Cyber Security Analyst

Pitech Solutions, Inc.

Washington, Northern (District of Columbia, KY)

Hybrid

USD 110,000 - 165,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PiTech Solutions Inc is seeking a Cybersecurity Analyst to support independent, evidence-based cybersecurity assessments for U.S. federal agencies.

The role plans and executes security control assessments, testing, and compliance evaluations aligned to FISMA/NIST; an active Top Secret clearance is required. Responsibilities include RMF support, hands-on testing across endpoints, cloud, and IAM, and delivering actionable findings with executive summaries.

Qualifications

  • Active TS clearance with eligibility to maintain access.
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field, or equivalent relevant experience.
  • 7+ years of cybersecurity experience in federal or regulated environments (or 5+ years with a Master’s degree).
  • Familiarity with federal cybersecurity requirements and assessment approaches (FISMA; NIST SP 800-53; RMF concepts and artifacts).
  • Hands‑on ability to review configurations and validate controls across Windows/Linux, AD/Azure AD, network, endpoints, and logging/monitoring.
  • Strong written and verbal communication; ability to produce executive-ready summaries.

Responsibilities

  • Assessment planning and scoping: engage with agency stakeholders to confirm system boundaries, environments (on-prem/cloud/hybrid), data types, and mission priorities; define objectives, methodology, schedule, sampling, and evidence requests.
  • Security control assessment: evaluate controls against baselines/overlays (NIST SP 800-53); map statements to evidence and document results, rationale, and traceability.
  • RMF support: assist with categorization, selection, implementation validation, assessment, authorization, and continuous monitoring; review SSPs, SAP/SAR, POA&Ms.
  • Technical validation and testing: perform hands-on security testing with authorization, including configuration reviews, vulnerability validation, log review across endpoints, servers, IAM services, cloud resources, and tooling.
  • Vulnerability and configuration assessment: run automated scans (credentialed when possible), benchmark configurations (CIS/STIG), identify false positives/negatives; provide remediation recommendations.
  • Cloud security assessment: evaluate cloud configurations and controls (identity, network segmentation, encryption, logging, key management, shared responsibility) across CSPs and FedRAMP expectations.
  • Incident readiness and operational security: assess SOC processes, playbooks, alerting, escalation, forensics readiness, and tabletop exercises; review logging coverage and retention.
  • Policy, governance, program reviews: assess cybersecurity program documentation, governance, risk acceptance, exception handling, asset management, vulnerability management, secure configuration, change control, and third‑party risk.
  • Evidence management: collect, organize, and protect sensitive assessment materials; maintain evidence trail (interview notes, screenshots, configuration exports, scan outputs, log samples).
  • Reporting and briefings: draft findings, risk ratings, root cause, impacts, recommendations; present to technical teams and executives; tailor communications for depth and decision-making.
  • Remediation support and verification: collaborate with owners to validate remediation plans, track POA&Ms, and re-test with evidence review.
  • Stakeholder coordination: work with federal personnel, contractors, and third parties; coordinate interviews and sessions; provide status updates and escalate blockers.
  • Quality and compliance: follow internal standards, templates, QA processes to ensure accuracy and contract alignment.

Skills

Written communication
Verbal communication
Leadership of workstreams
Technical testing
RMF knowledge

Education

Bachelor’s degree in Cybersecurity or related field
Master’s degree beneficial

Tools

GRC artifacts
Vulnerability scanning
IAM/AD
SIEM platforms
Cloud platforms

Job description

PiTech Solutions Inc is pleased to provide a comprehensive assessment of a federal agency's cybersecurity. Our mandate is a team of professionals that support an entire federal agency's technology infrastructure, cybersecurity posture and cloud services.

We will deliver six months of structured, evidence-based assessment work culminating in actionable findings across eight domains — organizational, governance, operational, infrastructure, cybersecurity, contracts and licensing, modernization, and data/AI readiness. Every recommendation is weighted against priorities, cybersecurity, and compliance first, followed by governance accountability, operational performance, technology lifecycle, and cost efficiency.

Job Description: Cybersecurity Analyst (Federal Assessments Top Secret Clearance)

Position Summary
PiTech Solutions Inc. is seeking a Cybersecurity Analyst to support independent, evidence-based cybersecurity assessments for U.S. federal agencies. This role plans and executes security control assessments, technical testing, and compliance evaluations aligned to federal requirements (e.g., FISMA, NIST, and agency-specific policies). The analyst documents objective evidence, identifies risk and root cause, and produces clear, actionable recommendations for executives and technical teams. This position requires an active Top Secret (TS) clearance (with eligibility to maintain access as required).

Key Responsibilities
  • Assessment planning and scoping: Participate in discovery with agency stakeholders to confirm system boundaries, environments (on-prem/cloud/hybrid), interconnections, data types, and mission priorities; define assessment objectives, methodology, schedule, sampling strategy, and evidence request lists.
  • Security control assessment (SCA): Evaluate management, operational, and technical controls against applicable baselines and overlays (e.g., NIST SP 800-53); map implementation statements to objective evidence and document assessment results, rationale, and traceability.
  • Risk Management Framework (RMF) support: Assist with RMF activities across the system lifecycle (categorization, selection, implementation validation, assessment, authorization support, and continuous monitoring); review and validate SSPs, SAP/SAR artifacts, POA&Ms, and continuous monitoring strategies.
  • Technical validation and testing: Perform hands‑on security testing where authorized, including configuration reviews, vulnerability validation, log review, and control verification across endpoints, servers, network devices, IAM services, cloud resources, and security tooling.
  • Vulnerability and configuration assessment: Execute and analyze results from automated scans (credentialed when possible), benchmark configurations (e.g., CIS/STIG guidance as applicable), and identify false positives/negatives; develop prioritized remediation recommendations.
  • Cloud security assessment: Assess cloud service configurations and controls (e.g., identity, network segmentation, encryption, logging/monitoring, key management, and shared responsibility considerations) across major CSP platforms and FedRAMP-aligned control expectations.
  • Incident readiness and operational security: Evaluate detection and response capabilities (SOC processes, playbooks, alerting, escalation, forensics readiness, and tabletop exercises); assess logging coverage and retention to support investigations and compliance.
  • Policy, governance, and program reviews: Assess cybersecurity program documentation, governance, and oversight processes (e.g., risk acceptance, exception handling, asset management, vulnerability management, secure configuration, change control, and third‑party risk).
  • Evidence management: Collect, organize, and protect sensitive assessment materials; maintain a defensible evidence trail, including interview notes, screenshots, configuration exports, scan outputs, and log samples in accordance with handling requirements.
  • Reporting and briefings: Draft assessment deliverables (findings, risk ratings, root cause, impacts, and recommendations) and present results to technical teams and executive leadership; tailor communications for both technical depth and leadership decision‑making.
  • Remediation support and verification: Collaborate with system owners and engineers to validate remediation plans, track POA&Ms, and confirm corrective actions through re‑testing and evidence review.
  • Stakeholder coordination: Work effectively with federal personnel, contractors, and third parties; facilitate interviews and working sessions; provide clear status updates and elevate blockers in a timely manner.
  • Quality and compliance: Follow internal assessment standards, templates, and QA processes to ensure consistency, accuracy, and alignment with contract requirements and federal audit expectations.
Required Qualifications
  • Active Top Secret (TS) clearance (and ability to meet ongoing access eligibility requirements).
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field, or equivalent relevant experience.
  • Demonstrated experience conducting cybersecurity assessments, audits, or security control assessments in federal or regulated environments, including 7+ years of related cybersecurity experience (or 5+ years with a Master’s degree).
  • Working knowledge of federal cybersecurity requirements and assessment approaches (e.g., FISMA; NIST SP 800-53 control assessments; RMF concepts and artifacts such as SSP, SAP/SAR, and POA&M).
  • Hands‑on technical capability to review configurations and validate controls across common enterprise technologies (Windows/Linux, Active Directory/Azure AD or equivalent IAM, network fundamentals, endpoint security, vulnerability management, and logging/monitoring).
  • Strong written communication skills, including ability to produce clear findings, objective evidence narratives, and executive‑ready summaries.
  • Strong verbal communication and interviewing skills; comfortable working with stakeholders from engineers to senior leaders.
  • Ability to lead assessment workstreams with minimal oversight, including mentoring junior assessors, coordinating evidence requests, and driving deliverable quality.
  • Ability to manage multiple tasks, meet deadlines, and work independently with minimal supervision.
Desired Qualifications
  • Industry certifications such as Security+, CySA+, SSCP, CISSP, CISM, CISA, CCSP, or equivalent.
  • Experience supporting ATO packages and authorization activities, including coordination with Authorizing Officials (AOs) and SCA teams.
  • Familiarity with FedRAMP requirements and control expectations for cloud services.
  • Experience with DISA STIGs and security technical implementation guidance; familiarity with benchmark tooling and configuration baselines.
  • Experience with vulnerability scanning and security tools (e.g., Tenable/Nessus, Qualys, Rapid7; endpoint security; SIEM platforms such as Splunk, Sentinel, or Elastic).
  • Basic scripting/automation experience (e.g., PowerShell, Python) for evidence collection, analysis, or reporting efficiency.
  • Experience supporting Zero Trust initiatives (e.g., identity‑centric security, MFA/conditional access, segmentation, device compliance, and continuous verification) aligned to federal guidance.
  • Experience performing tabletop exercises, incident response assessments, or log management maturity reviews.
Tools & Technologies (Representative)
  • GRC and assessment artifacts: SSP/SAP/SAR/POA&M documentation, evidence trackers, control matrices, and risk registers
  • Vulnerability and configuration assessment: credentialed scanning, secure configuration benchmarks, patch/vulnerability remediation workflows
  • Identity and access management: RBAC, MFA, privileged access management concepts, account lifecycle processes
  • Logging and monitoring: SIEM queries, log source onboarding validation, alert triage concepts, retention/immutability considerations
  • Cloud platforms: configuration review concepts for major CSP services (networking, IAM, encryption, logging, resource governance)
  • Collaboration and documentation: Microsoft 365, Word/Excel/PowerPoint, SharePoint/Teams, ticketing systems, and secure file handling
Security Requirements

This position requires an active Top Secret (TS) clearance and strict adherence to all applicable security requirements, including need-to-know access, approved information system use, and proper handling of sensitive and classified information. Candidate must be able to maintain clearance eligibility and comply with agency and contract‑specific security policies.

Work may be performed on‑site at federal facilities and/or in secure environments as required by the agency. Occasional travel may be required for on‑site interviews, evidence collection, and briefings. The role may involve working with time‑sensitive deliverables during assessment fieldwork and reporting cycles.

Work shall be performed primarily onsite in NW, Washington, DC 20573. We recognize that select analytical activities (e.g., drafting, synthesis, and report development) may be performed offsite when coordinated with the COR; however, quoters shall assume the engagement requires substantial onsite presence to support interviews, workflow observation, and stakeholder engagement

Period of Performance 6 months

PiTech Solutions Inc. is an equal opportunity employer. Employment decisions are based on qualifications, merit, and business needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Federal Cybersecurity Assessor (TS Clearance)
Federal Cybersecurity Assessor (TS Clearance)

Pitech Solutions, Inc. • Washington, Northern (KY)

Hybrid
USD 110,000 - 165,000
Cybersecurity Analyst - Security Standards & Baselines / Active Secret
Cybersecurity Analyst - Security Standards & Baselines / Active Secret

Peraton • Arlington (VA)

Hybrid
USD 86,000 - 138,000
System Technical Security Analyst
System Technical Security Analyst

FSR, LLC. • Herndon (VA)

On-site
USD 100,000 - 130,000
Systems Security Analyst
Systems Security Analyst

ADG Tech Consulting, LLC • Vienna (VA)

Hybrid
USD 90,000 - 120,000
PENDING CONTRACT AWARD: Cybersecurity Task Lead (Applicants must already hold a Top Secret Clea[...]
PENDING CONTRACT AWARD: Cybersecurity Task Lead (Applicants must already hold a Top Secret Clea[...]

Cipher Tech Solutions • Baltimore (MD)

On-site
USD 66,000 - 149,000
401k matching
Health benefits
Paid time off
Cybersecurity Engineer
Cybersecurity Engineer

Thinktekllc • Arlington (VA)

On-site
USD 150,000 - 185,000
Medical Insurance
Dental Insurance
Vision Insurance
+1
Technical Project Manager
Technical Project Manager

ECS • Richmond (VA)

Hybrid
USD 110,000 - 125,000
Cyber Risk Analyst (TS/SCI)
Cyber Risk Analyst (TS/SCI)

Beyond SOF • Reston (VA)

On-site
USD 95,000 - 140,000
Health insurance
Cyber Security Administrator
Cyber Security Administrator

Prescient Edge • Town of Florida (NY)

On-site
USD 85,000 - 120,000
Competitive salary with performance bonus opportunities
Comprehensive healthcare benefits
Substantial retirement plan
+2
Cybersecurity Engineer
Cybersecurity Engineer

ThinkTek • Arlington (VA)

On-site
USD 150,000 - 185,000
Medical, dental, and vision insurance
Paid time off (PTO)
Paid leave options