Cybersecurity Analyst - Senior

Remote, USA Full-time
Company OverviewBy LightProfessional IT Services LLC readies warfighters and federal agencies with technology and systems engineered to connect, protect, and prepare individuals and teams for whatever comes next. Headquartered in McLean, VA, By Light supports defense, civilian, and commercial IT customers worldwide. Position OverviewBy Light is seeking personnel to provide comprehensive support for the Defense Contract Management Agency (DCMA) Facilities Management team in the implementation and sustainment of a Computer-Aided Facility Management (CAFM) software solution.This engagement, titled "DCMA CAFM SaaS Support Services," encompasses a base year plus four option years (September 30, 2025 - September 29, 2030), and will facilitate the optimization of facility operations across DCMA's nationwide and overseas portfolio, totaling over 1.3 million square feet. By Light will deliver a FedRAMP-approved, Impact Level 4 SaaS solution and a full spectrum of professional services, including system implementation, software development, system administration, help desk customer support, virtual and on-site training, and ongoing cybersecurity management.The CAFM system is required to streamline space planning, asset and lease tracking, capital and building operations management, and reporting, while enabling seamless integration with Autodesk and compliance with all applicable DoD cybersecurity and accessibility standards. Responsibilities• Lead the implementation, management, and continuous monitoring of cybersecurity controls for the DCMA Computer-Aided Facility Management (CAFM) SaaS system, ensuring full compliance with FedRAMP Moderate, DoD RMF, and NIST 800-53 standards.• Conduct ongoing vulnerability assessments, risk analyses, and security audits of cloud and on-premises components, identifying weaknesses and formulating mitigation strategies. • Develop and maintain cybersecurity documentation including System Security Plans (SSPs), policies, procedures, Plan of Action & Milestones (POA&Ms), and incident response plans. • Support the development, submission, and maintenance of Authority to Operate (ATO) packages in alignment with DCMA, DoD, and federal requirements.• Coordinate and conduct security testing (e.g., penetration tests, vulnerability scanning, compliance checks) using industry-standard tools and methodologies, documenting results and remediation actions. • Collaborate with DevSecOps, software development, and system administration teams to ensure secure design and implementation of all technical solutions and integrations. • Manage user access controls, account provisioning, and privileged access in compliance with least privilege and zero trust principles.• Lead incident response efforts, performing security event investigation, analysis, and reporting; coordinate with government stakeholders to report incidents in line with contractual requirements. • Monitor threat intelligence feeds, emerging vulnerabilities, and cyber risk advisories; provide recommendations to enhance system defenses. • Conduct security awareness training and ensure user compliance with established security standards, policies, and procedures. Required Experience/Qualifications• Bachelor's Degree in Cybersecurity, Information Assurance, Computer Science, Information Systems, or a related technical field.• Minimum 7 years' experience in cybersecurity analysis, with at least 3 years supporting FedRAMP, DoD RMF, or NIST 800-53 compliant environments. • Proven expertise in vulnerability management, incident response, risk assessment, and compliance monitoring within cloud-based SaaS or federal IT environments. • Direct experience supporting system assessment and authorization (ATO) processes, including development and maintenance of RMF artifacts. • Strong knowledge of secure architecture principles, security incident management, and cloud security best practices.• Familiarity with security tools such as Splunk, Tenable, Nessus, McAfee, or similar platforms. Preferred Experience/Qualifications• Master's Degree in Cybersecurity, Information Assurance, or a related discipline. • Experience supporting DCMA, DoD, or other federal CAFM, asset management, or facilities management SaaS solutions. • In-depth knowledge of Authority to Operate (ATO) and FISMA/FedRAMP accreditation processes. • Experience with Security Technical Implementation Guides (STIGs), continuous monitoring, and penetration testing in federal environments.• Relevant industry certifications, such as:• Certified Information Systems SecurityProfessional (CISSP)• Certified Information Security Manager (CISM)• Certified Cloud SecurityProfessional (CCSP)• CompTIA Security+• CASP+• GIAC Security Essentials (GSEC) or comparable• Experience with Section 508, ITIL Foundation, or risk management certifications. • Background in providing security awareness and training and working within Agile or DevSecOps environments. Special Requirements/Security Clearance• U.S.citizenship required. Apply tot his job
Apply Now

Similar Jobs

Information Assurance Specialist - Mid Level

Remote, USA Full-time

SUPERVISORY QUALITY ASSURANCE SPECIALIST with Security Clearance

Remote, USA Full-time

Cybersecurity - Information System Security Manager (ISSM)

Remote, USA Full-time

SECURITY SPECIALIST- GS 12, Washington Field Office - Northern Virginia Resident Agency (FBI Employees Only)

Remote, USA Full-time

EHS Technologies – Systems Administrator (IAVM Patch Manager and Vulnerability Specialist) – Philadelphia, PA

Remote, USA Full-time

Information Assurance & Security Specialist – Journeyman

Remote, USA Full-time

Security GRC Specialist, Audit & Assurance (R13698)

Remote, USA Full-time

[Remote] RCI-GRD-872-1 Cyber Security Analyst (Cloud Prisma Tenable) EST REMOTE

Remote, USA Full-time

Cyber System Engineer

Remote, USA Full-time

Security Assurance Analyst

Remote, USA Full-time

Top 50 CPA Firm

Remote, USA Full-time

Liquidity Support Trader (Market Making)

Remote, USA Full-time

Senior Medical Claims Review Analyst/Clinical Supervisor - Complex Claim Unit

Remote, USA Full-time

Work from Home- Training and Sales (code 291)

Remote, USA Full-time

Logistics Analyst

Remote, USA Full-time

Customer Service Representative(Remote, Part time, Full time)

Remote, USA Full-time

Junior Editorial Writer Intern - Pop Culture & Lifestyle

Remote, USA Full-time

Southwest Airlines Remote From Home No Experience $30/Hour – Work From Home Job – US

Remote, USA Full-time

Senior Professional Strategic Sourcing job at bolthires in US National

Remote, USA Full-time

SQL ETL SNOWFLAKE/SNOWPARK Developer, Remote To Start in USA

Remote, USA Full-time
Back to Home