Security Analyst II

PBS
  • Alexandria, Virginia
    14 days ago

    Job Description

    Position Title:

    Security Analyst II

    Department:

    Cybersecurity & Program Management (inactive)


    Corporate Area:

    PBS Technology

    Status:

    Regular, Full time Exempt

    Manager Title:

    Director, Cybersecurity

    Position Overview:

    The Security Analyst II is responsible for building and maturing PBS’s governance, risk, and compliance (GRC) programs, including risk and vulnerability management, policy and procedure development, GRC tool configuration, automation, AI governance, and business continuity, while continuing to provide hands-on security operations support.
    This role is approximately 75% Governance, Risk & Compliance (GRC) program development and 25% security operations, including incident response and threat detection across cloud and on-prem environments.

    Key responsibilities will include, but are not limited to:

    Governance, Risk & Compliance (approximately 75%):'

    • Building and operating the enterprise cyber risk management program, including risk identification, assessment, treatment, and reporting aligned to NIST SP 800-53 Rev 5
    • Building and maturing the vulnerability management program, including scanning coverage, risk-based prioritization, remediation tracking, and metrics/reporting
    • Developing, updating, and maintaining cybersecurity policies, standards, and procedures, and driving their adoption across the PBS ecosystem
    • Configuring and administering GRC tooling, including workflow design, control mapping, and integrations with security and IT platforms
    • Designing and implementing automation to streamline GRC workflows (e.g., evidence collection, continuous control monitoring, and risk and compliance reporting)
    • Supporting the AI governance program, including the secure deployment, monitoring, and testing of AI, aligned to the NIST AI Risk Management Framework
    • Developing and maintaining business continuity and disaster recovery plans, documentation, and tabletop exercises
    • Supporting audits, assessments, and compliance activities, including evidence gathering and remediation tracking

    Security Operations (approximately 25%):

    • Monitoring information systems and assets to identify cybersecurity events and verify the effectiveness of protective measures
    • Detecting anomalous activity and assessing the potential impact of events
    • Executing incident response, containment, and recovery processes, and coordinating response activities with internal and external stakeholders (e.g., MSSPs and vendors)
    • Incorporating lessons learned from incidents into detection, response, and recovery processes
    • Streamlining security operations workflows using AI
    • Additional activities as necessary to support the overall cybersecurity and PBS mission

    Requirements for success:

    Experience requirement:

    • Minimum of 10 years’ experience in cybersecurity and/or information technology
    • Minimum of 5 years’ experience working in cybersecurity GRC (e.g., risk management, compliance, policy and governance, business continuity)
    • Minimum of 4 years’ experience working as a security analyst
    • Minimum of 3 years’ experience working as a systems engineer or administrator

    Education and/or certification requirement:

    • CISSP, CISA, CISM, CRISC, CGRC, or equivalent GRC-focused certifications desired
    • GCIH, GCIA, GMON, GCED, or equivalent GIAC defense focused certifications desired
    • Certifications by EC-Council, ISC2, Cisco, Microsoft, Fortinet, CompTIA, Offensive Security, etc. to be considered based on relevance to defensive cybersecurity operations
    • Bachelor’s Degree in a related field such as cybersecurity, information technology, or computer science; equivalent combination of education and experience may be considered

    Skills and abilities:

    • Ability to design, implement, and continuously improve GRC programs and processes, translating frameworks such as NIST SP 800-53 Rev 5, NIST CSF, and NIST AI RMF into practical policies, controls, and procedures
    • Ability to configure, integrate, and administer GRC platforms and build automated workflows across security and IT systems
    • Ability to participate as a technical lead on all projects requiring cybersecurity expertise and consultation
    • Ability to deploy, integrate, configure, and maintain systems which comprise the overall cybersecurity technology stack
    • Ability to support incident response activities in coordination with internal teams and Managed Security Services Partners (MSSPs)
    • Ability to communicate complex cybersecurity and risk concepts in a clear and concise manner for laypersons unfamiliar with cybersecurity and/or IT concepts
    • Desire and ability to help drive organizational adoption and buy-in of cybersecurity policies and standards across the PBS ecosystem
    • Eagerness to develop, grow, and maintain strong inter-team relationships across the business to aid in the accomplishment of the PBS mission

           

    Preferred qualifications:

    • Experience configuring and administering GRC platforms (e.g., ServiceNow GRC/IRM, Archer, OneTrust, or similar) and building automation and reporting on top of them
    • Strong working knowledge of NIST SP 800-53 Rev 5, NIST CSF, NIST AI RMF, CIS Benchmarks, and business continuity/disaster recovery planning
    • Working knowledge of security operations technologies and concepts including DFIR, SIEM, SOAR, EDR, IAM, PAM, DLP, NGFW, IDS/IPS, CASB, MITRE ATT&CK, MSSPs, vulnerability management, application security, and cloud security (IaaS & PaaS)
    • Fundamental knowledge of scripting and automation (e.g., PowerShell, Python, JavaScript), email security, MDM, OWASP, malware analysis, LOLBAS, WAF, DNS, Linux, Windows, and MacOS



    The base pay range for this position at the beginning of employment is expected to be between $155,000 and $165,000/year. The actual base pay offered may vary depending on multiple individualized factors, including but not limited to job-related knowledge, skills, and experience. The total compensation package for this position will also include other elements for eligible employees, including: (i) eligibility for discretionary bonuses; (ii) various insurance options, including medical, dental, vision, hearing, life, accidental death and dismemberment, short-term and long-term disability, and business travel accident insurance; (iii) identity protection program; (iv) employee assistance program; (v) financial and retirement savings benefits including the PBS Retirement Plan 403(b); (vi) paid time off (17 days per year), paid sick time benefits (12 days per year), paid parental leave (60 days / 12 weeks ), and paid holidays (12 days per year). Details of these benefit plans will be provided upon request. The application window for this position is expected to close on 10/5/2026.


    If hired, the employee will be in an “at-will position,” and the Company reserves the right to modify the base hourly rate/salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.


    PBS is an Equal Opportunity Employer in accordance with the EEOC and the Commonwealth of Virginia.



    Numbers & Facts

    LocationAlexandria, Virginia

    Skills

    • Alliance/Partner Managementunmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Artificial Intelligence (AI) Programming Languagesunmatched
    • Automationunmatched
    • Benchmarkingunmatched
    • Business Developmentunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Applicationsunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Compensation and Benefitsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Improvementunmatched
    • Disaster Recoveryunmatched
    • Documentation Planunmatched
    • Ecosystemsunmatched
    • Establish Prioritiesunmatched
    • GCIA - GIAC Certified Intrusion Analystunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • Home Automationunmatched
    • Incident Responseunmatched
    • Information Assetsunmatched
    • Information Technology & Information Systemsunmatched
    • Infrastructure as a Service (IaaS)unmatched
    • Internet Securityunmatched
    • Intrusion Detection Systemsunmatched
    • Intrusion Prevention Systemsunmatched
    • Machine Toolunmatched
    • Metricsunmatched
    • Operational Supportunmatched
    • Platform as a Service (PaaS)unmatched
    • Policy Developmentunmatched
    • Procedure Developmentunmatched
    • Project/Program Managementunmatched
    • Protective Servicesunmatched
    • Retirement Planunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Analysisunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • ServiceNowunmatched
    • Systems Administration/Managementunmatched
    • Systems Engineeringunmatched
    • Systems Maintenanceunmatched
    • Technical Leadershipunmatched
    • Testingunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder