Cybersecurity Analyst
Shrgroup.net
About SHR Consulting Group SHR Consulting Group, LLC is a small business delivering enterprise IT, cybersecurity, and program management services to the Department of Defense and federal civilian agencies. We support mission-critical infrastructure at the Pentagon and across the National Capital Region, and we invest in our people through competitive compensation, professional certification support, and long-term career growth on stable, multi-year programs. Position Summary We are a rapidly growing organization seeking experienced Cybersecurity Analysts to support cyber compliance, technical security assessments, vulnerability management, cyber hardening, and Risk Management Framework (RMF) activities for a large enterprise Department of Defense environment. Multiple openings are available at Senior and Intermediate levels. The successful candidate will analyze enterprise security-tool results, validate technical findings, drive remediation, maintain RMF evidence in eMASS, support cyber-readiness activities, and brief technical and Government leadership on risk and compliance status. eMASS is a government-owned application that supports integrated cybersecurity management, dashboard reporting, control-scorecard measurement, and authorization-package development. Key Responsibilities
- Perform technical cybersecurity assessments of enterprise Windows, Red Hat Linux, workstation, server, application, network, and supporting infrastructure environments.
- Analyze and validate findings from ACAS, HBSS/ESS, Trellix, Axonius, Evaluate-STIG, Splunk, Tanium, SCAP, STIG Viewer, and other approved Enterprise Security Services (ESS) tools.
- Assess systems against DISA STIGs, IAVM notices, DoD cyber tasking, and approved security baselines; identify vulnerabilities, configuration deviations, missing patches, security-tool coverage gaps, and asset discrepancies.
- Coordinate with system administrators, engineers, system owners, and platform teams to implement and validate patches, Group Policy changes, certificate updates, endpoint-security changes, and secure-configuration remediations.
- Drive assigned systems toward compliance with DISA STIGs, IAVMs, applicable DoD orders, and organizational remediation timelines.
- Develop, maintain, and track Plans of Action and Milestones (POA&Ms) for unresolved vulnerabilities and compliance deviations, including technical details, risk impact, mitigation actions, responsible parties, milestones, and planned completion dates.
- Support RMF activities in accordance with DoDI 8510.01 and NIST guidance, including eMASS updates, control implementation statements, evidence collection, security-control validation, assessment artifacts, risk records, and authorization-package support.
- Validate security controls against NIST SP 800-53 requirements and document results in eMASS, SharePoint, or other approved repositories.
- Support CCORI, CORA, CSSP, and Cyber Hardening Mission activities through pre-assessment validation, checklist management, evidence preparation, corrective-action tracking, remediation coordination, and closure verification.
- Monitor approved DoD, DISA, JSP, and organizational channels for IAVMs, cyber orders, security directives, and other tasking; disseminate actions to responsible teams and track execution through closure.
- Provide DTO support by reviewing, analyzing, coordinating, tracking, and validating closure of DISA Task Orders, including required security configuration changes, firewall-rule updates, ports/protocols/services changes, vulnerability mitigations, technical documentation, validation testing, and completion evidence in accordance with established DoD, DISA, JSP, and program procedures.
- Maintain and validate required security-tool coverage across managed assets, ensuring ESS/HBSS, ACAS, Splunk, Tanium, and other required tools are installed, properly configured, communicating with management consoles, and tracked to resolution when reporting issues occur.
- Support patch and hot-fix deployment across multiple operating-system platforms using MECM, Group Policy, PowerShell, Tanium, Red Hat Satellite Server, YUM, or equivalent enterprise-management tools.
- Develop cyber-compliance metrics, remediation trackers, dashboards, and executive-ready reports for monthly program reviews and leadership briefings.
- Apply advanced Microsoft Excel skills-including formulas, pivot tables, XLOOKUP/VLOOKUP, conditional logic, data reconciliation, charts, and trend analysis-to evaluate vulnerability trends, compliance posture, risk scores, overdue actions, and remediation performance.
- Brief technical teams, program management, and Government leadership on technical findings, enterprise risk, compliance trends, remediation status, and decisions required.
- Support Systems Security Reviews, independent control testing, audit preparation, inspection response, and continuous-monitoring activities.
- Demonstrated ability and experience in daily operations and maintenance of large, complex IT projects and IT staff similar in size and scope to this order
- Three (3) or more years of experience securing operating systems against DISA STIGs and configuring/maintaining host firewalls; experience hardening Windows Server and Red Hat Linux platforms required.
- Working knowledge of the DoD IAVM program, the DISA Vulnerability Management System (VMS), and the Continuous Monitoring Risk Scoring (CMRS) system.
- Knowledge of DoD vulnerability scanning standards and tools, defense-in-depth concepts, and incident response, auditing, and CNDSP practices.
- Hands-on experience with cyber tools, including HBSS/ESS, ACAS (Tenable), Splunk, and Tanium.
- Experience supporting RMF (NIST SP 800-37), NIST SP 800-53R control documentation and validation, and accreditation programs such as FISMA, OMB, DoD IG inspections, and ACA.
- Experience deploying patches and hot fixes against required deadlines using MECM, Group Policy, PowerShell, Red Hat Satellite/YUM, or Tanium.
- For the Senior variant: 5+ years of experience and ACAS administrator certification/experience are strongly preferred.
- Strong analytical, written, and verbal communication skills with the ability to brief technical risk to Government leadership.
- Bachelor's degree in Computer Engineering, Computer Information Systems, Telecommunications, Management Information Systems, Cybersecurity, or a related field; or equivalent combination of education and three (3)+ recent years of documented relevant experience.
- Must meet DoD 8570.01-M / DoD 8140 IAT Level II baseline certification requirements prior to start (e.g., Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, or equivalent). Computing Environment certification appropriate to the role is also required.
- Active Secret clearance required at minimum. U.S. citizenship required.
- 100% onsite at a government facility within the National Capital Region (NCR), primarily at the Pentagon, Crystal Gateway, Taylor Building, Mark Center, or other JSP-designated alternate site. Must be local to the DC Metro Area with reliable transportation.
- Competitive salary commensurate with experience and clearance level
- Comprehensive medical, dental, and vision coverage
- 401(k) with company contribution
- Paid time off and eleven federal holidays
- Certification reimbursement and training support (DoD 8140 baseline and computing environment certifications)
- Life and disability insurance
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cybersecurity Analyst in Arlington, VA vacancy
$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by utilizing enterprise-level vulnerability scanning and assessment tools to identify internally and externally facing vulnerabilities...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$99k - $225k
Enterprise Cybersecurity AnalystThe Opportunity:Support mission-critical cybersecurity operations for Booz Allen's Impact Level 5 (IL5) environment by administering advanced security tools, including CrowdStrike Falcon EDR/AV, Tenable Cloud Security Enterprise, and BigID...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- DescriptionActioNet has an immediate opportunity for a Cyber Security Analyst requiring a Public Trust clearance located in Silver Spring,... ...and requirements: Firewall Policy, Ports & Protocols, Cybersecurity, CybersafeFamiliarity with Tenable and BigFix, preferred.Experience...SuggestedImmediate start2 days per week1 day per week
$135k - $143k
...0/year Work Location: Remote with occasional on-site work in Washington, DC, at least once per month. The Senior Cybersecurity Analyst leads in the proactive defense of the organization's information systems. This role provides expert-level guidance on cybersecurity...SuggestedFull timeContract workCasual workRemote workFlexible hours- ...MANTECH seeks a motivated, career and customer-oriented Cybersecurity Analyst - Nights to join our team in Tysons, VA The Cybersecurity Analyst will monitor Air Gapped Security Fabrics through managed SECOPs Tools. Responsibilities include but are...SuggestedWork at officeLocal areaShift workNight shift
- ...MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x7x365 cybersecurity support to one of the most coveted targets in the world. The Cyber Incident Response Analyst will work...Shift workNight shiftDay shiftAfternoon shift
$150k
...Dental Insurance, Vision Insurance Full-Time | On-site Required Skills Cyber Threat Analysis Network Security SIEM Firewalls Cybersecurity Analyst CoreLogic Systems Washington, District of Columbia, United States Job Description A Cybersecurity Analyst is responsible for...Full time$110k - $160k
...Cybersecurity SOC Analyst II Washington, District of Columbia, United States CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed...Contract workWork experience placementCasual workRelocation package$130k - $155k
...efficiency and operational reliability at significantly lower capital cost. We Are Seeking Qualified Applicants For The Position Cybersecurity Analyst Located Arlington Summary The Cybersecurity Engineer is responsible for designing, implementing, and maintaining security...- ...SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development... ...approval. SkyePoint Decisions is seeking a Cybersecurity Analyst to support the Diplomatic Security Cyber Mission (DSCM)...Contract workWork at officeRemote work
- ...Bridge Core (BCore) is seeking a Cybersecurity Analyst in McLean, VA. The ideal candidate should have at least 1 year of experience in cybersecurity roles and possess an active TS/SCI clearance with polygraph. Responsibilities include utilizing SIEM systems for threat...Shift workAfternoon shift
- ...Cybersecurity Analyst The contractor shall support the Pharmacy Operations Division (POD) Informatics System Security Manager (ISSM) in cybersecurity matters by providing analytic and technical advice to support DoD Cybersecurity policies and activities. Essential Job...Contract workFor contractors
$130k - $160k
...Amentum is seeking a Cybersecurity Analyst to join our team and support our McLean, VA customer. We are looking for team members who are passionate about making a difference by working on critical efforts we manage as a premier government contractor. Here at Amentum...Hourly payCivilian ContractorContract workFor contractorsWork at officeLocal area$120k - $179k
...Cybersecurity Analyst Bridge Core provides high energy, unified teams; technology integration experience; and innovative approaches, to enable our clients' mission. We enable our clients' mission by integrating innovative technologies and implementing adoption processes...Shift workNight shiftWeekend workAfternoon shift- ...Medical Insurance, Dental Insurance, Vision Insurance Full-Time | On-site Required Skills powershell Cybersecurity SIEM Cybersecurity Incident Response Analyst Job Description: The Cybersecurity Incident Response Analyst is responsible for real-time threat detection,...Full time
- ...learn and grow professionally? At Talent Acquisition Concepts, we are changing the way small businesses hire. We are seeking a Cybersecurity Analyst to report to the Cybersecurity Program Manager. This individual will serve as part of an integrated team of engineering and...Local areaRemote work
$130k - $160k
...Overview Amentum is seeking a Cybersecurity Analyst to support our McLean, VA customer. The role focuses on performing assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) for a federal civilian agency. The analyst will develop, review...- ...Cybersecurity Analyst We are seeking a dedicated and detail-oriented Cybersecurity Analyst to join our team and help safeguard our systems and data from potential threats. In this role, you will monitor and analyze security events, identify vulnerabilities, and implement...Temporary workFor contractorsImmediate startFlexible hours
- ...Overview Cybersecurity Analyst – McLean, VA. TS/SCI clearance with polygraph required. Bridge Core is seeking a skilled analyst to support government agencies in cyberspace. Responsibilities We are seeking a skilled and motivated Cybersecurity Analyst to join our team....Shift workNight shiftAfternoon shift
$135k - $216k
ResponsibilitiesPosition OverviewWe are seeking a Senior Cybersecurity Program Analyst to support a cleared federal government customer. The successful candidate will provide senior-level program management, cybersecurity portfolio analysis, governance, financial management...Contract workShift work$86k - $138k
Responsibilities Peraton is currently seeking to hire a Cybersecurity Analyst - Security Standards & Baselines to become part of our Federal Strategic Cyber group. Location: Hybrid position, based in Arlington, VA.In this role, you will:Support the Security Standards...Contract workCurrently hiringWork at officeShift work$110k - $120k
As Sr. Cybersecurity Analyst II, you’ll Provides a wide array of Information Technology (IT) oriented services to its 4,000 customers. These services include: incident and request support; conducting program analysis and studies; developing, operating, and maintaining IT...Full timeLocal area$86.8k - $198k
Enterprise Cybersecurity Product AnalystThe Opportunity:As an Enterprise Cybersecurity Product Analyst, you will support Booz Allen's Enterprise Cybersecurity (ECS) Product Security function by helping scale a structured, repeatable, and trackable security review model...Full timeContract workPart timeWork at officeLocal areaRemote work$110.18k - $183.63k
...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington, Virginia (US-VA), United States (US).Job Summary: The Cybersecurity and Risk Analyst is...Full timeTemporary workWork at officeRemote workFlexible hours- ...Clearance Node is supporting a U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and... ...Key Resources (CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management techniques...
- cFocus Software seeks a Cybersecurity Triage Analyst (Tier 1) to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance...Full timeWork at office
- Metropolitan Washington Airports Authority in Arlington, Virginia is seeking a Cybersecurity Analyst to implement and maintain information security systems within the Information Security Program. You will protect MWAA data, networks, and systems by deploying security measures...
- A progressive organization is seeking a Cybersecurity Analyst to join their integrated team of experts in Arlington, Virginia. This role involves supporting cybersecurity engineers and conducting risk assessments in the field. Ideal candidates will possess a Bachelor's...
- Amentum is seeking a Cybersecurity Analyst to support a McLean, VA based federal civilian agency as a contractor. The role focuses on RMF/A&A activities, developing SSPs, POA&Ms, SARs, and related RMF artifacts, with emphasis on risk analysis and security documentation....Civilian Contractor
- Peraton is seeking a Cybersecurity Analyst for Security Standards & Baselines in a Hybrid role based in Arlington, VA. You will support the SSB section within the TIE Office, drive automation of workflows, and ensure compliance with FISMA, NIST 800-53 Rev. 5, CIS Benchmarks...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Analyst. Be the first to apply!
Related searches
- cyber security specialist Arlington, VA
- cyber security consultant Arlington, VA
- cyber security architect Arlington, VA
- cybersecurity software engineer Arlington, VA
- work from home cyber security Arlington, VA
- cybersecurity administrator Arlington, VA
- remote cyber security Arlington, VA
- cybersecurity grc Arlington, VA
- cyber security lead Arlington, VA
- junior cyber security Arlington, VA



