> Markdown version of [/jobs/ext/2281105-information-security-analyst-journeyman](https://www.wearedevelopers.com/jobs/ext/2281105-information-security-analyst-journeyman). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - Journeyman - **Company:** QUANTUM SKY LLC - **Location:** United States - **Experience:** Experienced - **Salary:** $125,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Local Security Policy, NIPRNet, Red Team (Cyber Security), Secure Coding, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 28, 2026 - **Apply:** https://www.juju.com/job/00000000gpc321 ## About the Role Required: + US. citizenship. + DoD 8140 /cyberspace workforce qualification: IAT Level III or applicable CSSP/DCWF role. + Certification: CISSP, CEH, or other Government-accepted certification meeting the required 8140 work role. + 3+ years conducting DoW network assessments. + 5+ years performing secure code reviews. + 2+ years performing penetration testing. + 3+ years performing security evaluations. + 1+ year experience supporting DoW expeditionary network environments of similar size and complexity to the customer's Cyberspace Environment + Ability to meet current DoW, DoN, and USMC privileged-access, background investigation, training, and least-privilege requirements. Desired: + Experience with ACAS/Tenable, DISA STIGs, IAVM processes, RMF evidence development, POA&M workflows, and DoD/USMC network environments. ## Description Quantum Sky is searching for a **Information Security Analyst - Journeyman** with Red Team experience to support a DoW customer at Camp Smith. This candidate will provide hands-on continuous monitoring, vulnerability assessment, evidence management, remediation tracking, and security-control validation for assigned customer's systems and portfolios., + Support scheduled security control assessments and execute assessment procedures under approved scope and rules of engagement. + Perform monthly vulnerability scanning and IAVM-related analysis; review scan completeness, identify vulnerabilities, and track remediation status. + Collect, normalize, verify, and maintain cybersecurity evidence, including logs, configurations, scan results, POA&Ms, prior findings, and change records. + Monitor assigned systems for configuration drift and unauthorized changes and document results for senior review. + Assist in validating false positives/negatives, retesting remediated items, and mapping findings to applicable controls/frameworks. + Prepare technical inputs for assessment plans, findings, final reports, scan reports, configuration drift reports, and remediation trackers. + Support POA&M updates, evidence repositories, action tracking, and cross-site coordination., + Complete and maintain required initial/annual NIPRNET account training, including Cyber Awareness, OPSEC, and Privacy/PII. + Complete applicable SIPRNET training, including Derivative Classification and local SIPRNET user agreements; NATO Secret briefing if mission-required. + Complete annual CUI training and local installation/security briefings. + Maintain required CAC/DBIDS/site-access credentials and comply with DISS visit request requirements. + Maintain valid passport/visa/driver documentation when required by the duty location or travel assignment. Performance Expectations: + Produce complete, accurate, evidence-traceable assessment products in accordance with the SOW, approved QCP, Government formats, and established delivery timelines. + Escalate critical/high or mission-impacting issues through Quantum Sky program leadership in accordance with the approved governance and escalation process. + Protect classified information, CUI, Government property, credentials, and assessment data in accordance with contract and local security requirements. + Operate within the non-personal-services construct; Government personnel provide requirements, priorities, surveillance, and acceptance, while Quantum Sky management directs contractor personnel. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)