Search

Cybersecurity Analyst I-II

PublishedPublished: 6/14/2022
Technology

Job Description

Job DescriptionDescription:

About Us

Aspis strives to make enterprise cybersecurity solutions and professional services accessible to organizations of all sizes, from small and medium-sized businesses to large enterprises, nonprofits, and municipal, state, and federal government agencies. Aspis is a HUBZone-certified small business. Our values are Integrity, Community, and Diversity. https://aspis.consulting


Job Description

Aspis is hiring a Cybersecurity Analyst (Level I or Level II, depending on your experience) to perform cybersecurity engineering work as a subcontractor supporting a federal civilian agency's application development and modernization portfolio. You will be the security voice in the software release process — analyzing changes before they deploy, running and interpreting the scans, telling developers plainly what has to be fixed and why, and writing the analyses and recommendations that leadership uses to make decisions.


This is hands-on engineering work with a heavy documentation component. If you like finding the problem but dislike writing it up, this is not the role. If you can do both — and can explain a vulnerability to a program manager in plain language — you will do well here.


You do not need years of experience to be considered. We have filled this position successfully with someone who arrived with a Security+ certification, real aptitude, and no professional experience at all. If that describes you, apply — we will train you, pair you with senior review, and support your next certification. If you already have two to five years behind you, you will come in at Level II and carry the documentation deliverables sooner.


This position is based in the U.S. Virgin Islands and is performed remotely from your home. See the residency requirement below before applying; it is a firm condition of this posting.


Levels and Pay

· Level I (0–2 years): $24.00 – $27.00 per hour. CompTIA Security+ required. Work is assigned with clear direction and reviewed before client delivery. Expect structured mentoring and employer-supported progress toward an intermediate certification.

· Level II (2–5 years): $27.00 – $29.95 per hour. Security+ required and progress toward an intermediate certification such as CySA+, GIAC, or a cloud security credential. Carries analyses and written deliverables with light review.

Level is determined at offer based on experience, certifications, and a practical exercise. Advancement from Level I to Level II is based on demonstrated capability, not tenure alone.


Application security analysis and vulnerability management

· Perform Security Impact Analysis and vulnerability assessment before deployment to identify potential security issues, and recommend mitigations.

· Run scheduled and ad hoc dynamic and static software vulnerability scans using approved tools as part of the application release process, and interpret the results.

· Help developers and system owners interpret application vulnerability findings and modify applications to remediate them.

· Help automate software vulnerability scanning processes.

· Document and continuously improve the processes behind vulnerability scanning, Security Impact Analysis, and vulnerability assessment.


Security standards, architecture, and documentation

· Develop and document security standards — code scanning, security impact analysis, cloud implementation, and similar — and produce documented architectural security analyses and requirements for applications in development or modernization.

· Prepare briefing decks, risk analyses, white papers, waiver requests, and Analyses of Alternatives, written in plain language wherever possible. Each Analysis of Alternatives must set out the pros and cons of every technology considered.

· Support application design so that the resulting application is secure by construction.

· Evaluate enterprise architecture development activities for secure practices and make recommendations across architectural domains.

· Contribute to code standards, waivers, SDLC models, reviews, and processes.


Assessment, research, and program support

· Assess emerging technologies for how securely they can be integrated into the client's environments.

· Perform root analysis of existing systems and technologies to identify opportunities for consolidation or modernization.

· Produce trend analysis reports and support the risk analysis and threat analysis processes.

· Monitor NIST publications and assist with implementing new policy as it is issued.

· Assist with change control processes for agency security requirements.

· Coordinate the setup, deployment, and maintenance of security-specific tools.

· Research and recommend actions for technical solutions.


What Success Looks Like

This work is performed under contractual performance criteria. Deliverables are expected to be substantially free of errors, initial inquiries answered within two business days, and status communicated within two business days of completion. You will also record your time accurately in a web-based timekeeping system every day you work — on a labor-hour contract, timekeeping accuracy is a compliance obligation, not an administrative nicety.

Requirements:

Residency Requirement — Please Read Before Applying

This position is designated to support Aspis' certification under the U.S. Small Business Administration's HUBZone program. Under 13 C.F.R. § 126.200, a certified HUBZone small business must maintain at least 35 percent of its employees as HUBZone residents. The entire territory of the U.S. Virgin Islands is a qualified HUBZone.


As a condition of employment, the successful candidate must reside in the U.S. Virgin Islands at the time of hire and must maintain continuous residency in the U.S. Virgin Islands for as long as they hold this position. Applicants and employees will be asked to provide documentation of residency; SBA accepts a Virgin Islands driver's license or non-driver identification card as primary evidence, and where that is unavailable may accept a lease, deed, or utility bill (13 C.F.R. §§ 126.103, 126.200, 126.304). A change of residence outside the U.S. Virgin Islands may result in reassignment or separation, because the position would no longer serve the purpose for which it was created.


Residency in the U.S. Virgin Islands is a bona fide requirement of this position, applied uniformly to every applicant for the position, and is not based on race, color, religion, sex, national origin, citizenship status, age, disability, veteran status, or any other characteristic protected by federal or Virgin Islands law. Applicants of any national origin who reside in the U.S. Virgin Islands and are legally authorized to work in the United States are encouraged to apply. Residents of St. Thomas, St. Croix, St. John, and Water Island are all eligible.


This residency requirement applies to this posting only. It is a condition of this position's designation and is not a general requirement of the Cybersecurity Analyst role at Aspis.


Where and How You Will Work

Work is performed remotely from your home in the U.S. Virgin Islands. Aspis provides the laptop and software; you provide reliable internet and a workspace suitable for calls and focused analysis.


Please note: under the governing contract, the client retains the right to direct that specific activities be performed in the Kansas City, Missouri or Washington, D.C. metropolitan areas. Occasional approved travel may therefore be required. Approved non-local travel is reimbursed in accordance with federal travel regulations and company policy.


Aspis will reimburse hourly hot-desk passes at SEAT Caribbean in Charlotte Amalie, St. Thomas, or Accelerate VI Coworking in Christiansted, St. Croix, when a power or internet outage prevents work from home, with prior approval.


Qualifications

· Zero to five years of relevant cybersecurity experience. Level I (0–2 years) and Level II (2–5 years) are both open under this posting.

· Associate's degree or higher in Cybersecurity, Information Technology, or a related field preferred; equivalent experience and certifications considered in lieu of a degree.

· CompTIA Security+ or equivalent is required at both levels. Level II candidates should additionally be working toward an intermediate certification such as CySA+, GIAC, or a cloud security credential. Aspis funds certification progression.

· Level II: hands-on experience running vulnerability scans and interpreting results, with familiarity with static and dynamic application security testing (SAST/DAST) tooling. Level I: exposure through coursework, labs, a home lab, or certification study is sufficient — we will train you on our tooling.

· Familiarity with NIST SP 800-53, the NIST Cybersecurity Framework, and the Risk Management Framework, appropriate to level. At Level I, Security+ coverage of these topics is an acceptable starting point.

· Understanding of the software development life cycle and where security fits into it.

· Demonstrated ability to write clearly. You will produce security impact analyses, white papers, waiver requests, and Analyses of Alternatives. At Level I these are drafted under senior review; a writing sample or a well-organized lab write-up counts.

· Ability to explain technical findings clearly to non-technical stakeholders.

· Aptitude and coachability. At Level I these matter more to us than a resume: we are looking for someone who takes direction well, asks good questions, and improves fast.

· Ability to manage multiple assignments and deadlines, with oversight appropriate to level.

· Discretion in handling sensitive client, system, and company information.

· Ability to obtain and maintain a Public Trust background investigation and any required federal personal identity verification credential.

· Legally authorized to work in the United States without sponsorship.

· Residency in the U.S. Virgin Islands, maintained throughout employment (see above).

Nice to have: scripting or automation experience (Python, PowerShell, or shell) for scan automation; cloud security experience in AWS or Azure; experience supporting federal agency security programs; exposure to enterprise architecture review; certifications such as CySA+, CCSP, or CISSP Associate.


Requirements

· Position: Cybersecurity Analyst, Level I or Level II.

· Pay: $24.00 – $29.95 per hour depending on level, experience, and certifications.

· Benefits: Full-time employees are benefits eligible and bonus/award eligible.

· FLSA: Non-exempt. Hours are recorded daily in a web-based timekeeping system.

· Location: Work from home in the U.S. Virgin Islands. USVI residency required and must be maintained. Occasional client-directed activity in the Kansas City or Washington, D.C. metropolitan areas is possible.

· Equipment: Government-provided laptop and software.

· Workspace Support: Reimbursed hourly hot-desk passes at SEAT Caribbean (St. Thomas) or Accelerate VI Coworking (St. Croix) during power or internet outages, with prior approval.

· Background Check: Public Trust background investigation required. Position is subject to federal personal identity verification requirements and to a drug-free workplace policy.

· Degree Required: Associate's degree or higher preferred; equivalent experience and/or certifications considered.

· Experience Required: 0–5 years. Level I (0–2 years) and Level II (2–5 years) are both open under this posting.

· Industry Certifications: CompTIA Security+ or equivalent required at both levels. Progress toward an intermediate certification expected at Level II and supported at Level I.

· Training: Structured onboarding, senior review of deliverables, and employer-funded certification progression.

· Must pass reference check and background check.


We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veteran status, or any other characteristic protected by law. We will consider for employment qualified applicants with criminal histories consistent with applicable law.

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...