2

Entry Level Nist Cybersecurity Framework Jobs (NOW HIRING)

CyberSecurity Intern

Washington, DC ยท Remote

$18 - $20/hr

Element is seeking a motivated Cybersecurity Intern to support our organization's implementation of the NIST Cybersecurity Framework (CSF). This 12-week internship provides hands-on experience in ...

next page

Showing results 1-20

Entry Level Nist Cybersecurity Framework information

See salary details

$43K

$99.4K

$150K

How much do entry level nist cybersecurity framework jobs pay per year?

As of Jun 14, 2026, the average yearly pay for entry level nist cybersecurity framework in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

How do I get a job in cyber security with no experience?

Entry-level cybersecurity roles often require foundational knowledge of networking, operating systems, and security principles. Gaining certifications like CompTIA Security+ or Cisco's CCNA, along with hands-on practice through labs or internships, can improve your chances; demonstrating a strong interest in cybersecurity tools and concepts is also beneficial.

What are the key skills and qualifications needed to thrive as an Entry Level NIST Cybersecurity Framework Analyst, and why are they important?

To thrive as an Entry Level NIST Cybersecurity Framework Analyst, you need a foundational understanding of cybersecurity principles, risk assessment, and familiarity with the NIST Cybersecurity Framework, often supported by a relevant degree or coursework. Knowledge of security tools such as vulnerability scanners, SIEM systems, and basic certifications like CompTIA Security+ are commonly required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret data and work collaboratively. These skills and qualities are essential for identifying risks, ensuring compliance, and supporting organizational cybersecurity initiatives.

What is an Entry Level NIST Cybersecurity Framework role?

An Entry Level NIST Cybersecurity Framework role involves assisting organizations in implementing and maintaining cybersecurity controls based on the NIST Cybersecurity Framework (CSF). Individuals in this position typically help assess risks, identify security gaps, and support the development of policies and procedures to protect information systems. They often work under the supervision of more experienced cybersecurity professionals and may help with compliance, reporting, and awareness training. This role is ideal for those new to cybersecurity who want to build foundational knowledge in a widely adopted security framework.

How do I get an entry-level cyber security job?

To secure an entry-level NIST Cybersecurity Framework role, candidates should develop foundational knowledge of cybersecurity principles, familiarize themselves with the NIST standards, and gain hands-on experience through internships or labs. Earning relevant certifications such as CompTIA Security+ or Cisco's CCNA Security can also improve job prospects, along with strong problem-solving skills and familiarity with security tools like firewalls and intrusion detection systems.

What are some typical challenges faced by professionals in entry-level NIST Cybersecurity Framework roles, and how can they overcome them?

Entry-level professionals working with the NIST Cybersecurity Framework often face challenges such as understanding the framework's terminology, mapping its functions to existing organizational processes, and balancing compliance requirements with practical security controls. It can also be challenging to communicate technical findings to non-technical stakeholders. Overcoming these challenges involves continuous learning, seeking mentorship from experienced team members, and leveraging official NIST resources and training materials. Collaborating closely with cross-functional teams and participating in regular security meetings also helps build confidence and competence in applying the framework effectively.

Can I make $200,000 a year in cyber security?

Entry Level NIST Cybersecurity Framework roles typically have starting salaries below $100,000, but experienced cybersecurity professionals with advanced skills, certifications, and specialized knowledge can earn $200,000 or more annually. Achieving this level often requires several years of experience, expertise in areas like threat analysis or security architecture, and possibly working in high-demand industries or locations with higher pay scales.

What is the most entry-level cybersecurity role?

An entry-level cybersecurity role often refers to positions such as Security Analyst, Cybersecurity Technician, or IT Security Support Specialist. These roles typically require foundational knowledge of networking, security tools, and may involve tasks like monitoring security systems, assisting with incident response, and supporting security infrastructure, often with certifications like CompTIA Security+ or basic knowledge of frameworks like NIST Cybersecurity Framework.
More about Entry Level Nist Cybersecurity Framework jobs
What cities are hiring for Entry Level Nist Cybersecurity Framework jobs? Cities with the most Entry Level Nist Cybersecurity Framework job openings:
What are the most commonly searched types of Nist Cybersecurity Framework jobs? The most popular types of Nist Cybersecurity Framework jobs are:
What states have the most Entry Level Nist Cybersecurity Framework jobs? States with the most job openings for Entry Level Nist Cybersecurity Framework jobs include:
What job categories do people searching Entry Level Nist Cybersecurity Framework jobs look for? The top searched job categories for Entry Level Nist Cybersecurity Framework jobs are:
Cybersecurity Analyst

Cybersecurity Analyst

Montgomery County (PA)

Norristown, PA โ€ข On-site

$41.61 - $55.48/hr

Full-time

Posted 21 days ago


Job description

SUMMARY The Cybersecurity Analyst supports the county's security posture by performing vulnerability assessments, owning the vulnerability management program, leading Microsoft Purview data classification operations, and contributing to compliance activities aligned to the NIST Cybersecurity Framework (CSF). This is an early career security analyst position in an expanding cybersecurity operation. The analyst will own defined program areas within vulnerability management and data classification, draft cyber security policy and standards documentation, and manage the operational components of the county's cybersecurity awareness training program in coordination with the ITS training team.

The role reports to the network security administrator and works across ITS teams and county departments to identify, assess, and remediate security risks to county systems and data. ESSENTIAL DUTIES AND RESPONSIBILITIES Own the vulnerability management program lifecycle - define scan schedules and SLA thresholds, conduct regular vulnerability scans across county infrastructure including servers, endpoints, network devices, and cloud-hosted services, track remediation trending over time, and produce actionable risk-ranked findings reports for ITS leadership. Lead Microsoft Purview onboarding for county departments including departmental collaboration, sensitivity label taxonomy design, content classification rule maintenance, and exception adjudication.

Ensure county data classification standards are enforced consistently across Microsoft 365, SharePoint, Azure, and on-premises repositories. Support compliance and data classification activities under HIPAA, CJIS Security Policy, and applicable state and federal data privacy requirements by mapping technical controls to framework requirements and documenting compliance status. Draft cybersecurity policies, standards, and procedures grounded in the NIST Cybersecurity Framework for review by the Network Security Administrator, including documentation covering asset management, access control, and incident detection categories.

Monitor security alerts from existing tools (endpoint protection, email filtering, firewall logs) and triage potential incidents, escalating confirmed threats per established procedures. Coordinate patch management activities with infrastructure and applications teams to ensure timely remediation of known vulnerabilities, tracking patch compliance against defined SLAs. Support ITS in conducting risk assessments for new technology procurements and system changes using ITS security and risk assessment rubrics.

Manage the compliance components of the county's mandatory cybersecurity awareness training program in coordination with the ITS training team, including phishing simulation campaign execution, compliance tracking, automated notifications, and credential suspension workflows for overdue participants. Produce and deliver quarterly metrics reports to ITS leadership on training completion rates, simulation results, and program effectiveness. Participate in incident response activities including detection, containment, documentation, and post-incident review.

Contribute to the development of incident response playbooks as the county builds its response capability. Assist in updating documentation on security controls, vulnerability management metrics, and compliance posture for reporting to ITS leadership and county stakeholders. Research emerging threats, vulnerabilities, and attack techniques relevant to local government environments.

Assist with identity and access management reviews, including periodic access certifications and privileged account audits across county systems. QUALIFICATION REQUIREMENTS Required Knowledge, Skills, and Abilities Working knowledge of vulnerability scanning tools (e.g., Nessus, Microsoft Defender Vulnerability Management, Qualys or similar) and the ability to interpret scan results and prioritize remediation based on risk. Familiarity with the NIST Cybersecurity Framework (CSF) and the ability to map organizational practices to CSF categories and subcategories

Understanding ofdata classification concepts and applied classification and data loss prevention frameworks. Practical experience with Microsoft Purview Information Protection, sensitivity labels, or comparable data classification tooling and in onboarding businesses (e.g., teams, offices, departments) with onboarding andutilizingPurview including cloud (MS SharePoint and Azure) and on-prem repositories. Knowledge of common network protocols, operating systems for Microsoft (Windows Server, Windows 10/11), and Active Directory/Entra ID administration sufficient to understand security implications

Familiarity with HIPAA Security Rule requirements. Ability to produce clear, concise written reports and briefings that communicate technical findings to non-technical audiences, including department heads and elected officials. Ability to work across teams and organizational boundaries, coordinating remediation activities with staff who do not report to ITS.

Working understanding of common attack vectors, the MITRE ATT&CK framework, and how threat intelligence applies to vulnerability prioritization. Ability to manage competing priorities and maintain documentation discipline in an environment where processes are being established for the first time. Required Qualifications Bachelor's degree in cybersecurity, information technology, computer science, or a related field.

An equivalent combination of education and directly relevant experience will be considered. Minimum 3 years of experience in information security, vulnerability management, IT audit, or a related discipline. Public sector experience is preferred but not required.

At least one active industry certification: CompTIA Security+, Microsoft Security Operations Analyst, or GIAC GSEC, or equivalent. Experience with Microsoft Purview, Microsoft Defender for Endpoint, or Microsoft 365 security and compliance tools. Familiarity with SIEM platforms (e.g., Microsoft Sentinel, Splunk, Elastic) and security log analysis

Preferred Qualifications Experience with NIST SP 800-53 controls, CIS Controls v8, or NIST SP 800-171. ISACA CISM, ISACA CCOA, CompTIACySA+, or GIAC GCIH certification. Experience supporting HIPAA or CJIS compliance programs.

Experience developing or contributing to cybersecurity policies, standards, or governance documentation. PHYSICAL DEMANDS Work is performed primarily in an office environment with standard business hours. Occasional evening or weekend work may be required during security incidents or planned maintenance windows.

This position may require on-call availability on a rotating basis as the county's monitoring capability matures. Some travel between county facilities may be required. AI and Emerging Technology Competency Montgomery County ITS is actively adopting generative AI and automation tools to improve operational efficiency.

The Cybersecurity Analyst is expected to develop competency with AI-assisted security tools, including AI-driven threat detection, automated vulnerability prioritization, and AI-supported compliance documentation. The analyst should approach these tools with practical curiosity and ability test and operate tools within established security boundaries to ensure the safety of county data and operating systems. Equal Employment Opportunity Montgomery County is an equal opportunity employer committed to creating a diverse and inclusive workplace.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic.