> Markdown version of [/jobs/ext/2295860-senior-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/2295860-senior-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Analyst - **Company:** QUANTUM SKY LLC - **Location:** Oceanside, CA, United States - **Experience:** Expert - **Salary:** $140,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Cyber Security, Local Security Policy, NIPRNet, Red Team (Cyber Security), Secure Coding, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3369522981&tx=KP8585FFR&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role Required: * US. citizenship. * DoD 8140 /cyberspace workforce qualification: IAT Level III or applicable CSSP/DCWF role. * Certification: CISSP, CEH, or other Government-accepted certification meeting the required 8140 work role. * 3+ years conducting DoW network assessments. * 5+ years performing secure code reviews. * 2+ years performing penetration testing. * 3+ years performing security evaluations. * 1+ year experience supporting DoW expeditionary network environments of similar size and complexity to the customer's Cyberspace Environment * Ability to meet current DoW, DoN, and USMC privileged-access, background investigation, training, and least-privilege requirements. Desired: * Garrison-to-tactical architecture experience; OCONUS execution experience; strong written communication for AO-level risk reporting. ## Description Quantum Sky is searching for a Senior Information Security Analyst with Red Team experience to support a DoW customer at Camp Pendleton. This candidate will provide senior-level cybersecurity assessment and continuous monitoring support for customer's systems and networks, with emphasis on OCONUS execution, security control effectiveness, vulnerability analysis, configuration monitoring, and technically defensible risk recommendations., * Lead or execute security control assessments and continuous monitoring activities for assigned systems and portfolios. * Analyze vulnerability scans, IAVMs, configuration baselines, security-control evidence, and remediation status to determine control effectiveness and mission risk. * Conduct or support authorized secure code review, penetration testing, and security evaluation activities and document technical results. * Develop assessment plans, findings, final reports, vulnerability and drift reporting, POA&M recommendations, and quarterly AO reporting inputs. * Coordinate with system owners and site stakeholders to deconflict scan windows, testing, maintenance periods, and field-training schedules. * Validate remediation actions, conduct retests, and ensure findings are evidence-traceable and mapped to governing controls. * Mentor/support Journeyman-level personnel as assigned and help enforce technical and quality standards. * Maintain required certifications, clearance, privileged-access status, and training., * Complete and maintain required initial/annual NIPRNET account training, including Cyber Awareness, OPSEC, and Privacy/PII. * Complete applicable SIPRNET training, including Derivative Classification and local SIPRNET user agreements; NATO Secret briefing if mission-required. * Complete annual CUI training and local installation/security briefings. * Maintain required CAC/DBIDS/site-access credentials and comply with DISS visit request requirements. * Maintain valid passport/visa/driver documentation when required by the duty location or travel assignment. Performance Expectations: * Produce complete, accurate, evidence-traceable assessment products in accordance with the SOW, approved QCP, Government formats, and established delivery timelines. * Escalate critical/high or mission-impacting issues through Quantum Sky program leadership in accordance with the approved governance and escalation process. * Protect classified information, CUI, Government property, credentials, and assessment data in accordance with contract and local security requirements. * Operate within the non-personal-services construct; Government personnel provide requirements, priorities, surveillance, and acceptance, while Quantum Sky management directs contractor personnel. Certification: IAT Level III OR CSSP Analyst certification required (e.g. SecurityX, CISA, CISSP, CISA, CySA+) ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)