Sr Cyber Sec Analyst

senior
OtherAnalyst
1 views0 saves0 applied

Quick Summary

Overview

Description Integrating cybersecurity requirements and security controls into the software development lifecycle, from requirements definition through deployment and sustainment Reviewing system,

Technical Tools
OtherAnalyst
  • Integrating cybersecurity requirements and security controls into the software development lifecycle, from requirements definition through deployment and sustainment
  • Reviewing system, application, interface, and architecture designs for cybersecurity risks and compliance with applicable government requirements
  • Supporting implementation and maintenance of secure DevSecOps practices, including automated security testing and continuous monitoring
  • Conducting or supporting security assessments, control validation, risk analysis, and remediation tracking for software applications and supporting infrastructure
  • Analyzing vulnerability scan results, application security findings, code-scanning results, and configuration-compliance data; validate findings and coordinate mitigation actions
  • Performing Risk Management Framework (RMF) activities, including preparation and maintenance of security documentation, assessment artifacts, risk registers, and plans of action and milestones (POA&Ms)
  • Evaluating security impacts of software releases, configuration changes, third-party components, and architecture modifications
  • Collaborating with developers to implement secure coding practices and remediate security defects
  • Supporting security incident analysis, root-cause analysis, corrective-action development, and after-action reporting
  • Developing technical reports, executive summaries, risk briefings, security recommendations, and status updates for program and government stakeholders
  • Providing technical mentorship and quality review for junior cybersecurity analysts
  • Participating in Agile ceremonies, technical interchange meetings, architecture reviews, release-readiness reviews, and cybersecurity working groups

#LI-LL1

Requirements

~2 min read
  • Active TS/SCI clearance with the ability to maintain eligibility throughout employment
  • Active CISSP certification in good standing
  • Bachelor’s degree in cybersecurity, computer science, information systems, software engineering, engineering, or a related technical field
  • Eight or more years of progressive experience in cybersecurity, information assurance, application security, systems security engineering, or a related technical discipline
  • Three or more years of experience supporting cybersecurity activities on software development, software modernization, systems integration, or DevSecOps programs
  • Demonstrated experience applying cybersecurity principles within the SDLC, including requirements analysis, design review, development, testing, deployment, and sustainment
  • Experience with security-control assessment, risk analysis, vulnerability management, and remediation tracking
  • Working knowledge of NIST cybersecurity guidance and risk-management practices, including:
    • NIST Risk Management Framework (RMF)
    • NIST Special Publication 800-53 security and privacy controls
    • NIST Special Publication 800-37 risk-management guidance
    • NIST Special Publication 800-218 Secure Software Development Framework (SSDF)
  • Experience reviewing or analyzing findings from vulnerability-scanning, configuration-compliance, web application security, static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), or similar tools
  • Familiarity with secure coding concepts, common application vulnerabilities, and remediation approaches, including OWASP risks
  • Experience producing cybersecurity documentation, such as security assessment reports, system security plans, risk registers, POA&Ms, vulnerability-management reports, and briefing materials
  • Experience obtaining system authorization, performing continuous monitoring, obtaining Authority to Operate (ATO) packages, and performing control-assessment activities
  • Ability to communicate cybersecurity risks and recommendations effectively to software developers, engineers, program managers, and government stakeholders
  • Ability to work independently, manage competing priorities, and operate effectively in a mission-focused government program environment
  • No travel is required for this position
  • Master’s degree in cybersecurity, computer science, software engineering, systems engineering, or a related technical discipline
  • Ten or more years of cybersecurity, information assurance, application security, or systems security engineering experience
  • Five or more years supporting government software-development, enterprise IT, cloud, intelligence, defense, or national-security programs
  • Experience supporting Agile, Scrum, Scaled Agile Framework (SAFe), DevSecOps, continuous integration/continuous delivery (CI/CD), or automated release-management environments
  • Experience integrating security tools into CI/CD pipelines, including SAST, DAST, SCA, infrastructure-as-code scanning, container scanning, secrets detection, or dependency management
  • Experience with software-development and DevSecOps platforms, such as GitLab, GitHub,  Jira, Bitbucket, or comparable tools
  • Experience securing containerized or orchestrated environments, including Docker, Kubernetes, OpenShift, or similar platforms
  • Familiarity with Zero Trust architecture, identity and access management, privileged-access management, encryption, key management, endpoint security, network segmentation, and API security
  • Experience serving as an Information System Security Officer (ISSO), Information System Security Manager (ISSM), security control assessor, security engineer, application security analyst, or comparable position
  • Additional relevant certifications, such as:
    • Certified Cloud Security Professional (CCSP)
    • Certified Information Security Manager (CISM)
    • GIAC Web Application Penetration Tester (GWAPT)
    • GIAC Cloud Security Automation (GCSA)
    • AWS Certified Security – Specialty
    • Microsoft Certified: Azure Security Engineer Associate
    • Security+ or CASP+
  • Experience developing scripts or automation using Python, PowerShell, Bash, or similar languages
  • Experience conducting threat modeling, architecture risk assessments, secure code reviews, penetration-test coordination, or security test planning
  • Demonstrated experience leading cybersecurity workstreams, mentoring analysts, and briefing senior government or contractor leadership

Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.

 

SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment.

All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.

 

Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact jobs@scires.com for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.

Location & Eligibility

Where is the job
—
Location terms not specified

Listing Details

Posted
October 8, 2026
First seen
October 8, 2026
Last seen
October 8, 2026

Posting Health

Days active
-1
Repost count
0
Trust Level
55%
Scored at
October 8, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Sr Cyber Sec Analyst