> Markdown version of [/jobs/ext/2294777-information-security-analyst-sme](https://www.wearedevelopers.com/jobs/ext/2294777-information-security-analyst-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - SME - **Company:** QUANTUM SKY LLC - **Location:** Quantico, VA, United States - **Salary:** $155,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Local Security Policy, NIPRNet, Red Team (Cyber Security), Secure Coding, SC Clearance, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9122124/information-security-analyst-sme ## About the Role Required: * US. citizenship. * DoD 8140 /cyberspace workforce qualification: IAT Level III or applicable CSSP/DCWF role. * 3+ years conducting DoW network assessments. * 5+ years performing secure code reviews. * 2+ years performing penetration testing. * 3+ years performing security evaluations. * 1+ year experience supporting DoW expeditionary network environments of similar size and complexity to the customer's Cyberspace Environment * Ability to meet current DoW, DoN, and USMC privileged-access, background investigation, training, and least-privilege requirements. Desired: * Deep RMF/NIST 800-53A experience; advanced penetration testing/vulnerability analysis; customer's tactical/expeditionary experience; strong AO-level communication., Clearance: Secret clearance required with the ability to upgrade to a Top Secret Certification: IAT Level III OR IASAE II/III certification required (e.g. SecurityX, CISA, CISSP) ## Description Quantum Sky is searching for a Information Security Analyst - SME with Red Team experience to support a DoW customer at Quantico. This candidate will serve as a senior cybersecurity subject matter expert for complex RMF Step 6 assessments, advanced vulnerability analysis, security evaluation, and mission-impact risk assessment for assigned East Coast and tactical portfolios., * Lead complex security control assessments and provide expert interpretation of RMF, NIST, DoW, DoN, and USMC cybersecurity requirements. * Perform advanced vulnerability analysis, security evaluation, secure code review, and authorized penetration testing; assess attack paths, exploitability, exposure, and mission consequences. * Review assessment evidence and findings for technical sufficiency, reproducibility, and control mapping before release. * Develop technically feasible mitigation strategies, POA&M recommendations, compensating-control options, and remediation validation approaches. * Lead or support assessment planning, rules-of-engagement development, technical adjudication, exit briefs, and final report development. * Support quarterly AO control-effectiveness reporting and translate technical conditions into decision-quality risk statements and recommendations. * Provide technical leadership, mentoring, and reach-back support to Senior and Journeyman analysts across assigned portfolios. * Contribute to ConMon SOP updates, lessons learned, evidence standards, and continuous-improvement activities., * Complete and maintain required initial/annual NIPRNET account training, including Cyber Awareness, OPSEC, and Privacy/PII. * Complete applicable SIPRNET training, including Derivative Classification and local SIPRNET user agreements; NATO Secret briefing if mission-required. * Complete annual CUI training and local installation/security briefings. * Maintain required CAC/DBIDS/site-access credentials and comply with DISS visit request requirements. * Maintain valid passport/visa/driver documentation when required by the duty location or travel assignment. Performance Expectations: * Produce complete, accurate, evidence-traceable assessment products in accordance with the SOW, approved QCP, Government formats, and established delivery timelines. * Escalate critical/high or mission-impacting issues through Quantum Sky program leadership in accordance with the approved governance and escalation process. * Protect classified information, CUI, Government property, credentials, and assessment data in accordance with contract and local security requirements. * Operate within the non-personal-services construct; Government personnel provide requirements, priorities, surveillance, and acceptance, while Quantum Sky management directs contractor personnel. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [GenAI Is a Junior Dev With Root Access](https://www.wearedevelopers.com/videos/100191-genai-is-a-junior-dev-with-root-access) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)