiatives. This role focuses on identifying and mitigating risks related to complex supply chains, requiring an active TS clearance...
$105k
...APL. We are ranked as one of Computerworld’s Top Places to Work in IT for 8 years running, and we are seeking a Cyber and Information Systems Security Analyst who will play an instrumental role in the design and operation of national security systems. You will join a...- Ampcus Inc is seeking a Senior Cyber Security Analyst based in Washington, DC. The role involves administration of deployed cyber control technologies within the Security Operations Center (SOC). Key responsibilities include monitoring, analyzing, and responding to cyber...
- TechFlow Inc. is seeking a Cyber Security Analyst II to support a mission-critical DoD platform that enables collection, analysis, and secure exchange of data from Transportation Security Equipment. You will help protect the confidentiality, integrity, and availability...
$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience & Technology (PXT), Legal and Global Communications and Community Impact (GCCI) business units.Our Mission is to protect and safeguard...InternshipFlexible hours$136k - $184k
Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering... ...designing and developing innovative capabilities to identify cyber threat activities at scale.- Work individually and/or as a team...InternshipFlexible hoursShift work$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.... ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll...Local area$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats...InternshipFlexible hours$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...InternshipRemote workFlexible hours$100k - $110k
...enterprise software architectures that support the bank’s information security operations functions. This role performs feedback and... ...to Information Technology security leadership.Assists Security Analysts as an escalation point for security alerts, events, and logs, escalating...Temporary workRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security Analyst. Be the first to apply!
- information security consultant Washington DC
- cyber security analyst Washington DC
- remote cyber security analyst Washington DC
- cyber forensics Washington DC
- cyber sales Washington DC
- cyber threat intelligence analyst Washington DC
- cyber Washington DC
- cyber security architect Washington DC
- cybersecurity software engineer Washington DC
- cyber security technician Washington DC


