Benefits:
- 401(k)
- Competitive salary
- Dental insurance
- Health insurance
- Paid time off
- Training & development
- Vision insurance
We are seeking a Cybersecurity Protect Analyst to support our Defense Threat Reduction Agency (DTRA) Tier II Cybersecurity Services Provider (CSSP) Team. Spahr is a fast-growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well-planned information management environment. “Integrity. Purpose. Resolve” embodies our values and is paramount to both our and our customer’s success. By relentlessly upholding our values and investing in our employees we foster a culture of integrity and selfless service, build resilient teams that are ready to solve hard problems, and deliver real impact for the client.
We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. Visit us at https://www.spahrllc.com. Apply now to explore jobs with us!
The safety and health of our employees is of the utmost importance. By applying for a role at Spahr you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP".
Required Responsibilities:
· Subscriber Engagement & Liaison: Act as the technical cybersecurity liaison for subscriber organizations, providing advanced, hands-on guidance for resolving complex security posture issues, patching delays, and system misconfigurations.
· Data Element Dictionary (DED) Governance: Act as the primary auditor for the CSSP Data Element Dictionary (DED). Coordinate with data producers and data stewards to maintain canonical field mappings and machine-readable schemas. Oversee validation rules for identity-attributed, network, and object-access events to guarantee schema compliance across all DTRA subscriber tenants.
· Vulnerability Tracking & KEV Management: Actively track and analyze CISA’s Known Exploited Vulnerabilities (KEV) catalog using standardized cybersecurity frameworks, including Common Vulnerabilities and Exposures (CVE) identifiers, National Vulnerability Database (NVD) resources, Common Vulnerability Scoring System (CVSS) severity vectors, and Common Weakness Enumeration (CWE) classifications, to evaluate localized risks, prioritize mitigation efforts, and coordinate rapid remediation with system owners.
· Vulnerability Assessment & Analysis (VAA): Execute comprehensive vulnerability assessments using the Assured Compliance Assessment Solution (ACAS) and other enterprise scanning tools, analyzing raw scan data to deliver actionable, prioritized remediation steps to stakeholders.
· Cyber Threat Intelligence (CTI) Integration: Monitor, evaluate, and digest cyber threat intelligence feeds, indicator of compromise (IOC) alerts, and open-source threat reports to anticipate emerging vectors and proactively adjust defensive postures.
· ESM & Compliance Support: Support CSSP Evaluator Scoring Metric (ESM) compliance assessments, gathering technical evidence, conducting internal control reviews, and maintaining organizational readiness for JFHQ-DoDIN mandated evaluations.
· Blue Team & Posture Validation: Coordinate and conduct "Blue Team" assessments under Government supervision to evaluate subscriber security postures for DoW compliance, while validating detection playbooks and signature effectiveness by emulating adversary tactics to trigger alerts and detect Red Team activities.
· Endpoint & Malware Defense Validation: Perform technical validation of endpoint security tools, host-based security systems, and boundary defense mechanisms to ensure malware protection policies are active, correctly configured, and reporting to central CSSP consoles.
· Directive Implementation: Track, implement, and technically validate compliance with USCYBERCOM TASKORDs, Cyber Protection Condition (CPCON) shifts, and JFHQ-DoDIN operational directives.
· Audit Readiness & Evidence Gathering: Lead compliance focused working groups with subscriber IT teams. Guide them through gathering technical evidence, conducting internal control reviews, and ensuring total readiness for rigorous DoW and agency-level cybersecurity audits (e.g., CORA, CSSP evaluations).
Who We Are
Spahr is an SBA certified women owned and service disabled owned small business offering information technology and management consulting services to DoD and federal customers. Our dedicated and diverse employees provide high quality services to our customers. Our current core focus is software development, data analytics and software engineering. We also provide specialized management consulting services
Our CEO serves on the Board of Directors for the National Veteran Small Business Coalition. The NVSBC provides training, networking, advocacy for veteran and service disabled veteran owned small businesses in the federal and DoD market. This allows veteran entrepreneurs to start, operate, sustain and grow their business and ensure they are procurement ready.
Spahr participates in the SBA Mentor Protégé Program to promote and accelerate the maturation and evolution of its proven performance by strategically leveraging the resources, expertise, and experience of the mentor, TekSynap.
Above all else, we at Spahr value our employees. To join our team is to join our extended family. Every employee is a mission multiplier who brings something unique to the table, and we love learning from each other. We hear from our employees that they enjoy working for leaders who not just lead but are caring and compassionate. We hope you consider joining our growing team!
Above all else, we at Spahr value our employees. To join our team is to join our extended family. Every employee is a mission multiplier who brings something unique to the table, and we love learning from each other. We hear from our employees that they enjoy working for leaders who not just lead but are caring and compassionate. We hope you consider joining our growing team!
(if you already have a resume on Indeed)

