Cybersecurity Analyst II/ISSO
SPECTRUM CONTROL · Massachusetts
📍 Marlborough, MA💰 $85,000 - $120,000via workdayFirst listed here 2026-08-21
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to SPECTRUM CONTROL.
At Spectrum Control, most departments operate on a 4-day, 10-hour work schedule in exchange for a 3-day weekend . We offer competitive wages and PTO, plus our benefits begin on day 1 of employment. Come join a workforce where we put you first!
POSITION SUMMARY : The Cybersecurity Analyst II/ISSO protects enterprise systems, networks, and data by monitoring for threats, investigating security events, and managing vulnerability remediation. This role also owns a significant share of the security program's documentation and enablement work — authoring incident response playbooks, maintaining the security knowledgebase, and running the company's cybersecurity awareness training and newsletter. The analyst operates with limited supervision on routine work, escalates complex incidents to senior staff, and mentors Analyst I team members.
COMPENSATION RANGE: The expected compensation range for this position is $85,000 - $120,000 annually.
KEY RESPONSIBILITIES:
Threat Detection & Monitoring (~20%)
Monitor SIEM, EDR, email security, and network security tooling for indicators of compromise
Triage and investigate security alerts; determine scope, severity, and false-positive status
Tune detection rules to reduce alert noise and recommend new detection logic
Conduct basic threat hunting using threat intelligence feeds and indicators of compromise
Review and validate escalations from Analyst I staff
Incident Response & Playbook Development (~20%)
Serve as a first- and second-tier responder for security incidents
Author, test, and maintain incident response playbooks for recurring incident types including phishing, ransomware, account compromise, data exfiltration, insider risk, and production system events
Partner with senior security staff, IT, and business owners to validate playbook steps and escalation paths
Contain and remediate endpoint and account compromises
Document incident timelines, root cause, and lessons learned
Feed post-incident findings back into playbooks and detection logic
Participate in an on-call rotation and facilitate tabletop exercises
Vulnerability Management (~20%)
Run and interpret vulnerability scans across servers, endpoints, network devices, and cloud workloads
Prioritize findings by exploitability and business impact
Drive remediation with IT and application owners and escalate blocked items
Track remediation SLAs and report on aging and recurring findings
Validate patching and configuration hardening against CIS and vendor baselines
Information System Security Officer (ISSO) (20%)
Support implementation and execution of NIST Risk Management Framework (RMF)
Develop, maintain, and review system security documentation including: System security plans (SSPs), Hardware/software baselines, Configuration diagrams, and RMF policies
Perform continuous monitoring of system configurations, user accounts, privileged access, and audit logs
Track, assess, and patch system vulnerabilities and findings using vulnerability managers and STIGS
Ensure changes to system hardware, software, architecture, and configurations are evaluated for cybersecurity impact
Assess system compliance with NIST 800-53 Rev5 security controls, organizational policies, and contractual (DD254) requirements
Documentation & Knowledge Ownership (~10%)
Own the cybersecurity knowledgebase — create, review, and retire articles covering security processes, tool usage, request workflows, and troubleshooting guidance
Ensure documented processes are accurate, versioned, discoverable, and written for the intended audience
Establish and enforce a review cadence so articles do not go stale
Translate undocumented tribal knowledge into repeatable written process
Coach Analyst I staff on documentation standards
Security Awareness Training & Communications (~10%)
Own the enterprise cybersecurity awareness training program including curriculum selection, module assignment, tracking, and completion reporting
Create and publish the recurring cybersecurity newsletter, translating current threats and internal trends into practical guidance for a non-technical audience
Design and run phishing simulation campaigns; analyze results and target follow-up training
Deliver targeted training for high-risk roles and support onboarding security orientation
Support compliance evidence collection, access reviews, and internal and external audits
REQUIRED QUALIFICATIONS:
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience
2–5 years of hands-on experience in security operations, vulnerability management, or IT infrastructure
Working knowledge of SIEM platforms, EDR tooling, and vulnerability scanners
Solid understanding of TCP/IP networking, DNS, firewalls, VPN, and proxy concepts
Familiarity with Windows and Linux administration and Active Directory / Entra ID
Understanding of common attack techniques and the MITRE ATT&CK framework
Demonstrated strong technical writing ability — able to produce clear playbooks, procedures, and end-user-facing content
Comfort presenting and communicating security concepts to non-technical audiences
Must be able to obtain SECRET clearance
PREFERRED QUALIFICATIONS:
Experience in a DoD or defense manufacturing environment supporting CMMC / NIST 800-171 compliance requirements
Certifications such as Security+, CySA+, GCIH, GSEC, GCIA, SSCP, or an associate-level Azure or AWS security certification
Scripting experience (PowerShell, Python, KQL) for automation and log analysis
Cloud security experience with Azure, AWS, or the Microsoft 365 security stack
Experience administering a security awareness platform such as KnowBe4, Proofpoint, or Hoxhunt
Experience maintaining documentation in a knowledgebase or ITSM platform such as ServiceNow, Confluence, SharePoint, or Jira
Exposure to NIST CSF, ISO 27001, CIS Controls, or export-control-adjacent environments
Experience with SOAR a
More Massachusetts jobs
Massachusetts jobs · Browse all locations