Information Security Analyst - SME

QUANTUM SKY LLC
Quantico, VA, United States
3 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$155,000.0 - $165,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Local Security Policy NIPRNet Red Team (Cyber Security) Secure Coding SC Clearance Plan of Action and Milestones Vulnerability Analysis

Job description

Quantum Sky is searching for a Information Security Analyst - SME with Red Team experience to support a DoW customer at Quantico. This candidate will serve as a senior cybersecurity subject matter expert for complex RMF Step 6 assessments, advanced vulnerability analysis, security evaluation, and mission-impact risk assessment for assigned East Coast and tactical portfolios., * Lead complex security control assessments and provide expert interpretation of RMF, NIST, DoW, DoN, and USMC cybersecurity requirements.

  • Perform advanced vulnerability analysis, security evaluation, secure code review, and authorized penetration testing; assess attack paths, exploitability, exposure, and mission consequences.
  • Review assessment evidence and findings for technical sufficiency, reproducibility, and control mapping before release.
  • Develop technically feasible mitigation strategies, POA&M recommendations, compensating-control options, and remediation validation approaches.
  • Lead or support assessment planning, rules-of-engagement development, technical adjudication, exit briefs, and final report development.
  • Support quarterly AO control-effectiveness reporting and translate technical conditions into decision-quality risk statements and recommendations.
  • Provide technical leadership, mentoring, and reach-back support to Senior and Journeyman analysts across assigned portfolios.
  • Contribute to ConMon SOP updates, lessons learned, evidence standards, and continuous-improvement activities., * Complete and maintain required initial/annual NIPRNET account training, including Cyber Awareness, OPSEC, and Privacy/PII.
  • Complete applicable SIPRNET training, including Derivative Classification and local SIPRNET user agreements; NATO Secret briefing if mission-required.
  • Complete annual CUI training and local installation/security briefings.
  • Maintain required CAC/DBIDS/site-access credentials and comply with DISS visit request requirements.
  • Maintain valid passport/visa/driver documentation when required by the duty location or travel assignment.

Performance Expectations:

  • Produce complete, accurate, evidence-traceable assessment products in accordance with the SOW, approved QCP, Government formats, and established delivery timelines.
  • Escalate critical/high or mission-impacting issues through Quantum Sky program leadership in accordance with the approved governance and escalation process.
  • Protect classified information, CUI, Government property, credentials, and assessment data in accordance with contract and local security requirements.
  • Operate within the non-personal-services construct; Government personnel provide requirements, priorities, surveillance, and acceptance, while Quantum Sky management directs contractor personnel.

Requirements

Required:

  • US. citizenship.
  • DoD 8140 /cyberspace workforce qualification: IAT Level III or applicable CSSP/DCWF role.
  • 3+ years conducting DoW network assessments.
  • 5+ years performing secure code reviews.
  • 2+ years performing penetration testing.
  • 3+ years performing security evaluations.
  • 1+ year experience supporting DoW expeditionary network environments of similar size and complexity to the customer’s Cyberspace Environment
  • Ability to meet current DoW, DoN, and USMC privileged-access, background investigation, training, and least-privilege requirements.

Desired:

  • Deep RMF/NIST 800-53A experience; advanced penetration testing/vulnerability analysis; customer’s tactical/expeditionary experience; strong AO-level communication., Clearance: Secret clearance required with the ability to upgrade to a Top Secret

Certification: IAT Level III OR IASAE II/III certification required (e.g. SecurityX, CISA, CISSP)

Benefits & conditions

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $155,000-$165,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range., * Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

About the company

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don’t follow the map. We draw it.

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

2:47 min

Securing code provenance with digital identity signatures

Marcus Ross Marcus Ross · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all