Job Closed
This listing is no longer active.
Junior Security Analyst
Location
Virginia
Posted
114 days ago
Salary
0
Seniority
Junior
Job Description
Junior Security Analyst
ARETUM
• Execute vulnerability management activities using ACAS, ESS, SCAP tools, and manual validation techniques to confirm findings and reduce false positives. • Conduct application and web vulnerability assessments using tools such as Burp Suite and document results with clear remediation guidance. • Support vulnerability triage and prioritization based on mission impact, exposure, exploitability, and operational constraints. • Support the Vulnerability Disclosure Program (VDP) by managing intake, validation, tracking, and coordination with remediation stakeholders. • Ensure vulnerability findings, evidence, and remediation status are accurately documented and traceable within RMF artifacts (e.g., assessment inputs and POA&M updates). • Support SCAP/STIG-related validation by correlating scan results to configuration baseline requirements and documenting compliance status. • Demonstrate the ability to perform—or a strong willingness to learn—security assessment activities across ACAS, ESS, Burp Suite, VDP workflows, and SCAP/STIG compliance processes. • Cloud Security: Configure and manage AWS Security toolsets (CloudTrail, GuardDuty, Inspector, Security Hub). • Execute DISA STIG compliance activities across operating systems, applications, databases, and network devices • Validate security baselines using SCAP and manual assessment techniques • Identify deviations, document compensating controls, and support risk acceptance requests • Ensure configuration compliance aligns with mission requirements and operational constraints • Maintain and update RMF packages throughout the system lifecycle • Support ATO, IATT, and continuous monitoring activities • Track POA&Ms and remediation actions to completion • Coordinate with Government System Owners, ISSOs, ISSEs, and Authorizing Officials • Support cybersecurity assessments, inspections, and compliance reviews • Support SIEM monitoring and alert analysis • Assist with ESS deployment, configuration, and reporting • Support log analysis, threat detection, and incident response activities • Assist with continuous monitoring and cybersecurity metrics reporting
Job Requirements
- Master’s Degree or Bachelor’s Degree + 3 years of relevant experience
- 3–6 years of experience in information assurance, cybersecurity, or compliance-focused roles
- Active Top Secret Clearance Required
- Experience maintaining RMF packages in classified or regulated environments
- Working knowledge of NIST 800-series publications and DoD cybersecurity requirements
- Experience developing and maintaining SOPs, policies, or technical documentation
- Strong written and verbal communication skills
- Demonstrated willingness to learn new tools/techniques and support cross-functional cybersecurity activities as mission needs evolve
- Preferred Requirements**
- Extensive knowledge of AWS Security
- Experience supporting DoD or intelligence community customers
- Hands-on experience with eMASS or other GRC tools
- Familiarity with SIEM platforms, ESS/Trellix, Burp, Checkmarx, or other vulnerability management solutions
- DoD 8140 / 8570 certifications (e.g., Security+, CAP)
- Experience working in classified (SCIF) environments
Benefits
- Health Care Plan (Medical, Dental & Vision)
- Retirement Plan (401k)
- Life Insurance (Basic, Voluntary & AD&D)
- Paid Time Off
- Family Leave (Maternity, Paternity)
- Short Term & Long-Term Disability
- Training & Development
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
• Coordinate and execute recurring GRC tasks such as quarterly access reviews, audit evidence collection, and risk register reconciliation. • Document and track completion of control activities and escalate issues where needed. • Assist with internal and external audits, ensuring timely and complete evidence collection and review. • Collaborate with Sales, Legal, and Product teams to lead responses for customer security questionnaires and RFPs, progressively owning more complex requests as your experience deepens. • Maintain and continuously improve a centralized repository of commonly requested security documentation and artifacts (e.g., SOC 2, SIG, CAIQ). • Work closely with a broad array of business leaders to conduct initial and periodic vendor risk assessments, ensuring that third parties meet Rightway's security and compliance standards. • Track and follow up on remediation plans and risk treatment for vendors posing unacceptable risk. • Enable and support automation and optimization of the vendor risk assessment lifecycle using both AI and traditional tooling. • Support the implementation and operationalization of AI risk and governance controls in alignment with ISO/IEC 42001 (AI Management System) and emerging regulatory guidance e.g., CAIA (Colorado AI Act). • Monitor AI systems for compliance with ethical and legal standards.
• The Cybersecurity Analyst is responsible for the collection, analysis, validation, monitoring, and response to cybersecurity intelligence and events. • Perform day-to-day operational tasks by analyzing and responding to security events that have been logged and correlated by the SIEM or other security platform. • Monitor all in-place security solutions for efficient and appropriate operations. • Participate in investigation and resolution of anomalous activity. • Serve as a first responder and assist with initial investigations for potential security events. • Analyze configuration and vulnerability information to determine risk to the Bank’s data security. • Provide feedback on tuning of rules and alerts. Recommend tuning of rules that generate alerts to ensure low false positive rates.
• Perform analysis and management of information security risks, identifying vulnerabilities, assessing impacts, and proposing mitigation plans • Validate, review, and govern firewall rules, ensuring adherence to security policies, best practices, and compliance requirements • Work with the Security Operations Center (SOC) to define, validate, and continuously improve monitoring rules, event correlation, and security alerts • Evaluate and validate security incidents, supporting investigations, root cause analysis, and prevention recommendations • Ensure security processes and controls are aligned with ITSM frameworks, information security best practices, and service management • Prepare and maintain technical documentation, risk reports, incident reports, and security metrics • Collaborate with infrastructure, network, application, and governance teams to ensure the effectiveness of security controls • Support internal and external audits, ensuring compliance with security policies, standards, and certifications • Participate in the continuous improvement of cybersecurity processes, contributing to the maturity of the organization’s security posture
Senior Workday HRIS/Security Analyst
Advocate Aurora HealthAdvocate Aurora Health is one of the United States' largest not-for-profit, integrated healthcare systems, with more than 500 sites in Wisconsin and Illinois. In the past, Advocate
• Responsible for Workday Security for all HR modules • Participate in various HR projects to provide technical HR system support • Ensures security, end-user access, and data integrity across all HR platforms • Maintain Workday ticketing system • Help ensure data accuracy by validating security settings • Conduct regular audits of user access and security configurations




