QinetiQ North America

Senior Cybersecurity SME/Security Control Assessor

QinetiQ North America$150K — $185K *
Aerospace & Defense
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret clearance with SCI and SAP accesses.
  • At least 12 years of experience in IT and cybersecurity engineering, with increasing responsibilities.
  • Proven expertise in multi-domain operations with SAP and SCI Systems, including Cloud and PIT environments.
  • Active Information Assurance certification for IAT Level III or IAM Level III (e.g., CISSP, CISM).
  • Experience in defense innovation environments, particularly with rapid prototyping and Platform IT systems.

Responsibilities

  • Participate in technical reviews to ensure security is integrated from the outset.
  • Advise SCO teams on automated security testing within Agile frameworks.
  • Conduct threat modeling to preemptively address potential attacks during design phases.
  • Perform in-depth technical validations of vulnerability assessments and correlate them with operational risks.
  • Mastery of RMF policies to guide risk decisions in compliance shortfalls.
  • Assess security performance across varied architectures, including satellite and communication networks.
  • Lead Zero Trust architecture deployments in the SCO portfolio.

Benefits

  • Engagement with cutting-edge cybersecurity technologies and multi-domain systems.
  • Opportunities for continuous learning and professional development in advanced threat environments.
  • Collaboration with key stakeholders in the defense innovation ecosystem.
  • Active participation in shaping future cybersecurity measures against next-gen threats.
Full Job Description
Position Overview

QinetiQ US is seeking a highly technical Senior Cybersecurity Subject Matter Expert (SME) and Security Control Assessor (SCA). This role is explicitly designed to transcend traditional compliance validation.  The ideal candidate possesses deep technical engineering and integration experience, enabling them to dissect, analyze, and secure highly complex, multi-domain systems. Acting as a trusted technical adviser to the Authorizing Official (AO) and directly supports the CIO of SCO. The candidate will provide continuous risk determinations, influence system architecture, and ensure that cutting-edge capabilities are developed with intrinsic security that aligns with aggressive agency timelines, modern threat landscapes, and advanced operational requirements.

Responsibilities

Strategic Advisement & Lifecycle Integration

  • Engineering Technical Reviews: Actively participate in System Requirements Reviews (SRR), Preliminary Design Reviews (PDR), and Critical Design Reviews (CDR) to ensure security is baked in, rather than bolted on.
  • DevSecOps Alignment: Guide SCO project teams in integrating automated security testing (SAST/DAST) and continuous compliance monitoring into Agile development pipelines where appropriate.
  • Threat Modeling: Conduct system-level threat modeling during the design phase to identify potential attack vectors and recommend architectural mitigations before code is written or hardware is procured.

Advanced Assessment & Risk Determination

  • Technical Validation: Move beyond paperwork by conducting deep technical reviews of vulnerability scans (e.g., ACAS/Nessus), STIG checklists, and penetration testing reports. Correlate technical findings to actual operational risk.
  • RMF Execution: Demonstrate mastery of Federal, DoD, and Intelligence Community (IC) RMF policies (NIST SP 800-53 Rev 5, CNSSI 1253, DoD 8510.01, ICD 503). Assist the government AO by translating complex technical compliance shortfalls into actionable, mission-contextualized risk decisions.
  • Diverse Architectures: Evaluate the security performance, integrity, and residual risk of varied environments, including Platform Information Technology (PIT), hardware/software systems, communication networks, and satellite control systems, etc.

Zero Trust & Next-Generation Architecture

  • Zero Trust Implementation: Drive the adoption of DoD Zero Trust architectural pillars (User, Device, Network, Application/Workload, Data, Visibility/Analytics, and Automation/Orchestration) across all SCO portfolios.
  • Cross Domain Solutions (CDS): Provide specialized expertise in designing, evaluating, and implementing CDS technologies. This includes complex enterprise deployments in classified compartmentalized environments and point-to-point solutions for isolated, tactical IT architectures.
  • Emerging Technology Evaluation: Continuously monitor state-of-the-art technologies (e.g., AI/ML, edge computing, quantum-resistant cryptography) and the evolving threat landscape to ensure SCO systems anticipate and mitigate next-generation threats.

Stakeholder Engagement & Liaison

  • Technical Translation: Facilitate seamless communication with SCO Portfolio technical SMEs, effectively translating AO directives to engineers and engineering challenges to the AO.
  • Community Representation: Serve as a key liaison between the Defense Industrial Base (DIB), government cybersecurity entities, security assessment organizations, and Special Access Program (SAP) IT working groups to maintain alignment with the broader defense innovation ecosystem.
Required Qualifications
  • Active Top Secret clearance with SCI and SAP accesses. #qinetiqclearedjob
  • Minimum of twelve (12) years of demonstrated experience in IT, cybersecurity engineering, and Assessment & Authorization (A&A), with increasing responsibility.
  • Significant and proven multi-domain experience with SAP and SCI Systems, to include PIT, Cloud environments, Cross Domain Solutions.
  • Active baseline certification equivalent to DoD 8140.01 / 8570.01-M Information Assurance Workforce Improvement Program (IA WIP) for IAT Level III or IAM Level III (e.g., CISSP, CISM, GSLC, CASP+ CE).
  • Direct experience working within the defense innovation ecosphere, specifically with rapid prototyping, test environments, and Platform IT (PIT) systems.
Preferred Qualifications
  • Proven hands-on technical experience working as a systems integrator or cybersecurity engineer, specifically with enterprise networks, cloud computing systems, and/or all-domain platform IT architectures.
  • Master's Degree in Engineering, IT or Cybersecurity
Pay Transparency

The salary range for this role is $150,000 - $185,000 USD. The salary range provided is a good faith estimate representative of all experience levels. QinetiQ US considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidates work experience, location, education/training, and key skills.

About QinetiQ North America

QinetiQ North America (QNA) is a subsidiary of QinetiQ Group plc, a British multinational defense technology company. QNA provides technology solutions and services to the United States government and commercial customers. The company's offerings include unmanned systems, cybersecurity solutions, engineering services, and more. QNA has over 6000 employees and is headquartered in McLean, Virginia.
Learn more about QinetiQ North America
Size
6,000 employees
Industry
Founded
2005

Similar Jobs

More Jobs at QinetiQ North America

More Aerospace & Defense Jobs

Find similar Senior Cybersecurity SME/Security Control Assessor jobs: