1

Lead Cybersecurity Analyst Jobs (NOW HIRING)

... Analyst to become the organization''s first dedicated cybersecurity hire. You''ll work directly ... Lead vulnerability identification, prioritization, remediation tracking, and reporting * Respond to ...

Cybersecurity Analyst

Dahlgren, VA · On-site

$87K - $157K/yr

Conduct cybersecurity testing under the direction of the lead engineer and assist in documenting ... Familiarity with secure coding practices or experience with secure code analysis tools.

The Lead Cybersecurity Specialist within the Legence IT Security organization will be responsible ... Lead incident response efforts, including triage, containment, root cause analysis, and post ...

Cybersecurity Analyst

Dahlgren, VA · On-site

$87K - $157K/yr

Conduct cybersecurity testing under the direction of the lead engineer and assist in documenting ... Familiarity with secure coding practices or experience with secure code analysis tools.

Cyber Security Analyst

Melville, NY · On-site

$19K - $21K/yr

POSITION SUMMARY The Cyber Security Analyst is a front-facing role, working directly with incoming ... This position reports to the SOC Team Lead. RESPONSIBILITIES Monitor incoming alerts, reports, and ...

Job#: 3040649 Cybersecurity Analyst - ICD Location: Atlanta, GA (Onsite) ** Role Overview We are ... Lead the development, review, and maintenance of enterprise-wide security policies, standards, and ...

next page

Showing results 1-20

Lead Cybersecurity Analyst information

See salary details

$60.5K

$123.8K

$175K

How much do lead cybersecurity analyst jobs pay per year?

As of Jul 23, 2026, the average yearly pay for lead cybersecurity analyst in the United States is $123,849.00, according to ZipRecruiter salary data. Most workers in this role earn between $98,000.00 and $153,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Lead Cybersecurity Analyst, and why are they important?

To excel as a Lead Cybersecurity Analyst, you need deep expertise in information security, risk assessment, and threat mitigation, often supported by a relevant degree and industry certifications like CISSP or CISM. Familiarity with security information and event management (SIEM) tools, vulnerability scanners, and incident response frameworks is crucial. Strong leadership, analytical thinking, and effective communication skills help drive team performance and stakeholder collaboration. These competencies are vital to proactively defend organizational assets and ensure robust cybersecurity posture in a constantly evolving threat landscape.

Can you make $500,000 a year in cyber security?

Lead cybersecurity analysts and senior security professionals with extensive experience, advanced certifications, and specialized skills can potentially earn $500,000 or more annually, especially in high-demand industries or senior executive roles. Achieving this level often requires a combination of technical expertise, leadership responsibilities, and strategic oversight, along with working in organizations that offer high compensation packages.

How much do top cyber security analysts make?

Top cybersecurity analysts can earn six-figure salaries, often exceeding $100,000 annually, especially with advanced certifications like CISSP or CISM and extensive experience. Senior roles or positions in high-demand industries may see salaries reaching $150,000 or more.

What does a Lead Cybersecurity Analyst do?

A Lead Cybersecurity Analyst oversees an organization’s cybersecurity operations, managing teams that protect information systems from cyber threats. They are responsible for developing security policies, monitoring networks for suspicious activity, and responding to security breaches. Additionally, they often conduct risk assessments, ensure compliance with regulations, and guide the implementation of security protocols. Their leadership ensures the organization is proactive and resilient against evolving cyber risks.

What is L1 L2 L3 SOC analyst?

A Lead Cybersecurity Analyst working in a Security Operations Center (SOC) typically progresses through levels: L1 analysts handle initial threat detection and monitoring, L2 analysts perform deeper analysis and incident response, and L3 analysts are senior experts responsible for complex investigations and threat mitigation. These levels reflect increasing expertise, responsibility, and technical skills, often requiring certifications like CISSP or GIAC. The structure helps organizations efficiently manage security incidents and develop analyst skills over time.

How does a Lead Cybersecurity Analyst typically collaborate with other departments to strengthen organizational security?

A Lead Cybersecurity Analyst often works closely with IT, legal, compliance, and business operations teams to develop and implement security policies and incident response plans. They coordinate regular security assessments, share threat intelligence, and provide guidance on best practices to ensure all departments are aligned in mitigating cyber risks. This cross-functional collaboration is essential for proactively addressing vulnerabilities and ensuring the organization's data assets are protected. Effective communication and relationship-building are key aspects of this role, as it requires translating technical risks into actionable business strategies.

What is the difference between Lead Cybersecurity Analyst vs Cybersecurity Analyst?

AspectLead Cybersecurity AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CEH, CISSP (preferred but not always required)
Work EnvironmentLeads security projects, manages teams, develops security strategiesMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageUsed in organizations with security teams, often in mid to large companiesCommon entry to mid-level role across various industries

The main difference between a Lead Cybersecurity Analyst and a Cybersecurity Analyst is the level of responsibility. The Lead typically manages security initiatives and teams, while the Analyst focuses on monitoring and implementing security measures. Both roles require similar certifications, but the Lead has more leadership duties and strategic involvement.

Can you make $200,000 in cyber security?

Lead cybersecurity analysts with extensive experience, advanced certifications, and specialized skills can earn salaries approaching or exceeding $200,000 annually, especially in high-demand industries or senior roles. Factors such as location, company size, and technical expertise influence earning potential, and some professionals supplement income through consulting or leadership positions.
More about Lead Cybersecurity Analyst jobs
What states have the most Lead Cybersecurity Analyst jobs? States with the most job openings for Lead Cybersecurity Analyst jobs include:
Infographic showing various Lead Cybersecurity Analyst job openings in the United States as of July 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $123,849 per year, or $59.5 per hour.

Senior Cyber Security Analyst

Crowned Grace, Inc

Washington, DC • On-site

$54.32 - $60.09/hr

Full-time

Posted 14 days ago


Job description

Senior Cyber Security Analyst

***Offer Contingent Upon Contract Award***

Crowned Grace International seeks a Senior Cyber Security Analyst for the DC Water Department of Information Technology (DIT) to strengthen the security posture of the Authority's enterprise information technology (IT) and operational technology (OT) environments. As one of the largest water and wastewater utilities in the United States, DC Water operates critical infrastructure that must remain resilient against evolving cyber threats while meeting corporate, industry, and regulatory security requirements.

The Senior Cyber Security Analyst serves as a hands-on senior contributor and technical advisor, leading threat monitoring, incident response, vulnerability management, and security engineering activities across on-premises, cloud, and hybrid platforms. The role works closely with the network infrastructure, systems administration, database, and SCADA/Process Control System (PCS) teams to ensure that security controls are designed, implemented, and maintained in alignment with DC Water's security architecture and applicable regulatory standards.

Key Responsibilities

• Monitor, triage, and investigate security events and alerts across the enterprise using SIEM, endpoint detection and response (EDR), intrusion detection/prevention systems (IDS/IPS), and related security tooling.

• Lead and coordinate incident response activities, including detection, containment, eradication, recovery, and post-incident root cause analysis, and produce clear incident documentation and lessons-learned reports.

• Perform proactive threat hunting and analysis of indicators of compromise, correlating threat intelligence with internal telemetry to identify and mitigate emerging risks.

• Plan and execute vulnerability management activities, including scanning, risk-based prioritization, remediation tracking, and validation across servers, endpoints, network devices, and applications.

• Design, implement, and tune security controls across hybrid environments, including firewalls, VPN, network segmentation, and multi-DMZ architectures, IDS/IPS, and secure remote access.

• Administer and improve identity, access, and security controls across on-premises and cloud environments (Active Directory and Azure Entra ID/IAM), including multi-factor authentication, conditional access, least-privilege enforcement, and security hardening.

• Coordinate with the SCADA/PCS engineering team to ensure IT, PCS, and SCADA security architectures are aligned, and support the segmentation, monitoring, and protection of the Authority's operational technology environment.

• Conduct security assessments, configuration reviews, and control gap analyses against recognized frameworks, and recommend risk-based remediation.

• Support security governance, risk, and compliance activities, ensuring operation in compliance with current and future corporate, industry, and regulatory standards (e.g., NIST Cybersecurity Framework, AWIA, HIPAA, and other evolving cybersecurity protocols).

• Develop, update, and maintain security documentation, standard operating procedures, runbooks, hardening baselines, and asset inventories.

• Provide Tier 3 security engineering support and advanced problem resolution for critical security issues escalated by IT Operations and other teams, and mentor junior analysts as a subject matter expert.

• Partner with infrastructure, systems, database, and application teams to embed security into system design, changes, upgrades, and cloud migration initiatives, following established change management protocols.

Required Qualifications

• Experience: Minimum of seven (7) years of progressive experience in cyber security, information assurance, or information security, including hands-on incident response, vulnerability management, and security operations.

• Education: Bachelor's Degree in Computer Science, Information Technology, Cyber Security, or a related field (equivalent experience may be considered).

• Certification: Certified Information Systems Security Professional (CISSP) required.

• Technical Depth: Demonstrated expertise with SIEM and security monitoring tools, EDR, IDS/IPS, and firewall technologies, including experience configuring and managing stateful and application-proxy firewalls in multi-DMZ environments.

• Networking & Access: Strong understanding of enterprise/hybrid networking, secure authentication (RADIUS, TACACS+), IPSEC and SSL VPN, and identity and access management across Active Directory and Azure Entra ID.

• Frameworks: Working knowledge of security frameworks and regulatory requirements, such as the NIST Cybersecurity Framework, and experience applying risk-based security controls.

• Communication: Excellent written and oral communication skills, with the ability to document findings and present risk to both technical and non-technical stakeholders.

Preferred Qualifications

• Experience securing operational technology (OT), SCADA, or industrial control system (ICS) environments, ideally at a water, wastewater, or other critical-infrastructure utility.

• Additional certifications such as CISM, CCSP, GIAC (e.g., GCIH, GCIA, GICSP), CEH, or a cloud security certification (Azure/AWS).

• Hands-on experience with Cisco security platforms (Cisco ISE, Catalyst Center), Checkpoint firewalls, and Microsoft/Azure security tooling.

• Familiarity with virtualization and container security (VMware vSphere, Windows Server, Docker/Kubernetes) and cloud/hybrid security architecture.

• Experience supporting disaster recovery and business continuity planning and testing.

• Scripting or automation skills (e.g., Python, PowerShell) to support detection, response, and reporting.

DC Water Technical Environment

The selected candidate will operate within a diverse enterprise environment that includes, but is not limited to, the following technologies:

• Network & Security: Cisco switches, routers, firewalls, Cisco ISE and Catalyst Center; Checkpoint firewalls; IDS/IPS; IPSEC/SSL VPN; RADIUS and TACACS+.

• Identity & Cloud: Active Directory, Azure Entra ID/IAM, Microsoft Azure, and hybrid/multi-cloud architecture.

• Compute & Virtualization: VMware vSphere, Windows Server, and Docker/Kubernetes.

• Data & Applications: Oracle and MS SQL databases; Oracle ERP, SAP ISU, IBM Maximo, ESRI GIS, SharePoint, and various custom .NET/C#/Python/Java systems.

• Operational Technology: SCADA and Process Control Systems, including Modicon PLC platforms, requiring close coordination on IT/OT security architecture.

Work Conditions & Additional Information

• This is a hybrid assignment requiring three (3) days onsite per week at Blue Plains or Headquarters (HQO) and two (2) days remote.

• Initial assignment length is six (6) months, with the possibility of extension based on business needs and performance.

• The selected candidate may be subject to background and security screening consistent with DC Water's requirements for access to critical infrastructure systems.

• DC Water will provision the necessary IT equipment for the selected candidate.

• DC Water will own any work, product, or deliverable produced during the assignment.


  • Must be able to pass government background investigation.