Haystack
← Back to Jobs
Technology
TH

Security Analyst

The HLBUnited States🇺🇸United StatesPosted Oct 5, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
Yesterday

Job Description

PLEASE READ FULL JOB DISCRIPTION AND ENSURE YOU MEET THE REQUIRMENTS.

Job Title: Security Analyst
Location: Remote
Division: DMAC; NIOSH


Position Overview

The Security Analyst plays a critical role in protecting organizational systems, data, and operations through proactive threat identification, risk mitigation, and continuous security monitoring. This role supports compliance across federal and industry standards while enabling secure, resilient technology environments. The analyst will design and enhance security processes, drive incident response activities, and collaborate with engineering, compliance, and leadership teams to strengthen overall security posture. Candidates must demonstrate strong analytical expertise, technical acumen, and the ability to translate complex security risks into actionable guidance.

What You’ll Do

  • Perform system hardening, vulnerability assessments, STIG remediation, and POA&M tracking across Windows, Linux, and cloud environments.
  • Monitor security tools (e.g., endpoint protection, IAM/PAM platforms), troubleshoot issues, and validate remediation efforts with system owners and engineers.
  • Lead or support incident response activities, documenting findings, coordinating stakeholders, and improving response processes over time.
  • Conduct risk assessments, threat modeling, compliance reviews, and security audits aligned with regulatory frameworks.
  • Develop and maintain security governance artifacts, including policies, standards, operational guides, business continuity materials, and SA&A documentation.
  • Provide actionable recommendations for improving security posture, reducing attack surface, and enhancing detection and response capabilities.
  • Collaborate with cross-functional teams to ensure secure configuration management, least‑privilege access control, system authorization, and alignment with organizational mission and strategy.

Basic Qualifications

  • 5+ years of experience with cybersecurity operations, vulnerability management, and risk mitigation in regulated environments
  • Experience with network, server, database and/or application scanning tools such as Nessus, AppScan, Fortify, Web Inspect, or Squirrel 
  • Experience translating of vulnerability scan results into findings aligned to NIST SP 800-53 security controls
  • Possession of strong written communication skills for producing security reports, policies, and audit documentation
  • Possession of an Active CDC badge/credentials
  • Ability to perform system security assessments, SA&A processes, POA&M management, and compliance documentation.
  • Ability to analyze complex technical issues, communicate risk clearly, and develop actionable mitigation strategies
  • Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements
  • Bachelor’s degree

Nice If You Have: 

  • 3+ years of experience with supporting federal FISMA requirements, preferred 
  • Experience analyzing information system configurations and technical specifications against security control standards and identify deficiencies and remediation strategies 
  • Experience with AI/ML security applications such as anomaly detection, automated assessments, or AI‑driven threat intelligence
  • Experience contributing to AI governance, responsible‑AI practices, bias mitigation, or privacy‑preserving techniques
  • Experience mentoring junior analysts or supporting leadership in security strategy and operation design
  • Experience with enterprise data systems, large-scale modernization initiatives, or federal digital transformation programs
  • Possession of active HHS badge/credentials
  • Knowledge of DevSecOps workflows, container security, and cloud security architecture
  • 8500-compliant certification (CISSP Certification preferred) 

Similar jobs