Cybersecurity Assessment Data Analyst
Job Title: Cybersecurity Assessment Data AnalystJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to Start: TS/SCIEmployee Type: RegularPercentage of Travel Required: Up to 10%Type of Travel: Continental US* * * The Opportunity:
CACI is seeking a Cybersecurity Assessment Data Analyst to turn assessment, scan, asset, evidence, and remediation data into trusted operational insights. The analyst will support penetration testing, red team, and attack-surface evaluation by normalizing data, validating quality, identifying trends and risk concentrations, and producing repeatable dashboards and reporting products. This is a shared analytical capability; it does not replace the technical judgment of assessment SMEs.
This position will provide continuous technical assessment support for full‑time, proactive testing of externally and internally visible federal cyber assets. This expands federal visibility by conducting continual assessments of .gov domains, subdomains, and internet‑facing assets to uncover unknown exposures, validate vulnerabilities, and provide agencies with actionable remediation guidance. This role supports the Continuous Diagnostics and Mitigation (CDM) Program’s mission to safeguard and secure cyberspace in an environment where the threat of cyber-attack is continuously growing and evolving and is responsible for enhancing the security, resilience, and reliability of the Nation’s cyber and communications infrastructure. The CDM Program defends the United States (U.S.) Federal Information Technology (IT) networks from cybersecurity threats by providing continuous monitoring sensors (tools), diagnosis, mitigation tools, and associated services to strengthen the security posture of Government networks.
Responsibilities:
- Ingest, normalize, reconcile, and quality-check data from customer-approved assessment tools, scanners, APIs, repositories, tickets, operator evidence, and remediation workflows.
- Develop repeatable data models, queries, scripts, metrics, dashboards, and reporting packages that show asset coverage, finding trends, attack paths, severity, remediation status, and delivery performance.
- Correlate vulnerability and exposure data with CISA KEV, CVSS, EPSS, asset criticality, exploit evidence, threat context, and customer priorities.
- Investigate duplicates, conflicting identifiers, missing fields, stale records, outliers, and reconciliation issues; document source lineage and metric definitions.
- Build clear visualizations and executive summaries while preserving drill-down access to technical evidence and limitations.
- Partner with assessment SMEs, technical writers, project management, and customer stakeholders to answer recurring and ad-hoc questions accurately and quickly.
- Automate recurring extracts, transformations, validation checks, and deliverables using source-controlled code and documented procedures.
Qualifications:
Required:
• U.S. citizenship is required.
- The selected candidate must meet eligibility requirements for access to sensitive information and be able to obtain a Public Trust fitness determination (High Risk).
- Ability to work in customer-provided remote environments, use customer-approved tools, and comply with rules of engagement, data-handling requirements, evidence controls, deconfliction procedures, and stop-work criteria.
- Five or more years of data analysis, cybersecurity analytics, reporting, business intelligence, or data-engineering experience, including work with technical security data.
- Strong SQL and Python skills and practical experience with data cleaning, joins, APIs, structured files, quality validation, reproducible analysis, and version control.
- Experience building dashboards and reports in Power BI, Tableau, Splunk, Elastic, or comparable tools.
- Working knowledge of vulnerability, asset, finding, evidence, ticket, and remediation data and of concepts such as CVE, CVSS, CISA KEV, EPSS, false pos
Get remote data science jobs like this by email
One weekly digest. No spam, unsubscribe anytime.