Information Security Analyst - SME

Tyto Athene

$155K — $165K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • US citizenship required.
  • DoD 8140 qualification: IAT Level III or relevant CSSP/DCWF role.
  • Certification: CISSP, CEH, or equivalent Government-accepted certification.
  • 3+ years of DoW network assessments experience.
  • 5+ years in secure code reviews.
  • 2+ years in penetration testing.
  • 3+ years in security evaluations.
  • 1+ year in DoW expeditionary network environments.

Responsibilities

  • Lead security control assessments and interpret RMF, NIST, and USMC cybersecurity requirements.
  • Conduct advanced vulnerability analysis and penetration testing; assess attack paths and mission impact.
  • Review findings for technical accuracy and sufficiency before dissemination.
  • Develop mitigation strategies and remediation validation approaches.
  • Support assessment planning and develop technical reports.
  • Contribute to quarterly control effectiveness reporting and risk management.
  • Mentor junior analysts and support their technical needs.
  • Update operational procedures and promote continuous improvement.

Benefits

  • Health/Dental/Vision insurance.
  • 401(k) match.
  • Paid time off (PTO).
  • Short-term and long-term disability insurance.
  • Life insurance.
  • Referral bonuses.
  • Professional development reimbursement.
  • Parental leave.
Full Job Description
Description

Quantum Sky is searching for a Information Security Analyst - SME with Red Team experience to support a DoW customer at Quantico. This candidate will serve as a senior cybersecurity subject matter expert for complex RMF Step 6 assessments, advanced vulnerability analysis, security evaluation, and mission-impact risk assessment for assigned East Coast and tactical portfolios.

 

Responsibilities:

  • Lead complex security control assessments and provide expert interpretation of RMF, NIST, DoW, DoN, and USMC cybersecurity requirements.
  • Perform advanced vulnerability analysis, security evaluation, secure code review, and authorized penetration testing; assess attack paths, exploitability, exposure, and mission consequences.
  • Review assessment evidence and findings for technical sufficiency, reproducibility, and control mapping before release.
  • Develop technically feasible mitigation strategies, POA&M recommendations, compensating-control options, and remediation validation approaches.
  • Lead or support assessment planning, rules-of-engagement development, technical adjudication, exit briefs, and final report development.
  • Support quarterly AO control-effectiveness reporting and translate technical conditions into decision-quality risk statements and recommendations.
  • Provide technical leadership, mentoring, and reach-back support to Senior and Journeyman analysts across assigned portfolios.
  • Contribute to ConMon SOP updates, lessons learned, evidence standards, and continuous-improvement activities.
Qualifications Required:
  • US. citizenship.
  • DoD 8140 /cyberspace workforce qualification: IAT Level III or applicable CSSP/DCWF role.
  • Certification: CISSP, CEH, or other Government-accepted certification meeting the required 8140 work role.
  • 3+ years conducting DoW network assessments.
  • 5+ years performing secure code reviews.
  • 2+ years performing penetration testing.
  • 3+ years performing security evaluations.
  • 1+ year experience supporting DoW expeditionary network environments of similar size and complexity to the customer's Cyberspace Environment
  • Ability to meet current DoW, DoN, and USMC privileged-access, background investigation, training, and least-privilege requirements.
Desired:
  • Deep RMF/NIST 800-53A experience; advanced penetration testing/vulnerability analysis; customer's tactical/expeditionary experience; strong AO-level communication.
Required Training / Administrative Readiness:
  • Complete and maintain required initial/annual NIPRNET account training, including Cyber Awareness, OPSEC, and Privacy/PII.
  • Complete applicable SIPRNET training, including Derivative Classification and local SIPRNET user agreements; NATO Secret briefing if mission-required.
  • Complete annual CUI training and local installation/security briefings.
  • Maintain required CAC/DBIDS/site-access credentials and comply with DISS visit request requirements.
  • Maintain valid passport/visa/driver documentation when required by the duty location or travel assignment.
Performance Expectations:
  • Produce complete, accurate, evidence-traceable assessment products in accordance with the SOW, approved QCP, Government formats, and established delivery timelines.
  • Escalate critical/high or mission-impacting issues through Quantum Sky program leadership in accordance with the approved governance and escalation process.
  • Protect classified information, CUI, Government property, credentials, and assessment data in accordance with contract and local security requirements.
  • Operate within the non-personal-services construct; Government personnel provide requirements, priorities, surveillance, and acceptance, while Quantum Sky management directs contractor personnel.

Clearance: Secret clearance required with the ability to upgrade to a Top Secret

 

Location: Quantico, VA

About Tyto Athene

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $155,000-$165,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

 

Similar Jobs

More Jobs at Tyto Athene

More Information Technology Jobs

Find similar Information Security Analyst - SME jobs: