Roper logo
Roper

Local News, Global Context.

Cybersecurity Analyst II

Location

Florida

Posted

2 days ago

Salary

0

Seniority

Senior

Job Description

Cybersecurity Analyst II

Roper

• Own and maintain key elements of the corporate security program, including identity governance, security policy, and security posture reviews. • Conduct access reviews and support least-privilege access management across corporate systems and SaaS applications. • Manage and maintain endpoint security standards and device security baselines. • Coordinate with third-party security service providers regarding detections, investigations, and response activities. • Develop, maintain, and communicate corporate security policies, standards, and acceptable use requirements. • Serve as a security resource for corporate employees seeking guidance on cybersecurity matters. • Support security awareness initiatives and employee education efforts. • Conduct periodic reviews of SaaS applications, cloud environments, and overall corporate security posture. • Support vendor security reviews and assessments. • Track and report security metrics, risks, and program status to leadership. • Assist in developing governance standards and acceptable use requirements for AI tools. • Evaluate security, privacy, and compliance considerations associated with emerging AI platforms. • Maintain working knowledge of cloud security principles across AWS, Microsoft Azure, and Google Cloud Platform (GCP).

Job Requirements

  • Minimum of 3 years of hands-on cybersecurity experience.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience.
  • Experience in cybersecurity operations, governance, cloud security, identity security, or related disciplines.
  • Understanding of identity and access management, SaaS security, and modern security practices.
  • Strong written, verbal, and interpersonal communication skills.
  • Ability to work independently and manage multiple priorities.
  • Strong analytical and problem-solving skills.

Benefits

  • Health insurance
  • Paid time off
  • Flexible work arrangements
  • Professional development opportunities

Related Job Pages

More Security Analyst Jobs

Valid logo

SOC Engineering Analyst N1 – Senior

Valid

Valid, a evolução da confiança.

Full TimeRemoteTeam 5,001-10,000Since 1957H1B Sponsor

• Monitor security events in real time using SIEM, XDR, and other industry-standard security tools. • Perform advanced alert triage, distinguishing false positives from real incidents. • Correlate events from multiple sources (network, endpoint, identity, cloud). • Execute operational playbooks for initial response. • Escalate relevant incidents to higher tiers (N2) with structured context. • Contribute to rule tuning and continuous improvement of detection quality. • Document evidence, analyses, and classifications in incident management tools.

Brazil
Valid logo

SOC Engineering Analyst N2 – Senior

Valid

Valid, a evolução da confiança.

Full TimeRemoteTeam 5,001-10,000Since 1957H1B Sponsor

• Conduct end-to-end technical investigations of security incidents. • Execute response actions (containment, eradication, and recovery). • Perform forensic analysis on endpoints and network events (intermediate/advanced level). • Develop and refine incident response playbooks. • Conduct proactive threat hunting based on hypotheses and threat intelligence. • Prepare technical and executive incident reports. • Collaborate with infrastructure, cloud, and identity teams. • Develop and execute threat hunting strategies based on TTPs. • Create and optimize use cases and detection rules. • Integrate and analyze threat intelligence feeds. • Support complex investigations and critical incidents. • Develop dashboards, advanced queries, and behavioral analyses. • Participate in Red/Purple Team exercises. • Support the technological evolution of the SOC.

Brazil
CEA logo

Analista de Arquitetura Sênior – Segurança da Informação

CEA

CEA is the exclusive distributor of JCB, Atlas Copco, Ditch Witch, & Dynapac equipment.

Full TimeRemoteTeam 201-500Since 1981H1B Sponsor

• Elaborar diagramas técnicos, documentos de arquitetura e modelos de ameaça • Analisar arquiteturas de sistemas, aplicações e integrações sob a ótica de segurança • Realizar análises de risco técnico e recomendar controles de segurança • Atuar no desenho de soluções seguras para cloud, aplicações e infraestrutura • Apoiar times de desenvolvimento, infraestrutura e DevOps na implementação de controles • Avaliar configurações de segurança (hardening, baseline, CIS Benchmarks) • Apoiar processos de auditoria, compliance e gestão de vulnerabilidades • Efetuar modelagem de ameaças, análise de risco e sugestões de sistemas internos e fornecedores • Conhecimento avançado em OWASP Top 10, CWE, NIST e padrões de segurança • Conhecimento em code reviews com foco em segurança para apoiar times de desenvolvimento na correção de vulnerabilidades • Desenvolver scripts e automações para análise e mitigação de vulnerabilidades

Brazil
Noblis logo

Information System Security Compliance Analyst

Noblis

An independent nonprofit organization, Noblis provides U.S. federal government clients with science, technology, and engineering services to solve challenging p

Role Description We are seeking a detail-oriented cybersecurity compliance professional to support system authorization and continuous monitoring activities within a Federal environment. This role is responsible for managing the security authorization lifecycle for one or more information systems, ensuring compliance with Federal cybersecurity requirements, and maintaining the documentation necessary to support Authorization to Operate (ATO) decisions. The ideal candidate will have experience working with NIST RMF, NIST SP 800-53 controls, security authorization packages, POA&M management, and compliance documentation. Candidates should be comfortable working with technical teams to assess control implementation, identify compliance gaps, and provide guidance to support remediation efforts and POA&M closure. Key Responsibilities - Manage the security authorization lifecycle for one or more information systems in accordance with Federal Risk Management Framework (RMF) requirements. - Coordinate activities required to obtain and maintain Authorization to Operate (ATO) approvals. - Assess and track implementation of NIST SP 800-53 security controls and associated compliance requirements. - Develop, review, update, and maintain authorization package documentation, including: - System Security Plans (SSPs) - Security Assessment Reports (SARs) - Plan of Action and Milestones (POA&Ms) - Risk Assessments - Continuous Monitoring documentation - Security-related policies and procedures - Manage POA&M activities by tracking findings, monitoring remediation progress, validating corrective actions, and supporting closure efforts. - Provide technical guidance and compliance recommendations to system owners, engineers, administrators, and security stakeholders to facilitate POA&M remediation and closure. - Coordinate with technical teams to gather evidence supporting security control implementation and compliance requirements. - Review vulnerability scan results, assessment findings, and security documentation to identify compliance gaps and areas requiring remediation. - Support continuous monitoring activities by tracking security posture, compliance status, and ongoing control effectiveness. - Participate in security assessments, audits, and compliance reviews conducted by internal and external stakeholders. - Assist in the development of risk mitigation strategies and recommendations for addressing identified security weaknesses. - Track authorization milestones, compliance deadlines, and remediation activities to ensure timely completion. - Communicate compliance status, risks, findings, and recommendations to both technical and non-technical stakeholders. - Support audits and reporting activities related to Federal cybersecurity requirements and organizational security programs. Qualifications - Experience supporting cybersecurity compliance, security authorization, risk management, or information security programs. - Experience working with the NIST Risk Management Framework (RMF). - Subject matter expertise with NIST SP 800-53 security controls and Federal cybersecurity compliance requirements. - Experience supporting the development, maintenance, or review of authorization package documentation, including SSPs, SARs, POA&Ms, and Risk Assessments. - Understanding of the Authorization to Operate (ATO) process and continuous monitoring requirements. - Experience tracking and managing POA&M findings through remediation and closure. - Ability to review technical security information and translate findings into compliance documentation and actionable recommendations. - Understanding of cybersecurity principles, security controls, vulnerability management, and risk management concepts. - Strong organizational skills with the ability to manage multiple systems, priorities, and compliance activities simultaneously. - Strong written and verbal communication skills, including the ability to develop and review formal security documentation. - Proficiency with Microsoft Office applications, particularly Excel, Word, and PowerPoint. - U.S. Citizen or Green Card Permanent Resident with a minimum of three (3) years of U.S. residency. - Ability to obtain and maintain an FAA Public Trust. Education & Experience Substitutions - Mid to senior: Bachelor’s degree in Cybersecurity, Information Technology, Telecommunications, or a related field with 9+ years of experience in cybersecurity or network security roles. - Substitutions: A High School degree with a total of 15 years of experience in cybersecurity or network security roles; a Master's degree with a total of 6 years of experience in cybersecurity or network security roles. - Senior: Bachelor’s degree in Cybersecurity, Information Technology, Telecommunications, or a related field with 16+ years of experience in cybersecurity or network security roles. - Substitutions: A High School degree with a total of 20 years of experience in cybersecurity or network security roles; an Associate's Degree with a total of 18 years of experience in cybersecurity or network security roles; a Master's degree with a total of 13 years of experience in cybersecurity or network security roles. Desired Qualifications - Experience supporting federal government programs, preferably within the FAA, Department of Transportation, or other civilian federal agencies. - FAA or transportation sector experience preferred. - Experience serving as an Information System Security Officer (ISSO), Security Control Assessor (SCA), Information System Security Manager (ISSM), or similar cybersecurity compliance role. - Experience managing authorization packages for multiple systems simultaneously. - Strong knowledge of NIST SP 800-53 Rev. 5, NIST RMF, FISMA, and related Federal cybersecurity requirements. - Experience developing, reviewing, and maintaining SSPs, SARs, POA&Ms, Risk Assessments, Contingency Plans, and other authorization artifacts. - Experience conducting control assessments, compliance reviews, and security documentation audits. - Ability to interpret technical findings from vulnerability scans, configuration assessments, and security reviews to support risk-based decision-making. - Experience providing technical guidance to engineering and operations teams to support corrective actions and POA&M closure. - Familiarity with continuous monitoring programs and ongoing authorization requirements. - Experience working with vulnerability management tools, compliance dashboards, and governance, risk, and compliance (GRC) platforms. - Knowledge of cloud security compliance, Zero Trust Architecture, and modern Federal cybersecurity initiatives. - Industry certifications such as: - CISSP - CAP (Certified Authorization Professional) - Security+ - CISM - GSLC - CGRC - or equivalent certifications - Strong written, verbal, analytical, and interpersonal communication skills, with the ability to interact effectively with technical teams, auditors, system owners, and government stakeholders. Compensation Ranges - For D.C., NJ, Remote: $78,900 - $123,300 - Senior: For D.C., NJ, Remote: $95,500 - $180,525

United States
$78.9K - $180.5K / year