> Markdown version of [/jobs/ext/2153674-cybersecurity-information-assurance-lead](https://www.wearedevelopers.com/jobs/ext/2153674-cybersecurity-information-assurance-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity / Information Assurance Lead - **Company:** QUANTUM SKY LLC - **Location:** Arlington, VA, United States - **Experience:** Expert - **Salary:** $140,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cloud Computing, Cyber Security, Data Control, Data Security, Identity and Access Management, Zero Trust Network Access, Security Information and Event Management, Software Technical Review, Software Vulnerability Management, Information Security Management System, Cisco Discovery Protocol, Virtual Environment, Patch Management, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 20, 2026 - **Apply:** https://dejobs.org/x/x/5B395CE6F9C14F52987502900F9A84C1/job/ ## About the Role Required: * Education: MA/MS; substitution allowed with BA/BS and 12+ years of relevant experience. * Certification: DoD 8140/8570-aligned IAM Level III (e.g., CISSP, CISM, GSLC) appropriate to the position, subject to solicitation requirements. * Experience: 10+ years leading information security, cybersecurity, or information assurance programs in complex enterprise environments, including DoD RMF, NIST SP 800-53, continuous monitoring, vulnerability management, and ATO support. * Operations & leadership: demonstrated ability to lead cybersecurity staff and coordinate with ISSMs, ISSOs, system owners, engineers, and authorizing officials; experience embedding security across the lifecycle and reviewing architectures and changes for security impacts. * Zero Trust implementation spanning identity, device, network/environment, application/workload, and data controls. Desired: * SIEM operations (e.g., LogRhythm) and advanced incident response playbooks integrating threat intelligence. * ATO leadership for hybrid/on-prem and Cloud IL-5 environments with eMASS body of evidence management. * Participation in CyWGs, CTTs, CVPAs, and adversarial assessments; delivering actionable findings and remediation guidance. Clearance: * Top Secret at time of submission (SCI eligibility may be required). ## Description Quantum Sky is searching for a Cybersecurity / Information Assurance Lead that serves as the senior authority for enterprise cybersecurity and information assurance across the Joint Virtual Environment (JVE) in support of the F-35 Lightning II Joint Program Office (JPO). This role owns the cybersecurity strategy and governance for on-premises and Azure IL-5 environments, leads Risk Management Framework (RMF) execution and assessment & authorization (A&A) artifacts, directs continuous monitoring (ACAS, STIGs, ESS), and orchestrates incident response to ensure confidentiality, integrity, authenticity, non-repudiation, and availability of mission services. Onsite presence in Arlington, VA is required; travel may be necessary to support CONUS/OCONUS Tier sites., * Govern cybersecurity governance and policy: develop, maintain, and annually update security policies, standards, controls, and compliance aligned to DoDI 8500.01, DoDI 8510.01 (RMF), NIST SP 800-53, CNSS, CCRI criteria, and program directives. * Lead RMF and A&A lifecycle: coordinate system categorization, control selection, implementation, assessment, and authorization; produce and maintain the System Security Plan (SSP), Security Assessment Report (SAR), Security Control Traceability Matrix (SCTM), and Plan of Action and Milestones (POA&M) in eMASS. * Own continuous monitoring program: ensure monthly ACAS vulnerability scanning ( 98% scan rate), quarterly STIG reviews, and Endpoint Security Services (ESS) scores 95% at least 90% of the time; track compliance on a weekly Security Dashboard ( 75% update compliance). * Direct vulnerability and patch management: drive remediation governance for IAVA/IAVB, benchmark compliance, and OS STIG settings; ensure timely reporting and closure across all assets. * Oversee security operations and incident response: ingest SIEM telemetry, lead detection, triage, containment, eradication, and recovery per the OCIO incident response plan; coordinate with CSSP and JFHQ-DoDIN when thresholds are not met. * Embed security into engineering: review architectures, designs, and changes for security impacts; serve as primary liaison between Enterprise Architecture and Systems SecurityEngineering (ISSE/SSE) to integrate controls through the SE process. * Support Technical Design Reviews: provide personnel to participate in TDRs/SETRs/ISSEWGs; deliver Cyber Engineering Design Review Reports within 5 business days with risks, findings, and recommended actions. * Deliver capability security engineering: execute Common Cyber Modeling Process (or equivalent) and provide Cyber Engineering Capability Reports covering requirements and verification approaches for new capabilities. * Lead Zero Trust implementation: advance identity, device, network/environment, application/workload, and data security controls across JVE, coordinating configuration baselines with NOSC operations. * Champion security awareness and training: maintain 95% annual Cyber Awareness training compliance with certificates retrievable 100% of the time. * Provide reporting and governance to include Monthly Status Reports, POA&M status, vulnerability and eMASS summaries, and intrusion management reports in alignment with program cadence. Performance Metrics & Success Criteria: * Service Availability: Critical services 95% monthly uptime; less-critical services 90% during operational hours (excluding external outages). * Continuous Monitoring: ACAS scan rate 98% monthly; ESS 95% in all measured areas at least 90% of the time; STIG reviews conducted quarterly. * Risk Governance: POA&M updates weekly with quarterly artifact uploads in eMASS; Security Dashboard updated weekly meeting 75% update compliance (monthly measure). * Vulnerability Management: timely IAVM acknowledgments and closures; compliance tracked for OS STIG, software inventory patches, and benchmark adherence. * Quality & Reporting: accurate, complete, on-time deliverables per CDRLs; rapid corrective actions and open communications across COR/TPOC governance. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Your Code as a Crime Scene](https://www.wearedevelopers.com/videos/1342-your-code-as-a-crime-scene) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)