Information Security Analyst
Bath Savings Institution
Full-time
Bath, ME
Job description
Position Summary
Stratus Services is seeking a detail-oriented and motivated Cybersecurity Analyst to support our cybersecurity and compliance initiatives, with a focus on CMMC (Cybersecurity Maturity Model Certification) and NIST-based frameworks. This role will assist in assessing, implementing, and maintaining security controls for internal systems and client environments to ensure compliance with federal and industry standards.
The ideal candidate has foundational cybersecurity knowledge, strong documentation skills, and a working understanding of compliance frameworks such as NIST SP 800-171 and CMMC.
Key Responsibilities
- Assist in the implementation and monitoring of security controls aligned with CMMC and NIST SP 800-171
- Support gap assessments, risk assessments, and compliance readiness evaluations
- Develop and maintain documentation including:
- System Security Plans (SSPs)
- Plans of Action & Milestones (POA&Ms)
- Policies, procedures, and evidence artifacts
- Monitor security tools and alerts to identify and respond to potential threats
- Support internal and client audits related to cybersecurity compliance
- Collaborate with IT teams to ensure proper configuration and security baselines
- Stay current on evolving cybersecurity threats, compliance requirements, and best practices
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience)
- CompTIA Security+ (required) or equivalent certification
- 1–3 years of experience in cybersecurity, IT security, or compliance-related roles
- Basic understanding of:
- NIST SP 800-171
- CMMC framework
- Risk management principles
- Familiarity with security tools such as SIEM, endpoint protection, vulnerability scanners, and MFA solutions
- Strong analytical, organizational, and documentation skills
- Excellent written and verbal communication skills
Preferred Qualifications
- Certified CMMC Professional (CCP)
- CompTIA CySA+, GSEC, or similar certification
- Experience supporting DoD contractors or federal compliance requirements
- Knowledge of Microsoft 365 security tools (Defender, Sentinel, Intune, etc.)
- Experience with audit preparation and evidence collection
Core Competencies
- Attention to detail
- Problem-solving mindset
- Strong ethical standards and integrity
- Ability to manage multiple tasks and deadlines
- Team-oriented with client-facing professionalism
Job Type: Full-time
Pay: $65,000.00 - $85,000.00 per year
Benefits:
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
License/Certification:
- CompTIA Security+ or equivalent certification (Required)
Location:
- Anchorage, AK 99503 (Required)
Work Location: In person