Enable job alerts via email!
Boost your interview chances
Aerstone is seeking a Cybersecurity Analyst to support independent assessments of security controls based on NIST standards. This remote role is ideal for candidates with 2–5 years of experience, offering opportunities to expand skills in risk assessments and compliance standards. Join a veteran-owned firm valuing team performance and technical excellence.
Direct message the job poster from Aerstone
Position: Cybersecurity Analyst (Intermediate)
Location: Remote – U.S.-based
Company: Aerstone (Quest Consultants LLC DBA Aerstone)
Overview:
Aerstone is seeking a Cybersecurity Analyst to support independent assessments of customer security controls in accordance with the NIST Risk Management Framework (RMF). Assessment scopes may include applications, general support systems, cloud platforms, infrastructure components, and enterprise information systems.
This role is suited for candidates with 2–5 years of cybersecurity experience looking to expand their expertise in risk assessments and federal compliance standards.
About Aerstone:
Aerstone is a cybersecurity consulting firm based in the D.C. metro area. We offer a work-from-home model with team members distributed across the U.S. Most engagements are remote; travel is limited and estimated at less than 20%.
Aerstone is more than just a great company, it's a great culture. We are looking for someone that has a team-first mentality. At Aerstone, we believe strongly in team performance and that “the sum of the parts is greater than the whole.” Our chosen candidate will be the sort of teammate that participates, communicates, and is passionate about their work. Success is found when our team succeeds, and our customers’ needs are being met.
Key Responsibilities:
· Support planning and coordination of RMF-based security assessments
· Review system security plans (SSPs) and supporting documentation
· Conduct interviews with system owners and subject matter experts
· Identify and analyze cybersecurity risks, control gaps, and mitigation strategies
· Assist in the development of risk assessment reports and supporting materials
· Collaborate with internal teams and clients to clarify technical and procedural details
· Document findings clearly and concisely for technical and non-technical audiences
Qualifications:
Required:
2–5 years of experience in cybersecurity, including exposure to:
o Applications
o Operating systems
o Network infrastructure
o Cloud services
· Understanding of risk-based control assessment methodologies
· Familiarity with NIST SP 800-53 Rev. 4 and 5, and ability to apply control requirements
· Ability to work independently and manage time effectively including managing multiple projects concurrently
· Well-developed interpersonal, communication (written and verbal), organizational, and analytical skills
· Excellent consultative skills and the proven ability to work effectively with business partners, internal management and staff, vendors and consultants
· Strong written communication skills for documentation and reporting
· Proven ability to communicate technical issues to technical and non-technical business partners
· Experience preparing and leading assessment interviews of highly technical information systems
· Demonstrated proficiency with report and technical writing
· U.S. Citizenship and the ability to obtain a Public Trust clearance
Preferred:
· Experience participating in security assessments under FISMA, FedRAMP, or CMMC guidelines
· Knowledge of cloud platforms (AWS, Azure) and the inherited control model
· Exposure to threat modeling techniques
· Familiare with industry frameworks: NIST SP 800-30, ISO 27005/31000, PCI DSS, SOX
· Experience using industry standard project/task management tools
Certifications (Preferred but not Required):
· CISSP, CySA+, CISA, or equivalent
· AWS Cloud Practitioner, Azure Fundamentals, CCSP, or similar
· PMP or experience with structured project support
Additional Information:
· Education: Bachelor’s degree (technical or related field preferred)
· Clearance: Must be eligible to obtain a U.S. government Public Trust clearance
· Work Environment: Remote (U.S.-based); minimal travel required
· Other: May include collaboration with other cybersecurity teams or occasional client presentations
About Our Culture:
Aerstone is a Service-Disabled Veteran-Owned Small Business (SDVOSB) offering competitive benefits, remote work flexibility, and ongoing training opportunities. We value integrity, technical excellence, and a mission-driven mindset.
EEO & Compliance Statement:
Aerstone is an Equal Opportunity Employer. We are committed to an inclusive workplace where individuals are hired, promoted, and compensated based on merit, regardless of race, religion, gender, veteran status, or other legally protected status. U.S. citizenship is required due to federal contract requirements.
Referrals increase your chances of interviewing at Aerstone by 2x
Continue with Google Continue with Google
Baltimore, MD $90,000 - $110,000 3 weeks ago
Baltimore, MD $90,000 - $110,000 3 weeks ago
Maryland, United States $90,000 - $155,000 7 months ago
Owings Mills, MD
$125,000.00
-
$140,000.00
1 week ago
Maryland, United States
$211,000.00
-
$297,000.00
2 weeks ago
Baltimore, MD
$85,000.00
-
$165,000.00
2 weeks ago
Elkridge, MD
$185,000.00
-
$200,000.00
1 week ago
Maryland, United States
$90,000.00
-
$155,000.00
7 months ago
Maryland, United States
$101,900.00
-
$234,500.00
1 week ago
Fort Meade, MD $77,600 - $176,000 2 weeks ago
Maryland, United States $101,900 - $234,500 1 week ago
Fort Meade, MD $77,600 - $176,000 2 weeks ago
Maryland, United States $100,000 - $175,000 1 week ago
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.