Cyber Security Analyst
Pitech Solutions, Inc.
PiTech Solutions Inc is pleased to provide a comprehensive assessment of a federal agency's cybersecurity. Our mandate is a team of professionals that support an entire federal agency's technology infrastructure, cybersecurity posture and cloud services. We will deliver six months of structured, evidence-based assessment work culminating in actionable findings across eight domains — organizational, governance, operational, infrastructure, cybersecurity, contracts and licensing, modernization, and data/AI readiness. Every recommendation is weighted against priorities, cybersecurity, and compliance first, followed by governance accountability, operational performance, technology lifecycle, and cost efficiency. Job Description: Cybersecurity Analyst (Federal Assessments Top Secret Clearance) Position Summary PiTech Solutions Inc. is seeking a Cybersecurity Analyst to support independent, evidence-based cybersecurity assessments for U.S. federal agencies. This role plans and executes security control assessments, technical testing, and compliance evaluations aligned to federal requirements (e.g., FISMA, NIST, and agency-specific policies). The analyst documents objective evidence, identifies risk and root cause, and produces clear, actionable recommendations for executives and technical teams. This position requires an active Top Secret (TS) clearance (with eligibility to maintain access as required). Key Responsibilities Assessment planning and scoping: Participate in discovery with agency stakeholders to confirm system boundaries, environments (on-prem/cloud/hybrid), interconnections, data types, and mission priorities; define assessment objectives, methodology, schedule, sampling strategy, and evidence request lists. Security control assessment (SCA): Evaluate management, operational, and technical controls against applicable baselines and overlays (e.g., NIST SP 800-53); map implementation statements to objective evidence and document assessment results, rationale, and traceability. Risk Management Framework (RMF) support: Assist with RMF activities across the system lifecycle (categorization, selection, implementation validation, assessment, authorization support, and continuous monitoring); review and validate SSPs, SAP/SAR artifacts, POA&Ms, and continuous monitoring strategies. Technical validation and testing: Perform hands‑on security testing where authorized, including configuration reviews, vulnerability validation, log review, and control verification across endpoints, servers, network devices, IAM services, cloud resources, and security tooling. Vulnerability and configuration assessment: Execute and analyze results from automated scans (credentialed when possible), benchmark configurations (e.g., CIS/STIG guidance as applicable), and identify false positives/negatives; develop prioritized remediation recommendations. Cloud security assessment: Assess cloud service configurations and controls (e.g., identity, network segmentation, encryption, logging/monitoring, key management, and shared responsibility considerations) across major CSP platforms and FedRAMP-aligned control expectations. Incident readiness and operational security: Evaluate detection and response capabilities (SOC processes, playbooks, alerting, escalation, forensics readiness, and tabletop exercises); assess logging coverage and retention to support investigations and compliance. Policy, governance, and program reviews: Assess cybersecurity program documentation, governance, and oversight processes (e.g., risk acceptance, exception handling, asset management, vulnerability management, secure configuration, change control, and third‑party risk). Evidence management: Collect, organize, and protect sensitive assessment materials; maintain a defensible evidence trail, including interview notes, screenshots, configuration exports, scan outputs, and log samples in accordance with handling requirements. Reporting and briefings: Draft assessment deliverables (findings, risk ratings, root cause, impacts, and recommendations) and present results to technical teams and executive leadership; tailor communications for both technical depth and leadership decision‑making. Remediation support and verification: Collaborate with system owners and engineers to validate remediation plans, track POA&Ms, and confirm corrective actions through re‑testing and evidence review. Stakeholder coordination: Work effectively with federal personnel, contractors, and third parties; facilitate interviews and working sessions; provide clear status updates and elevate blockers in a timely manner. Quality and compliance: Follow internal assessment standards, templates, and QA processes to ensure consistency, accuracy, and alignment with contract requirements and federal audit expectations. Required Qualifications Active Top Secret (TS) clearance (and ability to meet ongoing access eligibility requirements). Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field, or equivalent relevant experience. Demonstrated experience conducting cybersecurity assessments, audits, or security control assessments in federal or regulated environments, including 7+ years of related cybersecurity experience (or 5+ years with a Master’s degree). Working knowledge of federal cybersecurity requirements and assessment approaches (e.g., FISMA; NIST SP 800-53 control assessments; RMF concepts and artifacts such as SSP, SAP/SAR, and POA&M). Hands‑on technical capability to review configurations and validate controls across common enterprise technologies (Windows/Linux, Active Directory/Azure AD or equivalent IAM, network fundamentals, endpoint security, vulnerability management, and logging/monitoring). Strong written communication skills, including ability to produce clear findings, objective evidence narratives, and executive‑ready summaries. Strong verbal communication and interviewing skills; comfortable working with stakeholders from engineers to senior leaders. Ability to lead assessment workstreams with minimal oversight, including mentoring junior assessors, coordinating evidence requests, and driving deliverable quality. Ability to manage multiple tasks, meet deadlines, and work independently with minimal supervision. Desired Qualifications Industry certifications such as Security+, CySA+, SSCP, CISSP, CISM, CISA, CCSP, or equivalent. Experience supporting ATO packages and authorization activities, including coordination with Authorizing Officials (AOs) and SCA teams. Familiarity with FedRAMP requirements and control expectations for cloud services. Experience with DISA STIGs and security technical implementation guidance; familiarity with benchmark tooling and configuration baselines. Experience with vulnerability scanning and security tools (e.g., Tenable/Nessus, Qualys, Rapid7; endpoint security; SIEM platforms such as Splunk, Sentinel, or Elastic). Basic scripting/automation experience (e.g., PowerShell, Python) for evidence collection, analysis, or reporting efficiency. Experience supporting Zero Trust initiatives (e.g., identity‑centric security, MFA/conditional access, segmentation, device compliance, and continuous verification) aligned to federal guidance. Experience performing tabletop exercises, incident response assessments, or log management maturity reviews. Tools & Technologies (Representative) GRC and assessment artifacts: SSP/SAP/SAR/POA&M documentation, evidence trackers, control matrices, and risk registers Vulnerability and configuration assessment: credentialed scanning, secure configuration benchmarks, patch/vulnerability remediation workflows Identity and access management: RBAC, MFA, privileged access management concepts, account lifecycle processes Logging and monitoring: SIEM queries, log source onboarding validation, alert triage concepts, retention/immutability considerations Cloud platforms: configuration review concepts for major CSP services (networking, IAM, encryption, logging, resource governance) Collaboration and documentation: Microsoft 365, Word/Excel/PowerPoint, SharePoint/Teams, ticketing systems, and secure file handling Security Requirements This position requires an active Top Secret (TS) clearance and strict adherence to all applicable security requirements, including need-to-know access, approved information system use, and proper handling of sensitive and classified information. Candidate must be able to maintain clearance eligibility and comply with agency and contract‑specific security policies. Work may be performed on‑site at federal facilities and/or in secure environments as required by the agency. Occasional travel may be required for on‑site interviews, evidence collection, and briefings. The role may involve working with time‑sensitive deliverables during assessment fieldwork and reporting cycles. Work shall be performed primarily onsite in NW, Washington, DC 20573. We recognize that select analytical activities (e.g., drafting, synthesis, and report development) may be performed offsite when coordinated with the COR; however, quoters shall assume the engagement requires substantial onsite presence to support interviews, workflow observation, and stakeholder engagement Period of Performance 6 months PiTech Solutions Inc. is an equal opportunity employer. Employment decisions are based on qualifications, merit, and business needs. #J-18808-Ljbffr Pitech Solutions, Inc.
- ...Vanguard’s Technology Leadership Program, in the Risk & Security Analytics track, invites graduates to help identify and mitigate cybersecurity and operational risks across Vanguard’s systems and clients. The two-year, three-rotation program includes real‑world capstones...Suggested
- ...and maintain servers continuously to meet security compliance standards. Ensure that the Red... ..., and implement network systems. Perform cyber investigations and analysis. Research and... ...Microsoft Certified: Security Operations Analyst Associate (SC-200) Microsoft Certified:...SuggestedFull time
$110k - $120k
...Job Overview The Cybersecurity Analyst – SOC Operations is responsible for monitoring, detecting... ...This role serves as a key member of the Security Operations Center (SOC) and focuses on... ...security visibility and minimizing cyber risk exposure. Key Responsibilities/Accountabilities...SuggestedFull timeFor contractorsLocal areaRemote work$83.9k - $101.9k
## Cyber Security AnalystApplylocations: Virtual-CO-Capitolbldg: Indian Land, South Carolinatime type: Full timeposted on: Posted 2 Days... ...purpose and people have always come before profit.Cyber Security Analyst-Security OperationsMovement is changing the financial...SuggestedRelocation- ...advance the state of the art. Responsibilities Responsible to provide cyber-technical expertise through the conduct of cyber analytical activities, evaluation of information/technical/physical security systems and practices, and to identify, investigate, and analyze...SuggestedFull timeTemporary workFor contractorsImmediate startRelocation package
- ...Blue Yonder Defense Solutions in Dallas, TX, is seeking an Information Security Analyst focused on vulnerability management. The role is hybrid (onsite twice monthly) and directs risk-based remediation across cloud and on-premises environments. Responsibilities include...
- ...accommodation or an alternative application process. Cybersecurity Analyst US 7 days ago Requisition ID: 1212 Location and Travel Details:... ...-related systems. This role will assist the Information System Security Officer (ISSO) with Risk Management Framework (RMF) compliance,...Temporary workLocal areaRemote work
$90k - $125k
...We are seeking a Security Awareness Analyst to help build and scale our security awareness program. This role focuses on reducing human risk by educating employees, driving behavior change, and supporting a strong security culture across the organization. You’ll partner...Local area$112.71k - $183.14k
...validation activities as needed. Maintain integrations between Qualys, ServiceNow, CMDB, cloud platforms, reporting systems, and approved security technologies. Oversee host discovery, authenticated infrastructure scanning, scanner appliance operations, and Cloud Agent...Part timeRelocationFlexible hours- ...facilities, we help water utilities build a complete picture of their cyber risk exposure and maturity, and guide them toward sustainable... ...risk assessments, program reviews, and governance-focused security evaluations for water utility clients. Independently execute defined...Full timeTemporary workPart timeCasual workLive inWork at officeLocal areaRemote workFlexible hours
$105k - $130k
Description Position Title: Cyber Security Analyst, Journeyman (PMA 271) Requisition #: 293 Work Environment: On Site Position Type: Exempt Salary Range: $105,000 — $130,000 ***This is an estimated salary range. Compensation will be commensurate with experience***...Work experience placementWork at office$7,094.23 per month
...be eligible for this role. Employees will be required to work at a FedEx office location up to several times per week. Sr Cyber Security Analyst Job Description We are seeking an experienced and technically proficient Senior Cyber Security Analyst to join our Information...Work experience placementWork at office$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.... ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll...Local area$204k - $240k
...making a rewarding impact and Keeping Commerce Human.Salary Range:$204,000.00 - $240,000.00What's the role?Etsy is seeking a Staff Security Engineer to join our Security Operations team. As part of the larger Security org, this team plays a pivotal role in protecting...Full timeWork at officeLocal areaVisa sponsorshipFlexible hours$82.6k - $162.8k
Position Summary Join our Deloitte Cyber team to deliver powerful solutions to help our clients navigate the ever-changing threat... ...resilience, grow with confidence, and proactively manage to secure success. Identity security market is undergoing a fundamental transformation...Local areaVisa sponsorship- AnaVation is seeking a Cyber Vulnerability Analyst to support mission-critical customer operations in Reston, VA or Colorado Springs, CO. You will maintain the Vulnerability Management Program, manage the patch repository, issue alerts, and track compliance while coordinating...
$155.6k - $306.8k
Position Summary Help clients reduce cyber risk by leading forward deployed engineering work focused on patching, remediation... ...help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber...Local area- ...Engineer to design and implement network enhancements, monitor systems, and resolve issues across routers, switches, firewalls, and security devices. You will work with Fortinet, BNA, PRTG, and other enterprise tools while supporting end users and coordinating outages....Flexible hours
$105.4k - $207.8k
...As a Full Stack Engineer Senior Consultant in Deloitte Cyber’s Digital Trust & Privacy practice, you will operate at the intersection... ...engineering teams, and communicate effectively with business, security, privacy, legal, and compliance stakeholders.Recruiting for this...Local areaVisa sponsorship$105.4k - $207.8k
...technology landscape against their recovery requirementsBA/BS in Computer Engineering, Computer Science, Information Systems, Cyber Security, or equivalent demonstrated technical backgroundAbility to travel up to 50%, on average, based on the work you do and the clients...Local areaVisa sponsorship$105.4k - $207.8k
Position Summary As a Senior Consultant - Cyber Defense and Resilience, you will help deliver security engineering solutions that modernize client security... ...into deployable capabilities that improve analyst efficiency, alert quality, and response speed. Recruiting...Local areaVisa sponsorship$97.61k - $188.38k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.... ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 10/31/2026Work you’ll...Local areaVisa sponsorship$105.4k - $207.8k
Position Summary Cyber Senior Consultant - DevSecOps Position Summary Are you interested in working in a dynamic environment... ...Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both...Local areaWorldwideVisa sponsorship$105.4k - $207.8k
Position Summary Join Deloitte’s Cyber practice as a Cyber SecOps Senior Consultant... ...landscape through scalable, resilient security operations solutions. In this hands-on role... ...with security operations center analysts and threat detection engineers to prioritize...Local areaVisa sponsorship$160k - $205k
...and make an impact. Join us!Job Description:Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America’s Cyber Security Assurance Offensive Security group. The program provides services to assess the security resilience...Full timeWork at officeShift workDay shift- ...Washington, DC area. You will resolve complex IT issues, including hardware, software, and telecom problems, while aligning with security and policy guidelines. You’ll work with security operations, perform malware analysis, and help harden network devices. Strong Microsoft...Full time
$155.6k - $306.8k
Position Summary As an Engineering Manager in Deloitte Cyber’s Digital Trust & Privacy practice, you will help clients solve complex identity, access, and data protection challenges through AI-enabled engineering solutions. This role sits at the intersection of...Local areaVisa sponsorship$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.... ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll...Local areaVisa sponsorship- Netcompany Group A/S, a European technology leader, seeks a Lead IT Business Analyst to drive large-scale transformation projects for EU and Public Sector units. You will mentor analysts, gather requirements with stakeholders, and prioritize backlogs to align business needs...
$131.8k - $290k
Job Title: Senior Cyber Network Operations Analyst Job Category: Engineering Time Type: Full time Minimum Clearance Required to Start: TS/SCI with... ...programs with peers who are dedicated to advancing national security. Participate in fun team outings and team building events...Full timeContract workWork experience placementLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security Analyst. Be the first to apply!
- information security consultant Brooklyn, NY
- cyber security analyst Brooklyn, NY
- remote cyber security analyst Brooklyn, NY
- cyber insurance Brooklyn, NY
- cyber sales Brooklyn, NY
- cyber Brooklyn, NY
- cyber security architect Brooklyn, NY
- cybersecurity software engineer Brooklyn, NY
- cyber security technician Brooklyn, NY
- work from home cyber security Brooklyn, NY

