Senior Cybersecurity Analyst
At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description—it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one.
For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska.
Together We Grow – One Mission, One Team – With a Commitment to Serve
Job Title: Senior Cybersecurity Analyst
Work Location: Remote or hybrid remote if near CO/VA offices
Labor Category: Exempt
Clearance Level: Secret
Travel: Up to 20%
Pay Rate: $91,000 - $124,000
About the Role
This role works collaboratively with IT leadership, systems administrators, business units, compliance personnel, vendors, auditors, and other stakeholders, the Senior Cybersecurity Analyst will help establish and maintain a risk-based, defense-in-depth cybersecurity program that supports organizational operations, contractual obligations, regulatory requirements, and the protection of critical information assets. The position requires a combination of strong technical cybersecurity expertise, analytical and investigative capabilities, regulatory and compliance knowledge, documentation skills, and the ability to communicate cybersecurity risk effectively to both technical and non-technical audiences.
What You'll Be Doing
- Monitor, investigate, and respond to cybersecurity alerts, incidents, vulnerabilities, and threats across enterprise, endpoint, cloud, network, and application environments.
- Support compliance with NIST SP 800-171, CMMC, and applicable federal/DoD cybersecurity requirements, including protection of CUI and FCI.
- Implement, assess, document, and continuously monitor cybersecurity controls and maintain SSPs, POA&Ms, policies, procedures, and compliance evidence.
- Conduct cybersecurity risk assessments, vulnerability assessments, and security reviews; prioritize findings and coordinate remediation efforts.
- Support internal and external audits, CMMC assessments, customer reviews, and other cybersecurity compliance activities.
- Analyze security logs, alerts, and threat intelligence using tools such as SIEM, EDR, Microsoft 365, Azure, Entra ID, firewalls, and endpoint security platforms.
- Participate in incident response activities, including investigation, containment, remediation, recovery, documentation, and post-incident reviews.
- Assess and improve security configurations, system hardening, patch management, endpoint protection, network security, cloud security, and data protection controls.
- Support identity and access management, including MFA, Conditional Access, privileged access, least privilege, RBAC, and periodic access reviews.
- Evaluate security posture across Microsoft 365, GCC High, Azure, Entra ID, Active Directory, and other enterprise platforms.
- Support third-party/vendor risk management, technology security reviews, change management, and cybersecurity assessments for new systems and services.
- Develop cybersecurity metrics, dashboards, risk registers, vulnerability reports, and compliance reporting for leadership.
- Develop and maintain cybersecurity policies, standards, procedures, incident response plans, and security documentation.
- Support security awareness programs, phishing simulations, cybersecurity training, and organization-wide security initiatives.
- Provide cybersecurity guidance to employees, IT teams, leadership, vendors, auditors, and assessors.
- Stay current on emerging threats, vulnerabilities, regulations, cy