Security Analyst
Computer World Services Corp. (CWS) · Morrisville, NC · Yesterday
HybridFull-time
About the role
Computer World Services (CWS) is seeking an experienced Security Analyst to support enterprise cybersecurity operations within a Federal IT environment. The successful candidate will administer and maintain security technologies, identify and mitigate vulnerabilities, support vulnerability management initiatives, and serve as a technical advisor to infrastructure and application teams. This individual will work closely with infrastructure engineers, application developers, and security stakeholders to improve the organization's security posture while ensuring compliance with NIST, FISMA, NIH/HHS, and other Federal security requirements.
Responsibilities
- Vulnerability Management
- Serve as the primary administrator for Tenable Security Center (SC) and Nessus vulnerability scanners.
- Perform authenticated and unauthenticated vulnerability scans across enterprise systems.
- Analyze scan results and prioritize remediation activities using CVSS scores, CISA Known Exploited Vulnerabilities (KEV), and organizational risk criteria.
- Produce recurring vulnerability reports for management, system owners, and compliance activities.
- Track remediation progress and validate vulnerability closures.
- Manage vulnerability waivers, risk acceptance documentation, and exception tracking.
- Monitor End-of-Life (EOL), End-of-Support (EOS), and Binding Operational Directive (BOD) vulnerability requirements.
- Coordinate with stakeholders across technical teams to drive timely vulnerability remediation efforts.
- Security Operations
- Experience with firewall management, Cisco Checkpoint, IDS/IPS technologies, log aggregation systems (Splunk), and file integrity monitoring solutions.
- Work with Red Hat Linux, Windows workstation and server OS, and macOS.
- Participate in incident investigations and support cybersecurity response activities.
- Assist with security assessments and continuous monitoring activities.
- Application & Infrastructure Security
- Perform application vulnerability scanning.
- Coordinate vulnerability remediation with application owners.
- Support troubleshooting for application security issues.
- Partner with the Application Development team to identify security improvements throughout the software lifecycle.
- Compliance & Reporting
- Support organizational compliance initiatives including NIST 800-53, FISMA, NIH/HHS cybersecurity policies, and CISA Binding Operational Directives (BODs).
- Prepare executive vulnerability reports, compliance dashboards, monthly security metrics, and remediation status reports.
- Serve as the primary coordinator for annual penetration testing activities, including:
- Coordinating testing schedules.
- Supporting external penetration testing teams.
- Managing findings.
- Tracking remediation efforts.
- Validating corrective actions.
- Producing final response documentation.
- Operational Support
- Provide day-to-day operational cybersecurity support, including customer requests, security consultations, incident investigations, security engineering support, and technical documentation.
- Security Frameworks
- Working knowledge of NIST 800-53, NIST Cybersecurity Framework (CSF), Risk Management Framework (RMF), FISMA, CISA Binding Operational Directives (BODs), and Continuous Monitoring (ConMon).
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Engineering, or related field, or equivalent experience.
- 5–8 years of experience in information security, network security, or related fields.
- Experience working in Data Center or hybrid infrastructure environments.
- One or more of the following certifications preferred:
- CompTIA Security+
- Tenable Certified Professional (TCP)
- ITIL certification
- Applicants must be able to obtain a Public Trust clearance.