Cybersecurity / Information Assurance Lead

Tyto Athene

$140K — $175K *
Aerospace & Defense
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • MA/MS required, or BA/BS with 12+ years of relevant experience
  • DoD 8140/8570-aligned IAM Level III certification (CISSP, CISM, GSLC)
  • 10+ years leading information security in complex environments, including DoD RMF
  • Proven ability to lead cybersecurity teams and collaborate with various stakeholders
  • Experience with Zero Trust implementation across multiple areas.

Responsibilities

  • Develop and maintain cybersecurity governance and policies in line with relevant directives
  • Lead the Risk Management Framework (RMF) lifecycle, including system security documentation
  • Manage a continuous monitoring program to ensure high compliance rates
  • Oversee vulnerability and patch management processes
  • Direct security operations and incident response efforts according to established plans
  • Integrate security into the engineering process through architecture reviews
  • Support Technical Design Reviews with timely security assessments

Benefits

  • Health/Dental/Vision coverage
  • 401(k) match
  • Paid Time Off
  • Short and long-term disability and life insurance
  • Referral bonuses and professional development reimbursement
  • Parental leave
Full Job Description
Description

Quantum Sky is searching for a Cybersecurity / Information Assurance Lead that serves as the senior authority for enterprise cybersecurity and information assurance across the Joint Virtual Environment (JVE) in support of the F-35 Lightning II Joint Program Office (JPO).

 

This role owns the cybersecurity strategy and governance for on‑premises and Azure IL‑5 environments, leads Risk Management Framework (RMF) execution and assessment & authorization (A&A) artifacts, directs continuous monitoring (ACAS, STIGs, ESS), and orchestrates incident response to ensure confidentiality, integrity, authenticity, non‑repudiation, and availability of mission services. Onsite presence in Arlington, VA is required; travel may be necessary to support CONUS/OCONUS Tier sites. 

 

Responsibilities:

  • Govern cybersecurity governance and policy: develop, maintain, and annually update security policies, standards, controls, and compliance aligned to DoDI 8500.01, DoDI 8510.01 (RMF), NIST SP 800‑53, CNSS, CCRI criteria, and program directives.
  • Lead RMF and A&A lifecycle: coordinate system categorization, control selection, implementation, assessment, and authorization; produce and maintain the System Security Plan (SSP), Security Assessment Report (SAR), Security Control Traceability Matrix (SCTM), and Plan of Action and Milestones (POA&M) in eMASS.
  • Own continuous monitoring program: ensure monthly ACAS vulnerability scanning (6398% scan rate), quarterly STIG reviews, and Endpoint Security Services (ESS) scores 9595% at least 90% of the time; track compliance on a weekly Security Dashboard (7575% update compliance).
  • Direct vulnerability and patch management: drive remediation governance for IAVA/IAVB, benchmark compliance, and OS STIG settings; ensuretimelyreporting and closure across all assets.
  • Oversee security operations and incident response: ingest SIEM telemetry, lead detection, triage, containment, eradication, and recovery per the OCIO incident response plan; coordinate with CSSP and JFHQ0DoDIN when thresholds are not met.
  • Embed security into engineering: review architectures, designs, and changes for security impacts; serve as primary liaison between Enterprise Architecture and Systems Security Engineering (ISSE/SSE) to integrate controls through the SE process.
  • Support Technical Design Reviews: provide personnel toparticipatein TDRs/SETRs/ISSEWGs; deliver Cyber Engineering Design Review Reports within 5 business days with risks, findings, and recommended actions.
  • Deliver capability security engineering: execute Common Cyber Modeling Process (or equivalent) and provide Cyber Engineering Capability Reports covering requirements and verification approaches for new capabilities.
  • Lead Zero Trust implementation: advance identity, device, network/environment, application/workload, and data security controls across JVE, coordinating configuration baselines with NOSC operations.
  • Champion security awareness and training:maintain9595% annual Cyber Awareness training compliance with certificates retrievable 100% of the time.
  • Provide reporting and governanceto includeMonthly Status Reports, POA&M status, vulnerability andeMASSsummaries, and intrusion management reports in alignment with program cadence.

Performance Metrics & Success Criteria:

  • Service Availability: Critical services 9595% monthly uptime; less0critical services 9090% during operational hours (excluding external outages).
  • Continuous Monitoring: ACAS scan rate 9898% monthly; ESS 9595% in all measured areas at least 90% of the time; STIG reviews conducted quarterly.
  • Risk Governance: POA&M updates weekly with quarterly artifact uploads ineMASS; Security Dashboard updated weekly meeting 7575% update compliance (monthly measure).
  • Vulnerability Management:timelyIAVM acknowledgments and closures; compliance tracked for OS STIG, software inventory patches, and benchmark adherence.
  • Quality & Reporting:accurate, complete, on0time deliverables per CDRLs; rapid corrective actions and open communications across COR/TPOC governance.
Qualifications

Required:

  • Education: MA/MS; substitution allowed with BA/BS and 12+ years of relevant experience.
  • Certification: DoD 8140/85700aligned IAM Level III (e.g., CISSP, CISM, GSLC)appropriate tothe position, subject to solicitation requirements.
  • Experience: 10+ years leading information security, cybersecurity, or information assurance programs in complex enterprise environments, including DoD RMF, NIST SP 80053, continuous monitoring, vulnerability management, and ATO support.
  • Operations & leadership:demonstratedability to lead cybersecurity staff and coordinate with ISSMs, ISSOs, system owners, engineers, and authorizing officials; experience embedding security across the lifecycle and reviewing architectures and changes for security impacts.
  • Zero Trust implementation spanning identity, device, network/environment, application/workload, and data controls.

Desired:

  • SIEM operations (e.g., LogRhythm) and advanced incident response playbooks integrating threat intelligence.
  • ATO leadership for hybrid/on0prem and Cloud IL5 environments witheMASSbody of evidence management.
  • Participation inCyWGs, CTTs, CVPAs, and adversarial assessments; delivering actionable findings and remediation guidance.

Clearance:

  • Top Secret at time of submission (SCI eligibility may berequired).

Location:

  • Arlington, VA; onsite presence required with willingness to travel to CONUS/OCONUS Tier sites.

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between 140-175K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

 

Similar Jobs

More Jobs at Tyto Athene

More Aerospace & Defense Jobs

Find similar Cybersecurity / Information Assurance Lead jobs: