Senior Cybersecurity Analyst

Ochtec

Washington (NJ)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Paid time off and Holidays
Medical, Dental, and Vision Insurance
401(k)
Tuition Reimbursement
Life Insurance
Short-term/Long-term Disability

Job summary

OCH Technologies, LLC seeks a Senior Cybersecurity Analyst to execute independent risk assessments and vulnerability scans across NAS and Mission Support systems at FAA hub locations in OKC, Egg Harbor, and Washington, DC. You will own assigned systems, lead on-site test events, and deliver SARs and POAMs with actionable remediation steps.

The role requires 8+ years of security assessment experience, strong knowledge of NIST SP 800-53A and RMF, and relevant certifications.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics.
  • 8+ years of hands-on security assessments experience, with at least 2 years recent.
  • Knowledge of NIST SP 800-53A, RMF, and FIPS-199.
  • Proficiency with vulnerability scanning tools (Nessus, WebInspect, nMap, etc.).

Responsibilities

  • Execute independent risk assessments on NAS and Mission Support systems.
  • Lead on-site assessment events at FAA facilities nationwide.
  • Develop SARs documenting findings, risk levels, and mitigations.
  • Create POAMs with actionable remediation steps.
  • Perform regression assessments to verify remediation.

Skills

Risk assessment
Vulnerability assessment
Interviews
Communication
Team leadership

Education

Bachelor's degree in Cybersecurity/CS/IT/Engineering/Math/Physics

Tools

Nessus
WebInspect
nMap
AppDetective Pro

Job description

(MMAC) Oklahoma City, OK OR (WJHTC) Egg Harbor, NJ OR (ATCSCC) Washington, DC

OCH Technologies is seeking a Senior Cybersecurity Analyst to execute independent risk assessments and vulnerability assessments at FAA facilities. Candidate should be based at one of three FAA hub locations (Oklahoma City, Atlantic City, or DC) where major NAS programs and equipment reside, with travel to other FAA sites for assessment events. The candidate will own assigned systems, run assessments from kickoff through artifact collection through SAR delivery, and lead on-site test events.

This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.

Location

On site: FAA hub locations- Mike Monroney Aeronautical Center (MMAC) Oklahoma City, OK OR William J. Hughes Technical Center (WJHTC) Egg Harbor, NJ OR Air Traffic Control System Command Center (ATCSCC) Washington, DC.

This position has the potential to travel up to 40% to other FAA facilities nationwide for assessment events.

Core Responsibilities & Duties
  • Execute independent risk assessments on NAS and Mission Support systems using the three NIST 800-53A assessment methods (Examine, Interview, Test).
  • Lead on-site assessment events at FAA facilities nationwide. Coordinate with facility personnel, system owners, and ACG to execute assessments on schedule.
  • Conduct vulnerability scanning using tools including Nessus, WebInspect, AppDetective Pro, nMap, and other FAA-approved tools.
  • Develop System Security Assessment Reports (SARs) documenting findings, risk levels, and recommended mitigations.
  • Develop draft Plans of Action and Milestones (POAMs) with clear, actionable remediation steps.
  • Perform regression assessments to validate that previously identified vulnerabilities have been remediated.
  • Collect and analyze system configuration files, security documentation, and other artifacts required for assessment.
  • Conduct interviews with system administrators, system owners, and other personnel as part of the assessment methodology.
  • Support the Security Assessment Lead in maintaining the Integrated Master Test Schedule and coordinating resource assignments.
  • Maintain proficiency with current assessment tools and techniques. Participate in cross-training during periods between scheduled assessments.

Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role.

Requirements
Minimum Qualifications

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution

Experience

  • A minimum of eight (8)+ years of hands‑on experience conducting security assessments or vulnerability assessments in federal or critical infrastructure environments. At least 2 years of relevant experience must be recent (performed within the last 3 years).
  • Working knowledge of NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37 (RMF), and FIPS‑199.
  • Proficiency with vulnerability scanning tools (Nessus, WebInspect, nMap, or equivalents).
Security Clearance Requirement

Candidate must have the ability to obtain and maintain a Public Trust

Certifications

At least one of the following risk assessment certifications required : CISSP, GCED (GIAC Certified Enterprise Defender), CASP (CompTIA Advanced Security Practitioner), or CISA (Certified Information Systems Auditor). Additional certifications (CEH, GPEN, CAP) preferred but not required

Preferred Qualifications
  • Prior experience assessing NAS systems or working at FAA facilities.
  • Experience with CIS Benchmarks and automated compliance scanning.
  • Experience assessing cloud environments (FedRAMP, AWS GovCloud, Azure Government).
  • Familiarity with operational technology (OT) or industrial control system (ICS) security.
  • Cloud security posture tools (Prowler, ScoutSuite) for assessing AWS GovCloud and Azure Government environments.
  • OpenSCAP or SCAP Compliance Checker for automated compliance validation against CIS Benchmarks and NIST baselines.
  • Elastic/ELK or Splunk for log-based assessment analysis and continuous monitoring data review.
  • AI-assisted documentation analysis tools for accelerating NIST 800-53 control gap identification across system security plans and configuration artifacts.
Other Required Skills and Abilities
  • Ability and willingness to lead test events on-site independently, not just participate as a team member.
  • Strong interpersonal skills for conducting interviews and coordinating with FAA facility personnel who have competing operational priorities.
  • Ability to work in lab and operational environments with appropriate care for safety-critical systems.
About Us

At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting‑edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward‑thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability.

What Defines Us:
  • Integrity - We act with unwavering honesty, ensuring every decision is rooted ethically.
  • Adaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead.
  • People‑Focused - We prioritize relationships, championing growth and mutual success.
  • Accountable - We own our outcomes, striving for excellence through continuous improvement.
  • Collaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions.
Why Join Us?

Step into a role at OCH where your contributions make a tangible impact. Join a team that values creativity and initiative, offering a platform to transform the landscape of government IT services. Here, your work is not just a career—it's a mission. Embrace the opportunity to grow, innovate, and excel alongside industry leaders who are as passionate about technology as they are about making a difference. Plus, we offer a comprehensive benefits package designed to support your wellbeing and work‑life balance, including:

  • Paid time off and Holidays
  • Medical, Dental, and Vision Insurance
  • Short‑term disability, long‑term disability, and life insurance - Employer Paid!
  • 401(k)
  • Additional Voluntary Life Insurance
  • Tuition Reimbursement

& More!

E-Verify Participation: OCH Technologies, LLC is a participant of E-Verify to verify the identity and employment eligibility of newly hired employees.

Veteran’s Preference and Accessibility Statement: At OCH Technologies, we deeply respect and appreciate the unique skills and experiences that veterans bring to our team. As a federal contractor, we encourage qualified veterans to apply and provide preference where permitted by law. Your service and dedication are valued here.

We are committed to creating a workplace that is open, welcoming, and accessible to everyone. In accordance with the Americans with Disabilities Act (ADA) and Section 503 of the Rehabilitation Act, we provide reasonable accommodations throughout the hiring process to ensure individuals with disabilities can apply without barriers. If you need assistance or an accommodation, please contact us at hiring@ochtec.com.

OCH Technologies, LLC is proud to be an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

OCH Technologies, LLC • Leesburg (VA)

On-site
USD 120,000 - 150,000
Medical, Dental, and Vision Insurance
Paid Time Off
401(k)
+1
Security Assessment Lead
Security Assessment Lead

Ochtec • Oklahoma City (OK)

Hybrid
USD 180,000 - 240,000
Paid time off
Medical, Dental, Vision insurance
Short‑/Long-term disability and life保险
+2
Cybersecurity Engineer
Cybersecurity Engineer

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 120,000 - 150,000
Medical, Dental, Vision Insurance
Paid time off & holidays
Parental Leave
+3
Cybersecurity Engineer
Cybersecurity Engineer

Ochtec • Washington (NJ)

Hybrid
USD 130,000 - 180,000
Medical, Dental, Vision Insurance
401(k)
Paid time off and holidays
+2
Security Assessment Lead
Security Assessment Lead

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 140,000 - 190,000
Paid time off
Medical, Dental, Vision Insurance
Parental Leave
+2
NCO (National Cybersecurity Operations) Technical Lead
NCO (National Cybersecurity Operations) Technical Lead

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 180,000 - 240,000
Paid time off
Health Insurance
Parental Leave
+4
Program Manager
Program Manager

Ochtec • Herndon (VA)

Hybrid
USD 150,000 - 210,000
Paid time off
Medical, Dental, Vision Insurance
401(k) plan
+2
Penetration Tester
Penetration Tester

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 120,000 - 180,000
Paid time off
Medical, Dental, and Vision Insurance
401(k)
+1
Program Manager
Program Manager

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 120,000 - 180,000
Paid time off and holidays
Medical, dental, and vision insurance
Paid parental leave
+2
Mid-I Technical Support Analyst
Mid-I Technical Support Analyst

OCH Technologies LLC • Warrenton (VA)

On-site
USD 70,000 - 100,000
Paid time off & holidays
Medical, Dental, Vision Insurance
401(k)
+2