Cybersecurity Analyst | San Diego, CA

CaVU ConsultingSan Diego, CA
$130,000 - $160,000Onsite

About The Position

CaVU is seeking a Cybersecurity Analyst to coordinate all cybersecurity activities to support Assessment and Authorization (A&A) Package documentation planning and development. The role involves preparing, developing, and maintaining Risk Management Framework (RMF) artifacts, packages, and deliverables for system validation and authorization to operate (ATO). The analyst will perform risk and vulnerability assessments, coordinate cybersecurity operations with program technical leads, and maintain RMF documents for systems with ATO. This position requires independent work, problem-solving, clear communication to both technical and non-technical audiences, and leadership in client task accomplishment. The role also includes developing and delivering cybersecurity update presentations to stakeholders, analyzing NIST controls, and assessing system impacts.

Requirements

  • Minimum of four (4) years of experience in a Cybersecurity, Engineering, Test and Evaluation (T&E) or A&A related field.
  • Experience working with Information Assurance tools such as DISA Enterprise Mission Assurance Support Service (eMASS), Assured Compliance Assessment Solution (ACAS), as well as the specific LCAT experience requirements the candidate is proposed under.
  • TS/SCI with no Foreign Exception Package (FEP) requirements
  • Bachelor degree from an accredited university in a technical or managerial related discipline
  • 4+ years experience working with the Information Technology (IT) systems for a DoD or government agency
  • 3+ years experience leading Navy RMF projects, including A&A activities for up-to TS/SCI systems, and the preparation, direct development, and maintenance of RMF artifacts, packages, and deliverables
  • 3+ years Implementing security controls and policies, performing cybersecurity compliance testing using industry standard tools, and performing vulnerability analysis and remediation of networks, systems, and communications protocols
  • Experience with eMASS, including Security Plan development and hands-on processing of packages through workflows, assisting with generating security policies, evaluating assessment documentation, and developing written security risks, mitigations, and recommendations
  • Experience with operating systems, platforms, and technologies, including Windows, Linux, virtualization, or containers
  • Experience with architecture visualization, and developing and maintaining system artifacts, including Boundary Diagrams and Data Flow Diagrams
  • Must be a self-starter and be able to independently execute tasking with excellent verbal and written communication skills
  • Ability to devise and execute client deliverables, work independently, identify problems and devise analysis and solutions, communicate results to both technical and non-technical audiences, and lead the accomplishments of client tasks from inception to completion
  • DoD 8140 qualified to include relevant education, training, and certification(s) – equivalent to the former DoD 8570 IAT II at a minimum

Nice To Haves

  • Experience with DoD Security Technical Implementation Guides (STIG) and Evaluate-STIG and tools such as Assured Compliance Assessment Solution (ACAS)
  • Experience integrating security into DevSecOps pipelines
  • Experience implementing automation methodologies and processes
  • Experience deploying, implementing, maintaining, and integrating cybersecurity tools and applications in alignment with the current threat landscape, and analyzing risks and opportunities at both tactical and strategic levels
  • Experience with network engineering functions, including Windows, Linux, and virtual operating systems, security tools, platforms, and technologies, including network and web application firewalls, web proxy, intrusion prevention systems, vulnerability scanners, and penetration tools
  • Experience with developing and maintaining cyber schedule, performance, and quality metrics within the systems development lifecycle and acquisition lifecycle
  • Experience with Navy initiatives and PMW 160 systems (e.g., Consolidated Afloat Network Enterprise Systems (CANES), Platform Application Services (PAS), Agile Core Services (ACS), Automated Digital Network System (ADNS))
  • Master’s degree in an Engineering, Computer Science, or equivalent technical discipline
  • Operating System (OS) Certification(s) e.g., Windows, RedHat, Linux
  • Familiarity with OCF Platforms is desired for one of the positions

Responsibilities

  • Prepare, develop, and maintain Risk Management Framework (RMF) artifacts, packages, and deliverables to support system validation and authorization to operate (ATO)
  • Perform risk and vulnerability assessments in network, system, and application areas
  • Coordinate day-to-day cybersecurity operations with program technical leads to discover cyber risks, understand applicable policies, and develop mitigation plans
  • Maintain RMF documents for system baseline variants that have achieved ATO
  • Work independently, identify problems and devise analysis and solutions, communicate results to both technical and non-technical audiences, and lead the accomplishments of client tasks from inception to completion
  • Develop and deliver cybersecurity update presentations to high level stakeholders that incorporate analysis of National Institute of Standards and Technology (NIST) controls and identified expected system and workload impacts

Benefits

  • 100% company-paid health, dental, and vision (to include individual, employee + significant other, or family)
  • 401K match with immediate vesting the date of hire with CaVU
  • Employer paid $100,000 life insurance policy
  • 11 paid holidays
  • 15 days of vacation with graduating accruals every two years
  • Access to corporate discounts on retail/travel/entertainment
  • Highly competitive compensation and opportunities for bonuses
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service