IT Security Analyst

IT Security Analyst

22 Mar 2025
Virginia, Virginiabeach, 23453 Virginiabeach USA

IT Security Analyst

Description Key Responsibilities:Vulnerability Management:

Perform routine vulnerability scans and assessments using industry-standard tools to identify and prioritize security risks across systems and networks.

Develop remediation strategies and work with IT stakeholders to address security vulnerabilities promptly.

Maintain a comprehensive record of vulnerabilities, including mitigation efforts, to track progress and establish compliance with organizational policies and standards.

Active Directory Security:

Manage and maintain Active Directory (AD), ensuring secure administration and enforcement of security policies across the environment.

Monitor and audit AD activity to detect potential misuse, privilege escalation, or unauthorized access.

Harden AD configurations to mitigate risks, including patching vulnerabilities, minimizing attack surfaces, and optimizing security strategies.

Incident Response:

Lead investigations into security incidents and events, including identifying root causes, assessing impact, and providing detailed reports to leadership.

Develop and execute incident response playbooks and workflows to ensure swift and effective handling of cybersecurity incidents.

Conduct post-incident analyses to identify lessons learned and recommend improvements to processes and tools.

Security Monitoring and Reporting:

Continuously monitor security tools and solutions to identify potential threats, unusual activity, or signs of intrusion.

Create timely and accurate security reports, highlighting findings from vulnerability scans, audits, and incidents.

Provide actionable insights and recommendations for strengthening security controls.

Collaborative Efforts & Training:

Work collaboratively with IT, engineering, and leadership teams to implement security measures that reduce vulnerabilities without disrupting workflows.

Provide training and guidance to employees and teams to foster a culture of cybersecurity awareness and best practices.

Requirements

Required Skills and Qualifications:

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field.

3+ years of experience in IT security, vulnerability management, Active Directory administration, or incident response.

Proficiency with vulnerability scanning tools such as Nessus, Qualys, Rapid7, or similar.

Strong understanding of Active Directory security best practices and protocols.

Hands-on experience with incident response processes, forensic analysis tools, and SIEM solutions (e.g., Splunk, LogRhythm).

Industry certifications (e.g., CISSP, Security+, CEH, GIAC) are highly desirable.

Preferred Skills:

Expertise in cloud security solutions and technologies such as AWS or Azure.

Knowledge of regulatory compliance frameworks, such as GDPR, PCI DSS, or HIPAA.

Technology Doesn't Change the World, People Do.®

Robert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app (https://www.roberthalf.com/us/en/mobile-app) and get 1-tap apply, notifications of AI-matched jobs, and much more.All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information.© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking “Apply Now,” you’re agreeing to Robert Half’s Terms of Use (https://www.roberthalf.com/us/en/terms) .

Related jobs

  • Req ID: RQ195997

  • Title: SECURITY CONTROL ASSESSOR (SCA) Location: United States-Virginia-Virginia Beach Job Number: 250000T5 Job Summary: The Security Control Assessor SCA oversees NEXCOM NAF IT cybersecurity risk assessment process which determines aggregate cybersecurity risk in support of an Authorization. Duties and Responsibilities: Incumbents of this position must be U.S. Citizens. Responsibilities include: - Provides NEXCOM cybersecurity support, by performing full package analysis of all IT systems, as defined by the Navy Risk Management Framework (RMF) guide. - Assists in the development of risk assessment requirements and participates in the execution of RMF assessment processes for authorization of systems to the Navy Exchange enterprise network to include ensuring that system hardware and software adheres to security standards that minimize risk to the Navy Exchange enterprise from cyber security threats based on the POA&M and other supporting documentation. - Participates in the development and maintenance of Navy Exchange cyber defense architectures, processes, standards, specifications, cyber threat profiles and enterprise risk assessments. - Independently and impartially assess and quantify aggregate cybersecurity risk using metrics consistent with DON guidance for both inherent system residual risks and system accessibility related risks in support of the Risk Management Program (RMP). - Produce the risk determination using the security assessment plan (SAP) and make a recommendation regarding system authorization. - Provides review and analysis of FedRAMP, PCI, and other third party package authorizations for reciprocity and use within the NEXCOM organization. - Provide initial concurrence on the SAP, ensuring all appropriate security controls will be assessed for compliance. - Support NEXCOM’s NAF IT continuous monitoring requirements. Determines and documents compliance with the assigned security controls. - Actively work with the Cybersecurity Compliance Assessor and Validator, and program management office to provide support and guidance throughout the RMF cybersecurity assessment and lifecycle. - Represent the system during DoD and DON Cybersecurity inspections, while responding to information requests and addressing identified findings. - Provides RMF/RMP Subject Matter Expert (SME) guidance. Provide guidance on the following: o Understanding of the RMF/RMP risk assessment process o Knowledge of implementation and applicability of security controls o Use of appropriate test procedures and tools and mitigation measures o Understanding of policies and their effects on the risk of a system. o Review and assessment of individual vulnerabilities in the POA&M - Keeps supervisors up to date on all assignments. - Performs other related duties as assigned. SECNAV M-5239.2, DoN, Information Assurance (IA) Workforce Manual requires incumbents of this position to possess and maintain current, two types of certifications as follows: IA Certification: Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), CompTIA Advanced Security Practitioner (CASP ), GIAC Security Leadership Certification (GSLC) Technical Certification: Operating System/Computing Environment (OS/CE) certificate of training as dictated by Supervisor and approved by Command Cyber IT/CSWF-PM. Candidate is also required to sign a Privileged Access Agreement. Candidates without the required certification may be placed into this job but must obtain the required certification within 6 months of appointment; failure to obtain this requirement will result in termination of employment. Qualifications: A total of 8 years of experience, consisting of the following: Qualified candidates must be U.S. Citizens. GENERAL EXPERIENCE: 3 years’ experience in security, technical or investigative work which demonstrated the ability and aptitudes required to perform technical, managerial or analytical work involving management information systems. OR SUBSTITUTION OF EXPERIENCE FOR EDUCATION: One year of related academic study above the high school level may be substituted for 9 months of experience up to a maximum of a 4 year bachelor\'s degree in IT security or computer information systems for 3 years of general experience. AND SPECIALIZED EXPERIENCE: 5 years of demonstrated experience in at least two of the following: - Risk management validation - IT security compliance and reporting; - Technical risk analysis; - Authorization and accreditation And experience in the performance of: - System Security Assurance: ensuring that entire systems meet security requirements, function securely, and undergo comprehensive testing for overall security assurance. - Security Assessments: conducting security assessments and developing Security Assessment Plans (SAPs). - Technical Understanding: interpreting network diagrams, vulnerability scans, and compliance scans. - Security Documentation: creating and maintaining various security documents, including Security Assessment Plans. - Risk Management Framework: conducting security control assessments following a Risk Management Framework approach, along with conducting risk assessments and developing security assessment reports. And in-depth knowledge of: - NIST 800-53, risk mitigation strategies for computer operating systems, networks, or cloud services, and security controls and compliance frameworks. This position is designated in accordance with SECNAV M-5510.30 and will require a favorable Single Scope Background Investigation (SSBI). Candidates must be eligible for and obtain a Top Secret Clearance, within 6 months of appointment. Failure to obtain will result in termination. Job: Infrastructure

  • Allied Universal®, North America’s leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels a culture that will reflect in our communities and customers we serve. We offer medical, dental and vision coverage, life insurance, retirement plan, employee assistance programs, company discounts, perks and more for most full-time positions!

  • Allied Universal®, North America’s leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels a culture that will reflect in our communities and customers we serve. We offer medical, dental and vision coverage, life insurance, retirement plan, employee assistance programs, company discounts, perks and more for most full-time positions!

Job Details

Jocancy Online Job Portal by jobSearchi.