Find Jobs
Find Jobs Near You – Available Work in Your Location
Cybersecurity Analyst II
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Maryland data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$121,766 / year median in Maryland
+3% projected growth
Job Description
The ideal candidate brings experience in cybersecurity testing and evaluation, vulnerability management, system hardening, and DoD security compliance, with exposure to Infrastructure as Code (IaC) and security automation. This individual will also provide technical vulnerability and configuration data to support Mission-Based Cyber Risk Assessments (MBCRAs) and broader risk-based cybersecurity decisions.
Key Responsibilities
Description of Duties:
The Cybersecurity Analyst is responsible for the planning, implementation, and assessment of security controls to ensure the confidentiality, integrity, and availability of information systems across on-premises, cloud, and hybrid environments. Under general supervision, the Analyst shall:- Performs cybersecurity testing and evaluation, including vulnerability assessments using DoD-approved tools (e.g., ACAS), and validates system configurations against DISA STIGs and SRGs
- Implements and automates security configurations for operating systems, network devices, and cloud resources in accordance with Infrastructure as Code (IaC) best practices
- Supports Mission-Based Cyber Risk Assessments (MBCRAs) by providing technical data on vulnerabilities and system configurations
- Develops and maintains RMF authorization package artifacts in the Enterprise Mission Assurance Support Service (eMASS)
- Active TS/SCI clearance
- Bachelor's degree and 3 years of relevant experience
- Or High School Diploma and 7 years of relevant experience
- IAM Level II (CGRC, CASP+, CISM, or equivalent)
Benefits
- Dental Insurance