Role Overview
As a Junior Cybersecurity Analyst, you will play a key role in evaluating client systems for compliance with FedRAMP and other federal security standards. Working remotely across the U.S., you will analyze cybersecurity documentation, gather evidence, and support security assessments aligned with FISMA, NIST Risk Management Framework, and Department of Defense requirements. Your work will directly contribute to strengthening the security posture of government-aligned cloud environments.
Key Responsibilities
- Conduct client interviews and collaborate directly to assess security needs and support compliance evaluations.
- Analyze system documentation, perform technical testing, and collect evidence to validate adherence to federal cybersecurity standards.
- Develop and maintain scripts in Python, PowerShell, or Bash to automate assessment workflows, reporting, and data collection processes.
- Perform vulnerability scans using tools such as Nessus, ACAS, SCC, and DISA STIGs, then interpret results for risk evaluation.
- Generate accurate, well-structured reports and documentation, integrating automated analysis where applicable.
- Work independently or as part of a distributed team, meeting deadlines in a fast-moving environment.
- Travel up to 25% may be required to support on-site client engagements when necessary.
Required Qualifications
- Strong verbal communication skills, with the ability to clearly convey technical concepts during client interactions.
- Fundamental understanding of cloud security, FedRAMP, FISMA, NIST RMF, and relevant NIST SP 800-series publications.
- Hands-on experience with scripting languages such as Python, PowerShell, or Bash to automate security tasks.
- Familiarity with vulnerability assessment tools including Nessus, ACAS, SCC, and DISA STIG Viewer.
- Excellent organizational skills, with close attention to detail and structured workflows.
- Self-driven mindset with a solid foundation in technical problem-solving.
- Must earn a FedRAMP-compliant industry certification (A2LA R311) within three months of starting.
- High School diploma and technical certification required; a Bachelor’s degree in Engineering, Information Systems, or a related field is mandatory.
- U.S. citizenship is required to meet government customer requirements for security clearance.
- Must have permanent authorization to work in the United States; sponsorship is not available for this role.
Preferred Qualifications
- At least one year of experience in FISMA-based Assessment and Authorization (A&A) activities.
- Proven experience writing and maintaining scripts for cybersecurity automation, such as compliance checks or scanning workflows.
- Technical proficiency with tools like Nessus, DB Protect, Acunetix, and ACAS in operational environments.
- Ability to identify, assess, and recommend mitigations for cybersecurity risks during formal evaluations.
- Background in security engineering, secure system architecture, network security, authentication protocols, cryptography, or application security.
Technical Environment
Proficiency with Nessus, ACAS, SCC, DISA STIGs, STIG Viewer, Python, PowerShell, and Bash is essential for success in this role.
Work Environment
This is a remote position open to candidates across the U.S., with up to 25% travel expected for client engagements. You will operate in a deadline-driven, independent setting while contributing to team-based security initiatives.

