> Markdown version of [/jobs/ext/2227768-nqv-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/2227768-nqv-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # NQV Information Security Analyst - **Company:** Professional Software Engineering, Inc. - **Location:** Portsmouth, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Security Content Automation Protocol, Firewalls (Computer Science), Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 25, 2026 - **Apply:** https://www.wayup.com/i-j-NQV-Information-Security-Analyst-PROSOFT-478087806549454/ ## About the Role Minimum of seven (7) years of experience in CS/A&A analysis support in IA controls analysis, conducting risk assessments, risk mitigation analysis, or developing plans. KSAs include: * Qualified and registered as a Navy Qualified Validator (NQV) * Expert knowledge of and experience with CS/RMF requirements as defined by Public Laws, National, DoD, and DON [e.g., Federal Information Security Management Act (FISMA), DoDD 8100.02, DODI 8500.01, DoDI 8520, DoDI 8530, DoDI 8531, SECNAV 5239 Series and OPNAV 5239 Series, NIST Special Publications Series 800, etc.] * Expert and Mastery levels with institutional knowledge on the mission critical procedures, systems, and processes, as they pertain to Information Technology and Cyber Security requirements. * Experience in certifying and accrediting DON information systems and networks, as well as Platform IT. * Expert knowledge and experience with the requirements outlined in OPNAVINST N9210.3 Safeguarding Naval Nuclear Propulsion Information Education: Bachelor's degree in an IT related discipline OR Level II Certification (Security+ or better) AND a minimum of seven (7) years of experience. Certifications: * Active Security + CE or higher * Active NQV ## Description The Information Security Analyst (NQV) shall work to support DoD Risk Management Framework (RMF) and validate Network and System assets. They will be responsible to: a. Follow Accreditation & Authorization (A&A) process and standards. b. Perform System / network vulnerability analysis. c. Conduct Risk assessment and risk mitigation analysis. d. Perform Security Test and Evaluation (ST&E) processing. e. Validate Security Technical Implementation Guide (STIG) Processing. Use automated STIG processing tools [e.g., Security Content Automation Protocol (SCAP), Evaluate STIG, STIGMAN, EMASSter]. Use of Enterprise Mission Assurance Support Services (eMASS) and similar RMF repositories. f. Setup and execute A&A Business Rules, Standard Operating Procedures (SOP)s, Concept of Operations (CONOP)s, and Plans. g. Perform Contingency planning, training and testing. h. Establish/interrupt Firewall Policy. i. Identify Interrupt, register Ports & Protocols. j. Review Hardware / Software, network boundaries, flow diagrams and technical drawings. k. Identify interrupting information in the system baseline configuration in VRAM by uploading vulnerability scan of a representative baseline system. l. Advise on the proper method to mitigate vulnerabilities. m. Produce executive documents, reports, project plans and plan of action and milestones (POA&M). ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) ## Related Articles - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)