Cybersecurity Analyst
$104,000–$120,000 year
On-site · Boston, Massachusetts, United States or Arlington, Virginia, United States
Job Summary
Cybersecurity Analyst to aid the Enterprise Cybersecurity Team with day-to-day security operations. Interfaces with internal/external stakeholders to identify and review software for use in a CMMC Level 2 environment and eventually Level 3; provides consulting on cybersecurity strategy, metrics, and compliance; supports development of CMMC assessment instructions; gathers evidence for audits; offers subject matter expertise on governance, standards, and processes; supports development and management of security policies to align with regulatory requirements; correlates threat information from multiple sources including user-reported incidents and security alerts; maintains current knowledge of DoD security guidelines and organizational policies; after-hours incident handling, maintenance, and patching; collaborates with cross-functional teams to drive security improvements within scope, time, and budget; required experience with Defender and Sentinel, Corelight Investigator, and security tooling; cloud security (AWS/Azure); strong analytical and communication skills; Bachelor’s degree and 2+ years in cybersecurity; certifications such as CISSP/CISM/OSCP/GIAC are a plus.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field (or equivalent experience)
- 2+ years of experience in cybersecurity, with a focus on architecture, strategy, or special projects
- Understanding of security frameworks (e.g., NIST, ISO 27001) and risk management methodologies
- Hands-on experience with security tools, vulnerability management, and incident response processes
- Experience with security architecture design, including cloud security platforms (AWS/Azure)
- Excellent written and verbal communication skills with the ability to present complex information to technical and non-technical stakeholders
- Preferred Certifications: CISSP, CISM, OSCP, or equivalent certifications; GIAC certifications (GCIH, GCFA, GCIA) and cloud security credentials (CCSP, AWS Security Specialty) a plus
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.