Job Requirements
Tyndall AFB, FL
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
$100,000 - $150,000
Job Description
Cybersecurity Monitoring & Reporting Analyst
Location: 2580 E HWY 98, Tyndal AFB, FL 32403 (On-Site) M-F
Employment Type: Full Time/Perm
Clearance: Must have a current and active Secret clearance
Relocation: Candidates willing to relocate within 2-4 weeks from offer will be considered.
Shifts Available: 11:00 PM – 9:00 AM (overnight shift; 2:00 PM – 12:00 AM (Midnight)
Position Summary
The Cybersecurity Monitoring & Reporting Analyst is responsible for monitoring, assessing, and reporting the cybersecurity posture of a large-scale Department of Defense enterprise environment. This role supports continuous cyber operations by identifying vulnerabilities, monitoring security events, analyzing enterprise security data, and ensuring compliance with DoD cybersecurity policies, Risk Management Framework (RMF), and regulatory requirements.
Working within a mission-critical environment, the analyst leverages enterprise cybersecurity tools—including ACAS, Tenable Security Center, Trellix ePO/ESS, Microsoft Defender for Endpoint (MDE), SIEM platforms, and centralized logging solutions—to detect threats, assess organizational risk, validate remediation efforts, and provide actionable reporting to technical teams and government leadership. The position also supports incident response, vulnerability management, compliance reporting, and continuous monitoring activities that strengthen the security and resiliency of Air Force information systems.
The ideal candidate possesses hands-on experience with enterprise vulnerability management, cybersecurity monitoring, RMF processes, security event correlation, and DoD security tools, along with a strong understanding of both host-based and network-based security technologies.
Required Qualifications
• Active DoD Secret Security Clearance
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related discipline.
• Minimum five (5) years of experience supporting Department of Defense enterprise cybersecurity operations, vulnerability management, security monitoring, and reporting.
• DoD 8570/8140 IAT Level III Certification (CASP+, CISSP, or equivalent).
• Experience supporting Risk Management Framework (RMF) processes and cybersecurity compliance.
• Experience producing cybersecurity reports, vulnerability assessments, compliance metrics, and executive reporting.
• Strong understanding of enterprise security architecture, endpoint security, network security, and incident response.
Key Responsibilities
Enterprise Monitoring & Reporting
• Monitor enterprise cybersecurity posture using ACAS, Tenable Security Center, Trellix ePO, Microsoft Defender for Endpoint, SIEM platforms, and enterprise logging solutions.
• Analyze enterprise security events using centralized logging and correlation platforms including ELK Stack, SYSLOG, SIEM, and ELICSAR.
• Produce recurring cybersecurity metrics, dashboards, executive reports, and vulnerability trend analysis.
• Monitor enterprise compliance status and verify remediation of cybersecurity findings.
• Track Zero-Day vulnerabilities, CVEs, IAVMs, and emerging threats.
• Prioritize remediation activities based on organizational risk.
• Develop operational reporting supporting cybersecurity leadership and RMF requirements.
Vulnerability Management
• Perform enterprise vulnerability assessments using ACAS, Nessus, Nessus Agents, Nessus Network Monitor, and related tools.
• Differentiate vulnerability findings from policy compliance findings.
• Validate remediation activities and verify closure.
• Identify false positives and work with system owners to resolve findings.
• Support continuous vulnerability management processes.
• Assist with security baseline reviews and configuration compliance assessments.
RMF & Compliance
• Support RMF lifecycle activities using eMASS.
• Assist with maintaining Authorization to Operate (ATO) documentation.
• Support cybersecurity inspections and audits.
• Monitor compliance with:
o NIST 800-53
o DISA STIGs
o Security Technical Implementation Guides
o DoD Cybersecurity policies
• Prepare compliance documentation and reporting for government leadership.
Security Operations
• Monitor enterprise IDS, IPS, firewalls, routers, switches, and endpoint security solutions.
• Correlate host-based and network-based security events.
• Analyze network traffic and SYSLOG events to identify Indicators of Compromise (IOCs).
• Support implementation of defensive cyber operations.
• Participate in threat hunting and security investigations.
• Assist with deployment and maintenance of enterprise cybersecurity tools.
Incident Response
• Perform incident detection, triage, containment, eradication, and recovery activities.
• Investigate security alerts and perform root cause analysis.
• Collect digital evidence.
• Document incident timelines and remediation activities.
• Coordinate with government cyber organizations and external incident response teams.
• Develop incident reports and lessons learned.
Technical Knowledge
Candidates should possess working knowledge of some combination of:
• Risk Management Framework (RMF)
• eMASS
• Vulnerability Management
• Compliance Assessments
• ACAS
• Tenable Security Center
• Nessus
• Nessus Agents
• Nessus Network Monitor
• Trellix ePO
• ESS / HBSS
• Microsoft Defender for Endpoint
• ELK Stack
• ELICSAR
• SYSLOG
• SIEM platforms
• Log aggregation and correlation
• IDS / IPS
• Firewalls
• Routers
• Switches
• NIDS / NIPS
• Host-Based Security
• Network Security
• Port Scanning
• Traceroute
• Active vs. Passive Vulnerability Scanning
• Compliance vs. Vulnerability Assessments
• Incident Response
• Threat Hunting
• IOC Analysis
• CVEs
• IAVMs
• Zero-Day Vulnerabilities
Location: 2580 E HWY 98, Tyndal AFB, FL 32403 (On-Site) M-F
Employment Type: Full Time/Perm
Clearance: Must have a current and active Secret clearance
Relocation: Candidates willing to relocate within 2-4 weeks from offer will be considered.
Shifts Available: 11:00 PM – 9:00 AM (overnight shift; 2:00 PM – 12:00 AM (Midnight)
Position Summary
The Cybersecurity Monitoring & Reporting Analyst is responsible for monitoring, assessing, and reporting the cybersecurity posture of a large-scale Department of Defense enterprise environment. This role supports continuous cyber operations by identifying vulnerabilities, monitoring security events, analyzing enterprise security data, and ensuring compliance with DoD cybersecurity policies, Risk Management Framework (RMF), and regulatory requirements.
Working within a mission-critical environment, the analyst leverages enterprise cybersecurity tools—including ACAS, Tenable Security Center, Trellix ePO/ESS, Microsoft Defender for Endpoint (MDE), SIEM platforms, and centralized logging solutions—to detect threats, assess organizational risk, validate remediation efforts, and provide actionable reporting to technical teams and government leadership. The position also supports incident response, vulnerability management, compliance reporting, and continuous monitoring activities that strengthen the security and resiliency of Air Force information systems.
The ideal candidate possesses hands-on experience with enterprise vulnerability management, cybersecurity monitoring, RMF processes, security event correlation, and DoD security tools, along with a strong understanding of both host-based and network-based security technologies.
Required Qualifications
• Active DoD Secret Security Clearance
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related discipline.
• Minimum five (5) years of experience supporting Department of Defense enterprise cybersecurity operations, vulnerability management, security monitoring, and reporting.
• DoD 8570/8140 IAT Level III Certification (CASP+, CISSP, or equivalent).
• Experience supporting Risk Management Framework (RMF) processes and cybersecurity compliance.
• Experience producing cybersecurity reports, vulnerability assessments, compliance metrics, and executive reporting.
• Strong understanding of enterprise security architecture, endpoint security, network security, and incident response.
Key Responsibilities
Enterprise Monitoring & Reporting
• Monitor enterprise cybersecurity posture using ACAS, Tenable Security Center, Trellix ePO, Microsoft Defender for Endpoint, SIEM platforms, and enterprise logging solutions.
• Analyze enterprise security events using centralized logging and correlation platforms including ELK Stack, SYSLOG, SIEM, and ELICSAR.
• Produce recurring cybersecurity metrics, dashboards, executive reports, and vulnerability trend analysis.
• Monitor enterprise compliance status and verify remediation of cybersecurity findings.
• Track Zero-Day vulnerabilities, CVEs, IAVMs, and emerging threats.
• Prioritize remediation activities based on organizational risk.
• Develop operational reporting supporting cybersecurity leadership and RMF requirements.
Vulnerability Management
• Perform enterprise vulnerability assessments using ACAS, Nessus, Nessus Agents, Nessus Network Monitor, and related tools.
• Differentiate vulnerability findings from policy compliance findings.
• Validate remediation activities and verify closure.
• Identify false positives and work with system owners to resolve findings.
• Support continuous vulnerability management processes.
• Assist with security baseline reviews and configuration compliance assessments.
RMF & Compliance
• Support RMF lifecycle activities using eMASS.
• Assist with maintaining Authorization to Operate (ATO) documentation.
• Support cybersecurity inspections and audits.
• Monitor compliance with:
o NIST 800-53
o DISA STIGs
o Security Technical Implementation Guides
o DoD Cybersecurity policies
• Prepare compliance documentation and reporting for government leadership.
Security Operations
• Monitor enterprise IDS, IPS, firewalls, routers, switches, and endpoint security solutions.
• Correlate host-based and network-based security events.
• Analyze network traffic and SYSLOG events to identify Indicators of Compromise (IOCs).
• Support implementation of defensive cyber operations.
• Participate in threat hunting and security investigations.
• Assist with deployment and maintenance of enterprise cybersecurity tools.
Incident Response
• Perform incident detection, triage, containment, eradication, and recovery activities.
• Investigate security alerts and perform root cause analysis.
• Collect digital evidence.
• Document incident timelines and remediation activities.
• Coordinate with government cyber organizations and external incident response teams.
• Develop incident reports and lessons learned.
Technical Knowledge
Candidates should possess working knowledge of some combination of:
• Risk Management Framework (RMF)
• eMASS
• Vulnerability Management
• Compliance Assessments
• ACAS
• Tenable Security Center
• Nessus
• Nessus Agents
• Nessus Network Monitor
• Trellix ePO
• ESS / HBSS
• Microsoft Defender for Endpoint
• ELK Stack
• ELICSAR
• SYSLOG
• SIEM platforms
• Log aggregation and correlation
• IDS / IPS
• Firewalls
• Routers
• Switches
• NIDS / NIPS
• Host-Based Security
• Network Security
• Port Scanning
• Traceroute
• Active vs. Passive Vulnerability Scanning
• Compliance vs. Vulnerability Assessments
• Incident Response
• Threat Hunting
• IOC Analysis
• CVEs
• IAVMs
• Zero-Day Vulnerabilities
group id: 91141814