Cyber Security Analyst II

Smiths Detection

Edgewood (MD)

On-site

USD 98,000 - 147,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, dental & vision insurance
401(k) with company match
Paid time off

Job summary

Smiths Detection in Edgewood, MD is seeking a Cyber Security Analyst II to join a small, high-impact security team supporting a DIB environment. This senior technical practitioner will own the Microsoft security stack and craft policies to sustain CMMC Level 2 under NIST SP 800-171.

You will mentor a junior analyst, drive vulnerability management and incident response, and collaborate with HR, IT, and Facility Security on joiner/mover/leaver processes, access reviews, and audits.

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field or equivalent experience.
  • 3–5 years of hands-on cybersecurity experience, with 2+ in Microsoft 365 / Entra ID / Intune / Defender.
  • Experience authoring security policies and procedures and knowledge of NIST SP 800-171 Rev. 2 / CMMC Level 2.

Responsibilities

  • Microsoft Security Operations: administer and tune Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Entra ID, Intune, and Purview.
  • Policy and Procedure Authorship: write and map controls to 171 Rev. 2 and CMMC Level 2.
  • Cross-Functional Process Ownership: coordinate joiner/mover/leaver, access reviews, privileged access management.
  • Vulnerability and Patch Management: conduct vulnerability cycles and report remediation.
  • Incident Response: act as tier-2 responder and drive post-incident reviews.
  • Evidence and Audit Support: maintain SSP and POA&M, prepare for audits.

Skills

Microsoft Defender
Entra ID
Intune
Purview
NIST SP 800-171
CMMC Level 2
SIEM
Vulnerability management
Incident response
Policy authoring

Education

Bachelor’s degree in Cybersecurity / Information Systems / CS

Tools

Nessus
Sentinel
Splunk
Google Chronicle

Job description

Job Description

Job Objective

The Cyber Security Analyst II is the senior technical practitioner on a small, high-impact security team supporting a Defense Industrial Base (DIB) environment handling controlled data. This role is the hands-on owner of our Microsoft security stack and the primary author of the policies, procedures, and evidence artifacts required to sustain our CMMC Level 2 posture under NIST SP 800-171. The analyst works directly with the Information & Cyber Security Manager to mature the program, own cross-functional processes, and mentor a junior analyst.

Responsibilities

Essential functions—job duties to include but are not limited to; other duties as assigned.

  • Microsoft Security Operations: Shared ownership of day-to-day administration and tuning of Microsoft Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Entra ID (Conditional Access, PIM, Identity Protection), Intune (compliance policies, configuration profiles, update rings, app protection), and Purview (DLP, Insider Risk, Information Protection).
  • Policy and Procedure Authorship: Draft, maintain, and operationalize written policies and procedures mapped to NIST SP 800-171 Rev. 2 and CMMC Level 2 practices. Translate control language into runbooks, checklists, and evidence artifacts that an assessor can verify.
  • Cross-Functional Process Ownership: Partner with HR, IT, and Facility Security to develop and improve the end-to-end joiner/mover/leaver process, quarterly access reviews, privileged access management, and onboarding/offboarding of authorized users.
  • Vulnerability and Patch Management: Run the recurring vulnerability management cycle (Defender Vulnerability Management, Nessus, or equivalent): triage, prioritize, track SLAs, and report on remediation against a defined framework.
  • Incident Response: Act as tier-2 responder for Defender and Entra alerts; investigate, contain, and document incidents; lead post-incident reviews; maintain and exercise the incident response plan.
  • Evidence and Audit Support: Collect and maintain evidence for internal self-assessments and customer audits. Maintain the System Security Plan (SSP) and POA&M alongside the Security Manager.
  • Security Awareness and Training: Execute and measure the monthly phishing simulation program and deliver targeted training for elevated-risk roles.
  • Mentoring: Provide technical direction and review for the Cyber Security Analyst I and serve as the escalation point for their work.
  • Other Duties: Other duties as assigned.
Qualifications

Qualifications

Education Requirements
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field OR equivalent combination of certifications and hands-on experience.
Preferred Education and Experience
  • 3–5 years of hands-on Cyber security experience, at least 2 of which include direct administration of Microsoft 365 / Entra ID / Intune / Defender in a production environment.
  • Demonstrable experience authoring security policies and procedures.
  • Working knowledge of NIST SP 800-171 Rev. 2 and/or CMMC Level 2; understands control mapping, procedure development, and evidence production.
Years of Experience
  • 3–5 years of hands-on Cyber security experience, at least 2 of which include direct administration of Microsoft 365 / Entra ID / Intune / Defender in a production environment.
  • Demonstrable experience authoring security policies and procedures.
  • Working knowledge of NIST SP 800-171 Rev. 2 and/or CMMC Level 2; understands control mapping, procedure development, and evidence production.
Additional Qualifications
  • U.S. Citizenship required.
  • Strong written communication — will produce documents read by executives, auditors, and government customers.
  • Prior experience in a DIB / defense contractor / cleared facility environment.
  • Experience with Microsoft GCC or GCC High tenants.
  • Experience with a SIEM (Sentinel, Splunk, Google SecOps/Chronicle, or similar) including log source onboarding and rule tuning.
  • Familiarity with DFARS 252.204-7012, ITAR, and the SPRS scoring process.
  • Microsoft certifications: SC-200, SC-300, SC-400, MS-500, AZ-500.
  • CMMC Registered Practitioner (RP) or Certified CMMC Professional (CCP).
Technical Knowledge, Skills and Abilities
  • Microsoft Defender suite (Endpoint, Office 365, Cloud Apps)
  • Entra ID
  • Intune
  • Purview
  • NIST SP 800-171 Rev. 2
  • CMMC Level 2
  • vulnerability management tools (Nessus or equivalent)
  • SIEM platforms, incident response
Additional Information
We offer…

Join us and we’ll help build your career, with excellent training and opportunities for career growth across the business, both locally and globally. You’ll experience an inclusive environment, with strong leadership and a focus on safety and wellbeing. You’ll also have the flexibility to choose from a wide range of benefits to suit your lifestyle, offering you and your family support from a health and wellbeing, financial and lifestyle perspective.

Join us and work for a world‑leader, with the benefits and training to reward your dedication and skills. Be part of a team where we are making the world a safer place.

The total compensation for this position ranges from $98,311 - $147,468/yr (Salary to be determined by the education, experience, knowledge, skills, & abilities of the applicant and the alignment with the internal team & market data). This role offers a competitive Business Profit Plan. This position includes a competitive benefits package. The comprehensive benefits package includes medical, dental & vision insurance; 401(k) with company match; paid time off; and other benefits. For details, please visit the Rewards & Benefits tab on our main careers page at Careers | Smiths Detection.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, protected veteran status, disability, or any other legally protected characteristic.

If you have a disability and you believe you need a reasonable accommodation in order to search for a job opening or to submit an online application, please e‑mail stat@smiths.com or call toll‑free 877-703-1029. This email and phone number is created exclusively to assist disabled job seekers whose disability prevents them from being able to apply online. Only messages left for this purpose will be returned. Messages left for other purposes, such as following up on an application or technical issues not related to a disability, will not receive a response. Smiths Detection participates in the Electronic Employment Verification Program.

All qualified applicants will receive equal consideration for employment based solely on their skills, experience, and ability to perform the job. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, or any other characteristic protected by applicable law.

We value professionalism, integrity, and respect in our workplace, and we strive to maintain an environment where every employee can contribute effectively to our mission.

At no time during the hiring process will Smiths Detection, nor any of our recruitment partners ever request payment to enable participation – including, but not limited to, interviews or testing. Avoid fraudulent requests by applying jobs directly through our career’s website.

All qualified applicants will receive equal consideration for employment based solely on their skills, experience, and ability to perform the job. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, or any other characteristic protected by applicable law.

We value professionalism, integrity, and respect in our workplace, and we strive to maintain an environment where every employee can contribute effectively to our mission.

At no time during the hiring process will Smiths Detection, nor any of our recruitment partners ever request payment to enable participation – including, but not limited to, interviews or testing. Avoid fraudulent requests by applying jobs directly through our career’s website.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst II
Cyber Security Analyst II

Smiths Group • Edgewood (MD)

On-site
USD 98,000 - 147,000
Cyber Security Analyst I
Cyber Security Analyst I

Smiths Detection • Edgewood (MD)

On-site
USD 76,000 - 115,000
Cyber Security Analyst I
Cyber Security Analyst I

Smiths Group • Edgewood (MD)

On-site
USD 76,000 - 115,000
Medical insurance
Dental insurance
Vision insurance
+2
Field Service Technician II CVG
Field Service Technician II CVG

Smiths Detection • Hebron Estates (KY)

On-site
USD 74,000 - 101,000
Medical insurance
Dental insurance
401(k) with company match
+1
Field Service Technician I - DFW
Field Service Technician I - DFW

Smiths Detection • Dallas (TX)

On-site
USD 65,000 - 88,000
Field Service Technician I - DTW
Field Service Technician I - DTW

Smiths Group • Detroit (MI)

On-site
USD 65,000 - 88,000
Field Service Technician I - DTW
Field Service Technician I - DTW

Smiths Detection • Detroit (MI)

On-site
USD 65,000 - 88,000
Training and career growth
Health benefits
401(k) with company match
+1
Field Service Technician I - ORF
Field Service Technician I - ORF

Smiths Detection • Norfolk (VA)

On-site
USD 59,000 - 88,000
Medical insurance
Dental insurance
Vision insurance
+2
Field Service Technician I - ORF
Field Service Technician I - ORF

Smiths Group • Norfolk (VA)

On-site
USD 59,000 - 88,000
Medical Insurance
401(k) with company match
Paid time off
Business Engagement Manager
Business Engagement Manager

Smiths Detection • Edgewood (MD)

On-site
USD 136,000 - 204,000
Medical, dental, & vision insurance
401(k) with company match
Paid time off