Cyber Security Analyst Level II

Tyto Athene, LLC

Northern (KY)

On-site

USD 75,000 - 85,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health/Dental/Vision
401(k) match
Paid Time Off
STD/LTD/Life Insurance
Referral Bonuses
Professional development reimbursement
Parental leave

Job summary

Quantum Sky is seeking a Cyber Security Analyst Level II to support AFRC IT services on a multi-year contract, providing SME for STIGs, POAMs, and CORA across NIPR/SIPR environments.

The role involves training system administrators, tracking STIG compliance, managing POAMs, and delivering monthly status reports while coordinating with stakeholders. Occasional travel and security clearances may apply.

Qualifications

  • Knowledge of computer systems and technology; operational support of networks, OS, Internet technologies, databases, and security infrastructure.
  • Cybersecurity controls, practices, procedures, and incident response program practices.

Responsibilities

  • Provide SME for STIG implementation and compliance.
  • Train system administrators on STIG processes.
  • Track STIG compliance across servers and infrastructure devices.
  • Coordinate STIG sampling with Communications Focal Point.
  • Review compliance checklists and set suspense dates.
  • Provide SME for POAMs in eMASS, DISPATCH, and CORA.
  • Manage POAM program for assigned base and remediation tracking.
  • Notify SAs and supervisors of open findings and suspense dates.
  • Provide monthly POAM status by severity (CAT I/II/III).
  • Lead cybersecurity applications for status, configuration, and indicators of compromise.
  • Support CORA/HSO reports and ESS reports; download weekly reports (DLP, Enhanced, Outdated Product, Rogues, Subnet Coverage).
  • Identify monthly fix actions required to meet CORA standards.
  • Report compliance status monthly.
  • Manage 38 CORA/HSO reports.
  • Configure and tailor policies for assigned bases.
  • Develop Master Software List for bases.

Skills

Network security architecture
Vulnerability scanning
Penetration testing tools
Network analysis tools

Education

Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Data Science, or Software Engineering

Tools

SCAP/ DISA tooling
eMASS experience

Job description

Description

Quantum Sky is searching for a Cyber Security Analyst Level II for a complex, multi-year contract to support the Air Force Reserve Command (AFRC) Information Technology (IT) Services. This role will provide Cyber Security/CORA support and Subject Matter Expertise (SME) for both NIPR and SIPR networks for AFRC host bases.

Responsibilities:

  • Will provide Subject Matter Expertise (SME) for process oversight in implementing/executing STIGS using automated and manual tools provided by DISA (ex. Security Content Automation Protocol – SCAP).
  • Will provide training to system administrators (SA) on STIG process as needed.
  • Track STIG compliance and quarterly updates for all servers and infrastructure devices and identify discrepancies to system administrators and A6 CORA Lead.
  • Works with Communications Focal Point to obtain quarterly STIGS random sampling (min ten percent (10%)) of physical and virtual workstations.
  • Review checklist for compliance and report findings of incomplete STIGS and set a suspense date for completion.
  • Will provide Subject Matter Expertise (SME) for process oversight in POAMs for Enterprise Mission Assurance Support Service (eMASS), DISPATCH, and STIGS for CORA.
  • Manages POAM program for assigned base\location by working with SAs to ensure a POAMs for all open findings from STIGS and vulnerability scans are created and updated every thirty (30) calendar days until remediation is complete.
  • Review and notify SAs and their immediate supervisor as well as the A6 CORA Lead for any incomplete or non-submitted POAMs.
  • Provide monthly status of open POAM status based on severity level (CAT I (Critical/High), CAT II (Medium) and CAT III (Low)
  • Will provide Subject Matter Expertise (SME) on ESS reports and will be responsible for downloading and analyzing weekly posted reports.
    • Reports:
      • Data Loss Prevention (DLP) Violations
      • Enhanced Reports
      • Outdated Product Report
      • Rogues
      • Subnet Coverage
  • Notify the office of responsibility SA of open findings and suspense SAs to identify devices for exemption (ex. Printers, non-OS systems). Use designated template for list of exempted devices.
  • Submit exempted device list to 561st Network Operations Squadron (NOS) Client Security via Remedy Ticket or designated ticketing system.
  • Work with office of responsibility to identify which two (2) systems within each populated subnet range will have Rogue Sensor Detectors (RSD) applied. Submit identified systems via designated ticketing system to 561 NOS Client Security.
  • Monitor and download weekly reports for status on open findings.
  • Serve as functional lead for cybersecurity applications used to manage / monitor cyber compliance status, configuration and indicators of compromise
  • Base Analysts will provide the following support in addition to STIGs, POAMs, and ESS compliance:
    • Identify monthly summary of fix actions (i.e. punch list) required to meet CORA standards and guidelines.
    • Integrate Command Cyber 365 Flight Plan guide with all required components.
    • Report monthly on compliance status from assigned bases.
    • Manage / report om implementation of policies established by Command Cyber Analysts
    • Manage 38 CORA/HSO reports for assigned bases or equivalent
    • Configure and tailor policies to address specific needs and intracacies of assigned bases.
    • Develop Master Software List (MSL) for assigned base(s).
Qualifications

Required:

  • Recommend 3+ years of experience
  • Knowledge of the limitations and capabilities of computer systems and technology; operational support of networks, operating systems, Internet technologies, databases, and security infrastructure; cybersecurity and information security controls, practices, procedures, and regulations; and incident response program practices and procedures.
  • Education: Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Data Science, or Software Engineering is typically required.
  • Certifications (DoD Approved): Common certifications for this role include GCIH (GIAC Certified Incident Handler), CEH (Certified Ethical Hacker), Security+, and others like PenTest+ or CySA+.
  • Skills & Knowledge:
    • Proficiency in network security architecture and application vulnerabilities.
    • Ability to conduct vulnerability scans and utilize penetration testing tools.
    • Knowledge of network analysis tools and techniques.

Clearance:

  • Active DoD Secret level clearance

Travel Required:

  • Minimal, less than 10%

Potential for Telework:

  • Based on customer needs
About Tyto Athene

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $75,000-$85,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology.

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Program Manager
Cybersecurity Program Manager

Tyto Athene, LLC • Homeland Park (MD)

Hybrid
USD 175,000 - 250,000
Senior Cyber Lead
Senior Cyber Lead

Quantum Sky • Linthicum (MD)

On-site
USD 170,000 - 230,000
Cybersecurity Program Manager
Cybersecurity Program Manager

Quantum Sky • Linthicum (MD)

Hybrid
USD 175,000 - 250,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
ISSM / Security Automation Engineer
ISSM / Security Automation Engineer

Tyto Athene, LLC • Northern (KY)

Hybrid
USD 175,000 - 190,000
Health/Dental/Vision
401(k) match
Paid Time Off
Chief Engineer / Technical Director
Chief Engineer / Technical Director

Tyto Athene, LLC • Arlington (VA), Northern (KY)

Hybrid
USD 200,000 - 240,000
Health/Dental/Vision
401(k) match
Paid Time Off
+2
SOC Analyst (Tier 2)
SOC Analyst (Tier 2)

Quantum Sky • Washington

On-site
USD 125,000 - 135,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Chief Engineer / Technical Director
Chief Engineer / Technical Director

Quantum Sky • Arlington (VA)

On-site
USD 200,000 - 240,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
SOC Analyst (Tier 2)
SOC Analyst (Tier 2)

Tyto Athene, LLC • Northern (KY)

Hybrid
USD 125,000 - 135,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Cybersecurity / Information Assurance Lead
Cybersecurity / Information Assurance Lead

Quantum Sky • Arlington (VA)

On-site
USD 140,000 - 175,000
Cybersecurity / Information Assurance Lead
Cybersecurity / Information Assurance Lead

Tyto Athene, LLC • Arlington (VA), Northern (KY)

Hybrid
USD 140,000 - 175,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4