The Cyber Security Analyst I is a growth-track role for someone early in their cybersecurity career who wants to work in a real DIB environment, learn CMMC and NIST 800-171 from the inside, and gain hands-on experience with the full Microsoft security stack. The analyst works alongside a senior analyst and the Information & Cyber Security Manager, supporting day-to-day security operations, evidence collection, user lifecycle management, and program documentation.
What you'd do
- Security Operations Support: Triage Defender alerts, monitor phishing simulation results, review Entra ID sign-in risk events, and escalate anomalies to the senior analyst.
- Vulnerability Tracking: Pull weekly vulnerability reports from Defender and Nessus, update the tracker, and follow up with remediation owners on overdue items.
- Documentation and Evidence: Keep evidence folders current for NIST 800-171 and CMMC controls. Update procedures, screenshots, and checklists as systems change.
- Policy Support: Assist the senior analyst in drafting and updating policies and procedures; own version control, review cycle, and distribution.
- Training and Awareness: Support the monthly phishing simulation program, track completion of annual security training, and follow up with incomplete users.
- Tickets and Access Requests: Own the security-ticket queue for access requests, exceptions, and general security questions from the business.
- Program Development: Shadow the senior analyst and manager on incident response, audits, and policy work; work toward CMMC RP / Security+ / SC-200 within the first year.
- Other Duties: Other duties as assigned.
What they want
- 0–2 years of professional experience. Internships, lab work, home-lab projects, IT help-desk time, and military IT experience are all considered.
- Familiarity with the Microsoft 365 admin center and eagerness to go deeper.
- Clear writing skills — ability to take a verbal explanation and produce a procedure a coworker can follow.
- CompTIA Security+ or A+/Network+ on the path to Security+.
- Coursework, certifications, or lab work in NIST 800-171, CMMC, or the Risk Management Framework.
- Any Microsoft fundamentals certification (SC-900, MS-900, AZ-900).
- Exposure to ticketing systems (ServiceNow, Jira) or documentation platforms (SharePoint, Confluence).
- Basic PowerShell or KQL — willingness to learn is more important than current proficiency.Technical Knowledge, Skills and Abilities
- Microsoft 365 admin center
- Defender for Endpoint
About Smiths Detection · Info Systems & Technology
Every minute of every day, Smiths Detection’s threat detection and security screening technology helps to protect people and infrastructure, making the world a safer place.
Smiths Detection is a global leader in the development, manufacture and management of security and detection solutions designed to make the world a safer place.