Hiring.Camp

Cybersecurity Analyst/ISSO

Spectrumcontrol

·

Today

Salary
$85k – $120k
Location
Marlborough, United States of America
Type
Full-time
Department
IT
Education
Bachelor
Clearance
Required
Source
Workday

Description

At Spectrum Control, most departments operate on a 4-day, 10-hour work schedule in exchange for a 3-day weekend. We offer competitive wages and PTO, plus our benefits begin on day 1 of employment. Come join a workforce where we put you first!

POSITION SUMMARY: The Cybersecurity Analyst II/ISSO protects enterprise systems, networks, and data by monitoring for threats, investigating security events, and managing vulnerability remediation. This role also owns a significant share of the security program's documentation and enablement work — authoring incident response playbooks, maintaining the security knowledgebase, and running the company's cybersecurity awareness training and newsletter. The analyst operates with limited supervision on routine work, escalates complex incidents to senior staff, and mentors Analyst I team members.

COMPENSATION RANGE: The expected compensation range for this position is $85,000 - $120,000 annually.

KEY RESPONSIBILITIES:

Threat Detection & Monitoring (~20%)

  • Monitor SIEM, EDR, email security, and network security tooling for indicators of compromise
  • Triage and investigate security alerts; determine scope, severity, and false-positive status
  • Tune detection rules to reduce alert noise and recommend new detection logic
  • Conduct basic threat hunting using threat intelligence feeds and indicators of compromise
  • Review and validate escalations from Analyst I staff

Incident Response & Playbook Development (~20%)

  • Serve as a first- and second-tier responder for security incidents
  • Author, test, and maintain incident response playbooks for recurring incident types including phishing, ransomware, account compromise, data exfiltration, insider risk, and production system events
  • Partner with senior security staff, IT, and business owners to validate playbook steps and escalation paths
  • Contain and remediate endpoint and account compromises
  • Document incident timelines, root cause, and lessons learned
  • Feed post-incident findings back into playbooks and detection logic
  • Participate in an on-call rotation and facilitate tabletop exercises

Vulnerability Management (~20%)

  • Run and interpret vulnerability scans across servers, endpoints, network devices, and cloud workloads
  • Prioritize findings by exploitability and business impact
  • Drive remediation with IT and application owners and escalate blocked items
  • Track remediation SLAs and report on aging and recurring findings
  • Validate patching and configuration hardening against CIS and vendor baselines

Information System Security Officer (ISSO) (20%)

  • Support implementation and execution of NIST Risk Management Framework (RMF)
  • Develop, maintain, and review system security documentation including: System security plans (SSPs), Hardware/software baselines, Configuration diagrams, and RMF policies
  • Perform continuous monitoring of system configurations, user accounts, privileged access, and audit logs
  • Track, assess, and patch system vulnerabilities and findings using vulnerability managers and STIGS
  • Ensure changes to system hardware, software, architecture, and configurations are evaluated for cybersecurity impact
  • Assess system compliance with NIST 800-53 Rev5 security controls, organizational policies, and contractual (DD254) requirements

Documentation & Knowledge Ownership (~10%)

  • Own the cybersecurity knowledgebase — create, review, and retire articles covering security processes, tool usage, request workflows, and troubleshooting guidance
  • Ensure documented processes are accurate, versioned, discoverable, and written for the intended audience
  • Establish and enforce a review cadence so articles do not go stale
  • Translate undocumented tribal knowledge into repeatable written process
  • Coach Analyst I staff on documentation standards

Security Awareness Training & Communications (~10%)

  • Own the enterprise cybersecurity awareness training program including curriculum selection, module assignment, tracking, and completion reporting
  • Create and publish the recurring cybersecurity newsletter, translating current threats and internal trends into practical guidance for a non-technical audience
  • Design and run phishing simulation campaigns; analyze results and target follow-up training
  • Deliver targeted training for high-risk roles and support onboarding security orientation
  • Support compliance evidence collection, access reviews, and internal and external audits

REQUIRED QUALIFICATIONS:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience
  • 2–5 years of hands-on experience in security operations, vulnerability management, or IT infrastructure
  • Working knowledge of SIEM platforms, EDR tooling, and vulnerability scanners
  • Solid understanding of TCP/IP networking, DNS, firewalls, VPN, and proxy concepts
  • Familiarity with Windows and Linux administration and Active Directory / Entra ID
  • Understanding of common attack techniques and the MITRE ATT&CK framework
  • Demonstrated strong technical writing ability — able to produce clear playbooks, procedures, and end-user-facing content
  • Comfort presenting and communicating security concepts to non-technical audiences
  • Must be able to obtain SECRET clearance

PREFERRED QUALIFICATIONS:

  • Experience in a DoD or defense manufacturing environment supporting CMMC / NIST 800-171 compliance requirements
  • Certifications such as Security+, CySA+, GCIH, GSEC, GCIA, SSCP, or an associate-level Azure or AWS security certification
  • Scripting experience (PowerShell, Python, KQL) for automation and log analysis
  • Cloud security experience with Azure, AWS, or the Microsoft 365 security stack
  • Experience administering a security awareness platform such as KnowBe4, Proofpoint, or Hoxhunt
  • Experience maintaining documentation in a knowledgebase or ITSM platform such as ServiceNow, Confluence, SharePoint, or Jira
  • Exposure to NIST CSF, ISO 27001, CIS Controls, or export-control-adjacent environments
  • Experience with SOAR and security automation workflows

CORE COMPETENCIES:

  • Analytical rigor and attention to detail under time pressure
  • Bias toward documenting and systematizing rather than re-solving the same problem
  • Sound judgment on when to escalate versus resolve independently
  • Collaborative; works effectively with infrastructure, application, manufacturing, and business teams
  • Continuous learner who tracks the evolving threat landscape
  • Able to teach and mentor less experienced analysts

WORKING CONDITIONS:

  • Occasional after-hours work for incident response, patching, and maintenance windows
  • On-site role based at Spectrum Control’s manufacturing facility in Marlborough, MA
  • U.S. person status is required

CAREER PATH

Progression to Cybersecurity Analyst III typically requires demonstrated incident command capability, ownership of a security domain or platform end to end, measurable program improvement, and an advanced certification or equivalent depth.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities


The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35(c)
 

Third-Party Recruiters

Please note, that per Spectrum Control Policy, we do not accept unsolicited resumes from third-party recruiters unless such recruiters are engaged to provide candidates for a specified opening and in alignment with our values and expectations. Any employment agency, person or entity that submits an unsolicited resume does so with the understanding that Spectrum Control will have the right to hire that applicant at its discretion without any fee owed to the submitting employment agency, person or entity. If you or your agency are interested in becoming an approved vendor please contact [email protected]

Skills

PythonAWSAzureLinuxJiraConfluenceServiceNowCybersecuritySIEMTCP/IPRisk ManagementComplianceTechnical WritingISO 27001

Similar Jobs

3

Cybersecurity Analyst / ISSO

Spry Methods · Stafford, VA · Hybrid

4 weeks ago

Cybersecurity Analyst / Information Systems Security Officer (ISSO)

KBR Careers · USA, Peterson AFB, 250 Vandenburg St, Colorado, United States of America

4 weeks ago

Cybersecurity Analyst / Information Systems Security Officer (ISSO)

Accelint · San Diego, CA

2 months ago