Jobs · Information Technology · Virginia

Information Security Analyst - SME

Quantum Sky · Quantico, VA · Today
On-siteInformation TechnologyFull-time

Responsibilities

  • Lead complex security control assessments and provide expert interpretation of RMF, NIST, DoW, DoN, and USMC cybersecurity requirements.
  • Perform advanced vulnerability analysis, security evaluation, secure code review, and authorized penetration testing; assess attack paths, exploitability, exposure, and mission consequences.
  • Review assessment evidence and findings for technical sufficiency, reproducibility, and control mapping before release.
  • Develop technically feasible mitigation strategies, POA&M recommendations, compensating-control options, and remediation validation approaches.
  • Lead or support assessment planning, rules-of-engagement development, technical adjudication, exit briefs, and final report development.
  • Support quarterly AO control-effectiveness reporting and translate technical conditions into decision-quality risk statements and recommendations.
  • Provide technical leadership, mentoring, and reach-back support to Senior and Journeyman analysts across assigned portfolios.
  • Contribute to ConMon SOP updates, lessons learned, evidence standards, and continuous-improvement activities.

Requirements

  • US citizenship.
  • DoD 8140 /cyberspace workforce qualification: IAT Level III or applicable CSSP/DCWF role.
  • Certification: CISSP, CEH, or other Government-accepted certification meeting the required 8140 work role.
  • 3+ years conducting DoW network assessments.
  • 5+ years performing secure code reviews.
  • 2+ years performing penetration testing.
  • 3+ years performing security evaluations.
  • 1+ year experience supporting DoW expeditionary network environments of similar size and complexity to the customer's Cyberspace Environment.
  • Ability to meet current DoW, DoN, and USMC privileged-access, background investigation, training, and least-privilege requirements.

Desired

  • Deep RMF/NIST 800-53A experience;
  • Advanced penetration testing/vulnerability analysis;
  • Customer's tactical/expeditionary experience;
  • Strong AO-level communication.

Performance Expectations

  • Produce complete, accurate, evidence-traceable assessment products in accordance with the SOW, approved QCP, Government formats, and established delivery timelines.
  • Escalate critical/high or mission-impacting issues through Quantum Sky program leadership in accordance with the approved governance and escalation process.
  • Protect classified information, CUI, Government property, credentials, and assessment data in accordance with contract and local security requirements.
  • Operate within the non-personal-services construct; Government personnel provide requirements, priorities, surveillance, and acceptance, while Quantum Sky management directs contractor personnel.

Similar jobs

Information Security Analyst

UChicago MedicineIllinois, United States· 1 mo ago
RemoteInformation Technologyapply on fa-etnf-saasfaprod1.fa.ocs.oraclecloud.com