SPAHR SOLUTIONS GROUP LLC

Cybersecurity Protect Analyst

SPAHR SOLUTIONS GROUP LLC Fairfax County, Virginia, United States

IT Services and IT Consulting · 11-50 employees

4 h ago
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Cybersecurity Protect Analyst will act as a technical liaison for subscriber organizations to resolve complex security issues and manage vulnerability tracking. They are responsible for executing comprehensive vulnerability assessments, monitoring threat intelligence, and ensuring compliance with USCYBERCOM and JFHQ-DoDIN directives.

What they look for

Cybersecurity Vulnerability assessment ACAS Threat intelligence Compliance auditing Risk management Network security Endpoint security Malware defense Incident response Data governance Security posture validation CVE analysis Technical liaison Policy implementation

Requirements

The role requires expertise in cybersecurity frameworks, vulnerability scanning tools like ACAS, and the ability to conduct technical audits and evidence gathering. Candidates must be capable of coordinating with system owners to prioritize remediation and validate security postures against adversary tactics.

Benefits

401(k) Dental insurance Health insurance Paid time off Training & development Vision insurance Life insurance Short-term disability Long-term disability

Full description

Benefits:

  • 401(k)
  • Competitive salary
  • Dental insurance
  • Health insurance
  • Paid time off
  • Training & development
  • Vision insurance

We are seeking a Cybersecurity Protect Analyst to support our Defense Threat Reduction Agency (DTRA) Tier II Cybersecurity Services Provider (CSSP) Team. Spahr is a fast-growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well-planned information management environment. “Integrity. Purpose. Resolve” embodies our values and is paramount to both our and our customer’s success. By relentlessly upholding our values and investing in our employees we foster a culture of integrity and selfless service, build resilient teams that are ready to solve hard problems, and deliver real impact for the client.

We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. Visit us at https://www.spahrllc.com. Apply now to explore jobs with us!

The safety and health of our employees is of the utmost importance. By applying for a role at Spahr you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP".

Required Responsibilities:

·       Subscriber Engagement & Liaison: Act as the technical cybersecurity liaison for subscriber organizations, providing advanced, hands-on guidance for resolving complex security posture issues, patching delays, and system misconfigurations.

·       Data Element Dictionary (DED) Governance: Act as the primary auditor for the CSSP Data Element Dictionary (DED). Coordinate with data producers and data stewards to maintain canonical field mappings and machine-readable schemas. Oversee validation rules for identity-attributed, network, and object-access events to guarantee schema compliance across all DTRA subscriber tenants.

·       Vulnerability Tracking & KEV Management: Actively track and analyze CISA’s Known Exploited Vulnerabilities (KEV) catalog using standardized cybersecurity frameworks, including Common Vulnerabilities and Exposures (CVE) identifiers, National Vulnerability Database (NVD) resources, Common Vulnerability Scoring System (CVSS) severity vectors, and Common Weakness Enumeration (CWE) classifications, to evaluate localized risks, prioritize mitigation efforts, and coordinate rapid remediation with system owners.

·       Vulnerability Assessment & Analysis (VAA): Execute comprehensive vulnerability assessments using the Assured Compliance Assessment Solution (ACAS) and other enterprise scanning tools, analyzing raw scan data to deliver actionable, prioritized remediation steps to stakeholders.

·       Cyber Threat Intelligence (CTI) Integration: Monitor, evaluate, and digest cyber threat intelligence feeds, indicator of compromise (IOC) alerts, and open-source threat reports to anticipate emerging vectors and proactively adjust defensive postures.

·       ESM & Compliance Support: Support CSSP Evaluator Scoring Metric (ESM) compliance assessments, gathering technical evidence, conducting internal control reviews, and maintaining organizational readiness for JFHQ-DoDIN mandated evaluations.

·       Blue Team & Posture Validation: Coordinate and conduct "Blue Team" assessments under Government supervision to evaluate subscriber security postures for DoW compliance, while validating detection playbooks and signature effectiveness by emulating adversary tactics to trigger alerts and detect Red Team activities.

·       Endpoint & Malware Defense Validation: Perform technical validation of endpoint security tools, host-based security systems, and boundary defense mechanisms to ensure malware protection policies are active, correctly configured, and reporting to central CSSP consoles.

·       Directive Implementation: Track, implement, and technically validate compliance with USCYBERCOM TASKORDs, Cyber Protection Condition (CPCON) shifts, and JFHQ-DoDIN operational directives.

·       Audit Readiness & Evidence Gathering: Lead compliance focused working groups with subscriber IT teams. Guide them through gathering technical evidence, conducting internal control reviews, and ensuring total readiness for rigorous DoW and agency-level cybersecurity audits (e.g., CORA, CSSP evaluations).

Similar roles