Senior Security Analyst – ATO / RMF (Active TS/SCI Clearance) SBSSenior Security Analyst – ATO / RMF (Active TS/SCI Clearance)Chantilly, Virginia$140,000–$195,000 / yearLocation: Chantilly, VA Work Type: 100% Onsite – Secure Facility Employment Type: Full-Time Citizenship: U.S. Citizenship required Clearance: Active TS/SCI required; CI Polygraph preferred but not required Certification: Active Security+ or higher (IAT Level II/III) required . SBS developed ATOaaS in collaboration with leading technology companies and DoD/Intelligence Community customers to help accelerate the process of bringing innovative commercial technologies into secure government environments.
Technical Business Analyst (AWS focus) ActioNet IncTechnical Business Analyst (AWS focus)Washington, DC$90,000–$142,000 / yearActioNet is a CMMI-DEV Level 4, CMMI-SVC Level 4, ISO 20000, ISO 27001, ISO 9001, HDI-certified, woman-owned IT Solutions Provider with strong qualifications and expertise in Agile Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. This role bridges the gap between business stakeholders and technical teams by gathering requirements, facilitating discovery discussions, and translating business needs into clear, actionable technical documentation.
IT Risk & Controls Analyst TandymIT Risk & Controls AnalystVienna, Virginia$45 / hourFamiliarity with NIST Cybersecurity Framework and 800 Series, ISO 27001/27002, SANS/CIS, and PCI DSS. Plan and scope IT and Information Security control assessments, including communications, risk and control matrices, scope documents, and supporting materials.
Information Governance Compliance Analyst Ropes & GrayInformation Governance Compliance AnalystWashington, DC, Washington, DC$88,600–$135,100 / yearThe firm has approximately 2,500 lawyers and professionals serving clients in major centers of business, finance, technology, and government in Boston, Chicago, Dublin, Hong Kong, London, Los Angeles, Milan, New York, Paris, San Francisco, Seoul, Shanghai, Silicon Valley, Singapore, Tokyo and Washington, D.C. Assist in monitoring compliance with PHI and PII document storage requirements in the DMS and other approved firm repositories, maintaining user-facing documentation, supporting PHI and PII best practices training, and participating in routine audits to confirm sensitive data is not retained longer than necessary.
DPAE Aircraft Carriers Data Scientist/RMF Analyst CACI International IncDPAE Aircraft Carriers Data Scientist/RMF AnalystWashington, DC$86,600–$181,800 / yearIn this role, you will help strengthen the cybersecurity posture and technical resilience of the Navy's most advanced aircraft carrier platforms by performing data‑driven analysis, executing RMF activities, and ensuring compliance with DoD cybersecurity requirements. Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications.
Network Based System Analyst Node.DigitalNetwork Based System AnalystArlington, VANode provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis capabilities. IAT Level II, IASAE II, CSSP Analyst, GCIA, GCIH, CSSP Analyst/CSSP Incident Responder, CEH - SANS GIAC GNFA preferred.
Cyber Threat Analyst PeratonCyber Threat AnalystLinthicum, Maryland$146,000–$234,000 / yearFull timeLeverages scanning tools (i.e., VirusTotal) to conduct suspicious file scanning; performing queries, pivoting on indicators, and malware analysis on characteristics (Message-Digest Algorithm 5 (MD5), Secure Hash Algorithm 1 (SHA1), file size, file name, file paths, etc.). This Cyber Threat Analyst position supports the Federal Government and participates as a team member performing threat analyses based on knowledge of cybersecurity and concepts supporting intelligence analysis requirements for all-source cyber analysis and reporting.
New(Cyber) Incident Management Analyst - 2nd Shift Nightwing Intelligence Solutions(Cyber) Incident Management Analyst - 2nd ShiftSterling, Virginia$99,000–$206,000 / yearSkill in recognizing and categorizing types of vulnerabilities and associated attacks- Knowledge of basic system administration and operating system hardening techniques, Computer Network Defense policies, procedures, and regulations- Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code). - Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code).
Digital Network Exploitation Analyst (DNEA) BytoaDigital Network Exploitation Analyst (DNEA)Annapolis Junction, MarylandAnalyze SIGINT and cybersecurity data at multiple levels up and down the OSI network stack and bring a solid understanding of logical/physical IP core infrastructure, communication devices and how they connect to networks, and the traffic movements in a network. In addition, it may also include engineering hardware and/or software, programming, computer/network security, vulnerability analysis, penetration testing, computer forensics, information assurance, systems engineering, and/or network and systems administration.
New(Cyber) Incident Management Analyst - Weekend Day Shift Nightwing Intelligence Solutions(Cyber) Incident Management Analyst - Weekend Day ShiftSterling, Virginia$99,000–$206,000 / yearSkill in recognizing and categorizing types of vulnerabilities and associated attacks- Knowledge of basic system administration and operating system hardening techniques, Computer Network Defense policies, procedures, and regulations- Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code). Desired Skills: - Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code).
Systems Vulnerability Analyst 4 Markon SolutionsSystems Vulnerability Analyst 4fort meade, MD$195,000–$205,000 / yearWorking alongside Red, Blue, and Purple Teams, the Systems Vulnerability Analyst supports offensive and defensive cyber operations while helping implement security best practices and Zero Trust principles. Experience implementing or assessing Zero Trust architectures supporting Computer Network Exploitation (CNE), Computer Network Operations (CNO), network infrastructure, or system hardening.
New(Cyber) Incident Management Analyst - 1st Shift Nightwing Intelligence Solutions(Cyber) Incident Management Analyst - 1st ShiftSterling, Virginia$99,000–$206,000 / yearSkill in recognizing and categorizing types of vulnerabilities and associated attacks- Knowledge of basic system administration and operating system hardening techniques, Computer Network Defense policies, procedures, and regulations- Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code). Desired Skills: - Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code).
Mid Business Analyst (BA) - Integrated Data Architecture SCOUT SolutionsMid Business Analyst (BA) - Integrated Data ArchitectureArlington, VirginiaWHCA is the joint-service Department of Defense organization, aligned under the White House Military Office, that delivers secure voice, video, data, and audiovisual communications for the President, the Vice President, the White House staff, the United States Secret Service, and Presidential emissaries — at the White House, at Camp David, and anywhere in the world the mission travels. Demonstrated experience gathering, analyzing, documenting, and validating business and data requirements for complex enterprise systems, databases, applications, interfaces, data exchanges, data transformations, reporting solutions, or integrated data environments.
Cybersecurity Analyst - Cryptographic Modernization ApolisCybersecurity Analyst - Cryptographic ModernizationArlington, VA$65–$75 / hourKey Responsibilities Support cryptographic modernization efforts through cybersecurity risk analysis and vulnerability assessment activities. Location: Arlington, VA (Pentagon) - 4 days/week minimum; occasional 5-day onsite support may be required.
(Cyber) Incident Management Analyst - Hybrid Nightwing Intelligence Solutions(Cyber) Incident Management Analyst - HybridSterling, Virginia$99,000–$206,000 / yearSkill in recognizing and categorizing types of vulnerabilities and associated attacks- Knowledge of basic system administration and operating system hardening techniques, Computer Network Defense policies, procedures, and regulations- Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code). Desired Skills: - Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code).
New(Cyber) Incident Management Analyst - 3rd Shift Nightwing Intelligence Solutions(Cyber) Incident Management Analyst - 3rd ShiftSterling, Virginia$99,000–$206,000 / yearSkill in recognizing and categorizing types of vulnerabilities and associated attacks- Knowledge of basic system administration and operating system hardening techniques, Computer Network Defense policies, procedures, and regulations- Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code). - Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code).
Mid Business Analyst (BA) - Automated Workflows SCOUT SolutionsMid Business Analyst (BA) - Automated WorkflowsArlington, VirginiaThe Automated Workflows workstream takes the manual, paper-and-email processes the agency depends on and turns them into governed, auditable, automated workflows — equipment accountability, personnel and access actions, mission tasking, service requests, change and approval chains, and readiness reporting. WHCA is the joint-service Department of Defense organization, aligned under the White House Military Office, that delivers secure voice, video, data, and audiovisual communications for the President, the Vice President, the White House staff, the United States Secret Service, and Presidential emissaries — at the White House, at Camp David, and anywhere in the world the mission travels.
(Cyber) Incident Management Analyst - Weekend Night Shift Nightwing Intelligence Solutions(Cyber) Incident Management Analyst - Weekend Night ShiftSterling, Virginia$99,000–$206,000 / yearSkill in recognizing and categorizing types of vulnerabilities and associated attacks- Knowledge of basic system administration and operating system hardening techniques, Computer Network Defense policies, procedures, and regulations- Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code). Desired Skills: - Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])- Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code).
Principal Threat Surface Analyst - Remote or Hybrid in MN or DC UnitedHealth Group IncPrincipal Threat Surface Analyst - Remote or Hybrid in MN or DCWashington, DCRemote$112,700–$193,200 / yearThe fraudulent LinkedIn messages and emails, which do not originate from any Executives LinkedIn account or of UnitedHealth Group's email domains, or those of any of its operating divisions, supposedly conducts an interview via a Zoom meeting, offers a work from home job at Optum, emails an application, sends a fake check by next day delivery through USPS and asks recipients to pay a vendor a large dollar amount. Experience implementing and supporting enterprise endpoint platforms such as: Microsoft Defender for Endpoint, Trend Micro, CrowdStrike, SentinelOne, Carbon Black.
Security Analyst Core One SolutionsSecurity AnalystMclean, VA$150,000–$200,000 / yearExperience in the following tools: NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, Azure Sentinel, Nessus, ACAS, AWS GovCloud, Azure Government, GCP, SCAP, STIG Viewer. Final compensation is determined based on factors including, but not limited to, relevant experience, education, certifications, security clearance level, contract requirements, geographic location, and internal pay equity, and may reflect market data specific to the awarded contract.