Enter a job title or keyword

Cybersecurity AnalystISSO

Spectrum Control


Job Location:

Marlborough, NH - USA

Yearly Salary: $ 85000 - 120000
Posted: 22 August 2026 (22 hours ago)
Application Deadline: 19 November 2026
Vacancies: 1 Vacancy

Job Summary

At Spectrum Control most departments operate on a 4-day 10-hour work schedule in exchange for a 3-day weekend. We offer competitive wages and PTO plus our benefits begin on day 1 of employment. Come join a workforce where we put you first!

POSITION SUMMARY: The Cybersecurity Analyst II/ISSO protects enterprise systems networks and data by monitoring for threats investigating security events and managing vulnerability remediation. This role also owns a significant share of the security programs documentation and enablement work authoring incident response playbooks maintaining the security knowledgebase and running the companys cybersecurity awareness training and newsletter. The analyst operates with limited supervision on routine work escalates complex incidents to senior staff and mentors Analyst I team members.

COMPENSATION RANGE: The expected compensation range for this position is $85000 - $120000 annually.

KEY RESPONSIBILITIES:

Threat Detection & Monitoring (20%)

  • Monitor SIEM EDR email security and network security tooling for indicators of compromise
  • Triage and investigate security alerts; determine scope severity and false-positive status
  • Tune detection rules to reduce alert noise and recommend new detection logic
  • Conduct basic threat hunting using threat intelligence feeds and indicators of compromise
  • Review and validate escalations from Analyst I staff

Incident Response & Playbook Development (20%)

  • Serve as a first- and second-tier responder for security incidents
  • Author test and maintain incident response playbooks for recurring incident types including phishing ransomware account compromise data exfiltration insider risk and production system events
  • Partner with senior security staff IT and business owners to validate playbook steps and escalation paths
  • Contain and remediate endpoint and account compromises
  • Document incident timelines root cause and lessons learned
  • Feed post-incident findings back into playbooks and detection logic
  • Participate in an on-call rotation and facilitate tabletop exercises

Vulnerability Management (20%)

  • Run and interpret vulnerability scans across servers endpoints network devices and cloud workloads
  • Prioritize findings by exploitability and business impact
  • Drive remediation with IT and application owners and escalate blocked items
  • Track remediation SLAs and report on aging and recurring findings
  • Validate patching and configuration hardening against CIS and vendor baselines

Information System Security Officer (ISSO) (20%)

  • Support implementation and execution of NIST Risk Management Framework (RMF)
  • Develop maintain and review system security documentation including: System security plans (SSPs) Hardware/software baselines Configuration diagrams and RMF policies
  • Perform continuous monitoring of system configurations user accounts privileged access and audit logs
  • Track assess and patch system vulnerabilities and findings using vulnerability managers and STIGS
  • Ensure changes to system hardware software architecture and configurations are evaluated for cybersecurity impact
  • Assess system compliance with NIST 800-53 Rev5 security controls organizational policies and contractual (DD254) requirements

Documentation & Knowledge Ownership (10%)

  • Own the cybersecurity knowledgebase create review and retire articles covering security processes tool usage request workflows and troubleshooting guidance
  • Ensure documented processes are accurate versioned discoverable and written for the intended audience
  • Establish and enforce a review cadence so articles do not go stale
  • Translate undocumented tribal knowledge into repeatable written process
  • Coach Analyst I staff on documentation standards

Security Awareness Training & Communications (10%)

  • Own the enterprise cybersecurity awareness training program including curriculum selection module assignment tracking and completion reporting
  • Create and publish the recurring cybersecurity newsletter translating current threats and internal trends into practical guidance for a non-technical audience
  • Design and run phishing simulation campaigns; analyze results and target follow-up training
  • Deliver targeted training for high-risk roles and support onboarding security orientation
  • Support compliance evidence collection access reviews and internal and external audits

REQUIRED QUALIFICATIONS:

  • Bachelors degree in Cybersecurity Information Technology Computer Science or equivalent practical experience
  • 25 years of hands-on experience in security operations vulnerability management or IT infrastructure
  • Working knowledge of SIEM platforms EDR tooling and vulnerability scanners
  • Solid understanding of TCP/IP networking DNS firewalls VPN and proxy concepts
  • Familiarity with Windows and Linux administration and Active Directory / Entra ID
  • Understanding of common attack techniques and the MITRE ATT&CK framework
  • Demonstrated strong technical writing ability able to produce clear playbooks procedures and end-user-facing content
  • Comfort presenting and communicating security concepts to non-technical audiences
  • Must be able to obtain SECRET clearance

PREFERRED QUALIFICATIONS:

  • Experience in a DoD or defense manufacturing environment supporting CMMC / NIST 800-171 compliance requirements
  • Certifications such as Security CySA GCIH GSEC GCIA SSCP or an associate-level Azure or AWS security certification
  • Scripting experience (PowerShell Python KQL) for automation and log analysis
  • Cloud security experience with Azure AWS or the Microsoft 365 security stack
  • Experience administering a security awareness platform such as KnowBe4 Proofpoint or Hoxhunt
  • Experience maintaining documentation in a knowledgebase or ITSM platform such as ServiceNow Confluence SharePoint or Jira
  • Exposure to NIST CSF ISO 27001 CIS Controls or export-control-adjacent environments
  • Experience with SOAR and security automation workflows

CORE COMPETENCIES:

  • Analytical rigor and attention to detail under time pressure
  • Bias toward documenting and systematizing rather than re-solving the same problem
  • Sound judgment on when to escalate versus resolve independently
  • Collaborative; works effectively with infrastructure application manufacturing and business teams
  • Continuous learner who tracks the evolving threat landscape
  • Able to teach and mentor less experienced analysts

WORKING CONDITIONS:

  • Occasional after-hours work for incident response patching and maintenance windows
  • On-site role based at Spectrum Controls manufacturing facility in Marlborough MA
  • U.S. person status is required

CAREER PATH

Progression to Cybersecurity Analyst III typically requires demonstrated incident command capability ownership of a security domain or platform end to end measurable program improvement and an advanced certification or equivalent depth.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities


The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about discussed or disclosed their own pay or the pay of another employee or applicant. However employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information unless the disclosure is (a) in response to a formal complaint or charge (b) in furtherance of an investigation proceeding hearing or action including an investigation conducted by the employer or (c) consistent with the contractors legal duty to furnish information. 41 CFR 60-1.35(c)

Third-Party Recruiters

Please note that per Spectrum Control Policy we do not accept unsolicited resumes from third-party recruiters unless such recruiters are engaged to provide candidates for a specified opening and in alignment with our values and expectations. Any employment agency person or entity that submits an unsolicited resume does so with the understanding that Spectrum Control will have the right to hire that applicant at its discretion without any fee owed to the submitting employment agency person or entity. If you or your agency are interested in becoming an approved vendor please contact


Required Experience:

IC


About Company

Company Logo

Spectrum Control is a global leader in high-performance RF and microwave signal processing and conditioning, and electromagnetic interference protection. For more than 70 years our company has led the way in developing reliable, high-performance technologies for powering and condition ... View more

View Profile View Profile