Cyber Security Analyst II

Smiths GroupEdgewood, MD
$98,311 - $147,468

About The Position

The Cyber Security Analyst II is the senior technical practitioner on a small, high-impact security team supporting a Defense Industrial Base (DIB) environment handling controlled data. This role is the hands-on owner of our Microsoft security stack and the primary author of the policies, procedures, and evidence artifacts required to sustain our CMMC Level 2 posture under NIST SP 800-171. The analyst works directly with the Information & Cyber Security Manager to mature the program, own cross-functional processes, and mentor a junior analyst.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field OR equivalent combination of certifications and hands-on experience.
  • 3–5 years of hands-on Cyber security experience, at least 2 of which include direct administration of Microsoft 365 / Entra ID / Intune / Defender in a production environment.
  • Demonstrable experience authoring security policies and procedures.
  • Working knowledge of NIST SP 800-171 Rev. 2 and/or CMMC Level 2; understands control mapping, procedure development, and evidence production.
  • U.S. Citizenship required.
  • Strong written communication — will produce documents read by executives, auditors, and government customers.
  • Microsoft Defender suite (Endpoint, Office 365, Cloud Apps)
  • Entra ID
  • Intune
  • Purview
  • NIST SP 800-171 Rev. 2
  • CMMC Level 2
  • vulnerability management tools (Nessus or equivalent)
  • SIEM platforms, incident response

Nice To Haves

  • Prior experience in a DIB / defense contractor / cleared facility environment.
  • Experience with Microsoft GCC or GCC High tenants.
  • Experience with a SIEM (Sentinel, Splunk, Google SecOps/Chronicle, or similar) including log source onboarding and rule tuning.
  • Familiarity with DFARS 252.204-7012, ITAR, and the SPRS scoring process.
  • Microsoft certifications: SC-200, SC-300, SC-400, MS-500, AZ-500.
  • CMMC Registered Practitioner (RP) or Certified CMMC Professional (CCP).

Responsibilities

  • Shared ownership of day-to-day administration and tuning of Microsoft Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Entra ID (Conditional Access, PIM, Identity Protection), Intune (compliance policies, configuration profiles, update rings, app protection), and Purview (DLP, Insider Risk, Information Protection).
  • Draft, maintain, and operationalize written policies and procedures mapped to NIST SP 800-171 Rev. 2 and CMMC Level 2 practices. Translate control language into runbooks, checklists, and evidence artifacts that an assessor can verify.
  • Partner with HR, IT, and Facility Security to develop and improve the end-to-end joiner/mover/leaver process, quarterly access reviews, privileged access management, and onboarding/offboarding of authorized users.
  • Run the recurring vulnerability management cycle (Defender Vulnerability Management, Nessus, or equivalent): triage, prioritize, track SLAs, and report on remediation against a defined framework.
  • Act as tier-2 responder for Defender and Entra alerts; investigate, contain, and document incidents; lead post-incident reviews; maintain and exercise the incident response plan.
  • Collect and maintain evidence for internal self-assessments and customer audits. Maintain the System Security Plan (SSP) and POA&M alongside the Security Manager.
  • Execute and measure the monthly phishing simulation program and deliver targeted training for elevated-risk roles.
  • Provide technical direction and review for the Cyber Security Analyst I and serve as the escalation point for their work.
  • Other duties as assigned.

Benefits

  • Excellent training and opportunities for career growth
  • Inclusive environment
  • Strong leadership
  • Focus on safety and wellbeing
  • Flexibility to choose from a wide range of benefits
  • Medical, dental & vision insurance
  • 401(k) with company match
  • Paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service