Security Analyst

Computer World Services
  • Morrisville, North Carolina
    30+ days ago

    Job Description

    Computer World Services (CWS) is seeking an experienced Security Analyst to support enterprise cybersecurity operations within a Federal IT environment. The Security Analyst will be responsible for administering and maintaining security technologies, identifying and mitigating vulnerabilities, supporting vulnerability management initiatives, and serving as a technical advisor to infrastructure and application teams.

     

    The successful candidate will possess strong experience with vulnerability management, firewall administration, security monitoring, and Federal cybersecurity compliance. This individual will work closely with infrastructure engineers, application developers, and security stakeholders to improve the organization's security posture while ensuring compliance with NIST, FISMA, NIH/HHS, and other Federal security requirements.

    Key Tasks & Responsibilities

    Essential Duties and Responsibilities

    Vulnerability Management

    • Serve as the primary administrator for Tenable Security Center (SC) and Nessus vulnerability scanners.
    • Perform authenticated and unauthenticated vulnerability scans across enterprise systems.
    • Analyze scan results and prioritize remediation activities using CVSS scores, CISA Known Exploited Vulnerabilities (KEV), and organizational risk criteria.
    • Produce recurring vulnerability reports for management, system owners, and compliance activities.
    • Track remediation progress and validate vulnerability closures.
    • Manage vulnerability waivers, risk acceptance documentation, and exception tracking.
    • Monitor End-of-Life (EOL), End-of-Support (EOS), and Binding Operational Directive (BOD) vulnerability requirements.
    • Coordinate with stakeholders across technical teams to drive timely vulnerability remediation efforts.

     

    Security Operations

    • Experience with:
      • Firewall Management
        • Cisco
        • Checkpoint
      • IDS/IPS technologies
      • Log aggregation systems (Splunk)
      • File integrity monitoring solutions
      • Red Hat Linux
      • Windows workstation and server OS
      • MacOS
    • Participate in incident investigations and support cybersecurity response activities.
    • Assist with security assessments and continuous monitoring activities.

     

    Application & Infrastructure Security

    • Perform application vulnerability scanning.
    • Coordinate vulnerability remediation with application owners.
    • Support troubleshooting for application security issues.
    • Partner with the Application Development team to identify security improvements throughout the software lifecycle.

      

    Compliance & Reporting

    Support organizational compliance initiatives including:

    • NIST 800-53
    • FISMA
    • NIH/HHS cybersecurity policies
    • CISA Binding Operational Directives (BODs)
    • Continuous Monitoring (ConMon)

    Prepare:

    • Executive vulnerability reports
    • Compliance dashboards
    • Monthly security metrics
    • Remediation status reports

     

    Penetration Testing Remediation Support

    Serve as the primary coordinator for annual penetration testing activities.

    Responsibilities include:

    • Coordinating testing schedules
    • Supporting external penetration testing teams
    • Managing findings
    • Tracking remediation efforts
    • Validating corrective actions
    • Producing final response documentation

     

    Operational Support

    Provide day-to-day operational cybersecurity support including:

    • Customer requests
    • Security consultations
    • Incident investigations
    • Security engineering support
    • Technical documentation

     

    Security Frameworks

    Working knowledge of:

    • NIST 800-53
    • NIST Cybersecurity Framework (CSF)
    • Risk Management Framework (RMF)
    • FISMA
    • CISA Binding Operational Directives (BODs)
    • Continuous Monitoring (ConMon)

     

    Education & Experience

    Education

    • Bachelor’s degree in Computer Science, Information Systems, Engineering, or related field. Equivalent experience.

    Experience

    • 5–8 years of experience in information security, network security, or related fields.
    Experience working in Data Center or hybrid infrastructure environments  

    Certifications

    One or more of the following preferred:

    • CompTIA Security+
    • Tenable Certified Professional (TCP) 
    • ITIL certification preferred.

    Security Clearance

    • Applicants must be able to obtain a Public Trust clearance
    Computer World Services is an affirmative action and equal employment opportunity employer. Current employees and/or qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, disability, protected veteran status, genetic information or any other characteristic protected by local, state, or federal laws, rules, or regulations.
    Computer World Services is committed to the full inclusion of all qualified individuals. As part of this commitment, Computer World Services will ensure that individuals with disabilities (IWD) are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact Human Resources at [email protected]
    We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

    Numbers & Facts

    LocationMorrisville, North Carolina

    Skills

    • Analysis Skillsunmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Authenticationunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • Cisco Network Systemsunmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Computer Servicesunmatched
    • Computer Workstationsunmatched
    • Corrective Actionunmatched
    • Department of Health and Human Servicesunmatched
    • Documentationunmatched
    • Establish Prioritiesunmatched
    • FISMA - Federal Information Security Management Actunmatched
    • Firewall Administrationunmatched
    • Firewallsunmatched
    • ITIL (IT Infrastructure Library)unmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Intrusion Detection Systemsunmatched
    • Intrusion Prevention Systemsunmatched
    • Mac Operating Systemunmatched
    • Maintain Complianceunmatched
    • Metricsunmatched
    • Microsoft Windows Serverunmatched
    • National Institutes of Health (NIH)unmatched
    • Nessusunmatched
    • Network Operations Centerunmatched
    • Network Securityunmatched
    • Operating Systemsunmatched
    • Operational Supportunmatched
    • Organizational Development/Managementunmatched
    • Organizational Skillsunmatched
    • Penetration Testingunmatched
    • Red Hat Linux Operating Systemunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Analysisunmatched
    • Security Consultingunmatched
    • Security Monitoringunmatched
    • Software Developmentunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Splunkunmatched
    • Status Reportsunmatched
    • Systems Engineeringunmatched
    • TCP (Transmission Control Protocol)unmatched
    • Technical Writingunmatched
    • Test Plan/Scheduleunmatched
    • Time Managementunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vulnerability Scannersunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder