Fors Marsh Logo

Fors Marsh

Cybersecurity Analyst, IT Operations

Posted 3 Days Ago
Remote
Hiring Remotely in United States
110K-125K Annually
Senior level
Remote
Hiring Remotely in United States
110K-125K Annually
Senior level
Support and enforce NIST/CMMC-aligned security controls; monitor SIEM/EDR and perform incident triage and response; manage Windows/AD environments; conduct vulnerability scanning and remediation; protect and classify FCI/CUI; support audits and control validation; maintain compliance documentation; collaborate with IT and business teams and communicate security risks to technical and non-technical stakeholders.
The summary above was generated by AI

WHO WE ARE: 

At Fors Marsh, we take on issues that matter. We are a team of researchers, strategists, and communicators working together to drive lasting change. We look at human behavior from all angles with a deep understanding of people and context to design solutions that influence decision-making and move people to action. Our work promotes health and well-being, shapes resilient communities, and builds effective and accountable institutions. We are a certified B Corporation and a Top Workplace for 7 consecutive years.

WHO WE ARE LOOKING FOR: 

We are seeking a detail-oriented Cybersecurity Analyst with hands-on experience in enterprise security operations and a strong understanding of federal compliance frameworks such as NIST SP 800-171, NIST SP 800-53, and CMMC. The ideal candidate has experience securing primarily Windows-based environments, with some exposure to Linux systems, managing vulnerabilities, and responding to security incidents, while also demonstrating a solid grasp of data classification and the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). This individual should be comfortable working in regulated environments where sensitive data is restricted to secure systems, supporting audits, maintaining compliance documentation, and collaborating across IT and business teams. Strong analytical skills, clear communication, and a proactive, accountable approach to safeguarding sensitive data are essential for success in this role.
Responsibilities include:

• Support the implementation, monitoring, and enforcement of security controls aligned with NIST SP 800-171, NIST SP 800-53, and CMMC Level 2 requirements
• Monitor security events and alerts across enterprise systems (e.g., SIEM, endpoint detection, network devices) and perform incident triage, investigation, and response
• Assist in maintaining and securing Windows-based enterprise environments, including Active Directory, servers, and endpoints
• Conduct vulnerability scanning and remediation tracking, including prioritization of findings based on risk and compliance impact
• Support the protection, processing, and storage of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) in accordance with company policy and contractual requirements
• Support and enforce organizational data classification policies, including identification, labeling, and handling of FCI, CUI, and other sensitive data types
• Ensure appropriate access controls, data handling procedures, and system protections are applied based on data classification levels
• Collaborate with IT and business teams to ensure systems and workflows properly segregate and protect sensitive data in secure environments
• Assist in monitoring and validating that CUI is restricted to authorized systems and not stored on end-user devices outside approved environments
• Participate in internal and external security assessments (e.g., CMMC, IRS Pub 4812, RMF, and client audits) by gathering evidence and supporting control validation
• Maintain documentation for security controls, system configurations, and procedures to ensure audit readiness
• Assist in mapping technical controls and remediation efforts to applicable compliance frameworks
• Work closely with IT operations, system administrators, and leadership to address security risks and operational issues
• Communicate security risks and recommendations clearly to both technical and non-technical stakeholders
• Promote user awareness of data handling expectations, including proper treatment of FCI and CUI in daily operations
Qualifications:

  • Bachelor's degree from an accredited college or university in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related field
  • Relevant industry certifications such as Security+, CISSP, CISM, GSEC, CySA+, CEH, .
  • Minimum of 7 years of progressively responsible experience in cybersecurity, information security, systems administration, network security, risk management, or a related IT discipline. Experience supporting security operations, incident response, vulnerability management, compliance, or security engineering in an enterprise environment.
  • Experience implementing or supporting security requirements aligned with frameworks such as CMMC, NIST 800-53, NIST 800-171 and Cybersecurity Framework (CSF), ISO 27001, CIS Controls, or similar standards..
  • Experience with security technologies such as SIEM platforms, endpoint detection and response (EDR), vulnerability scanning tools, identity and access management solutions, firewalls, and multifactor authentication technologies. Experience analyzing security logs, alerts, and incidents using tools with Nessus, Tenable or similar solutions
  • Ability to work on occasion in the Arlington, VA area.
  • Applicants will be subject to a government security investigation and must meet eligibility criteria for access to sensitive information.
  • Must be a U.S. Citizen and consent to a full background check due to our federal contract requirements.


We Offer:

Our benefits typically meet or exceed our competitors’ packages. What’s in it for you?

• Ability to make an impact on people’s lives, both internal and external to the organization.

• Top-tier health, dental, vision, and long and short-term disability coverage.

• Our company culture, which values balance and allows each employee to take leave as they require it to balance the responsibilities of both their work and home lives without worrying about depleting their available leave hours.

• A floating holiday bank so you can celebrate the days you value.

• Generous matching retirement contributions and no vesting period starting the third month of employment.

• Dedicated training and development budgets to expand your expertise and grow your skillset.

• You can volunteer your way with paid time off.

• You can participate in Fors Marsh staff-led affinity groups.

• Our employees receive product and service discounts through the certified B Corp network.


Salary:$110,000-$125,000

Internal Fors Marsh Career Map Title: Cybersecurity Analyst III

Location:  Remote, within the U.S. Occasional travel required.

Equal Opportunity Employer:All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Similar Jobs

59 Minutes Ago
In-Office or Remote
San Francisco, CA, USA
230K-298K Annually
Senior level
230K-298K Annually
Senior level
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
Provide transactional legal support for Circle's global capital markets business, drafting and negotiating complex crypto, fintech, and capital markets agreements (exchanges, market makers, liquidity, collateral, tokenized assets). Support Arc's capital markets go-to-market, create contract templates and playbooks, streamline contracting workflows, advise cross-functional partners, and stay current on crypto, stablecoins, and blockchain regulatory developments to enable commercial partnerships and revenue opportunities.
Top Skills: Ai ToolsApple MacosChatgptGoogle SuiteSlack
An Hour Ago
Remote or Hybrid
95K-193K Annually
Senior level
95K-193K Annually
Senior level
Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Sell Healthy Buildings Advisory and EHS/sustainability solutions, develop strategy, drive new business, manage account plans, build client relationships, collaborate with technical teams, support discovery through hand-off to implementation, and meet/exceed sales targets while traveling 25–50%.
Top Skills: Crm SoftwareExcelMs Office (WordOutlook)PowerPoint
An Hour Ago
Remote or Hybrid
95K-193K Annually
Senior level
95K-193K Annually
Senior level
Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Drive new business and exceed sales targets for EHS and sustainability advisory and software solutions. Develop strategy for Healthy Buildings practice, manage and prioritize accounts, engage customers to identify needs, craft customized solutions with technical teams, support hand-off to implementation and client success, and build industry relationships and trust. Travel 25–50% and operate fully remote.
Top Skills: Crm SoftwareExcelMicrosoft OutlookMicrosoft PowerpointMicrosoft Word

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account