Cybersecurity / Information Assurance Lead

Quantum Sky

Arlington (VA)

On-site

USD 140,000 - 175,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Quantum Sky seeks a Cybersecurity / Information Assurance Lead to serve as the senior authority for enterprise cybersecurity and information assurance across the Joint Virtual Environment (JVE) in support of the F-35 JPO. This role owns the cybersecurity strategy for on-premises and Azure IL-5 environments and leads RMF execution and A&A artifacts.

Onsite presence in Arlington, VA is required; travel may be necessary to CONUS/OCONUS Tier sites.

Qualifications

  • Education: MA/MS; substitution allowed with BA/BS and 12+ years of relevant experience.
  • Certification: DoD 8140/8570 IAM Level III (e.g., CISSP, CISM, GSLC).
  • Experience: 10+ years leading information security, cybersecurity, or information assurance programs in complex enterprise environments, including DoD RMF, NIST SP 800-53, continuous monitoring, vulnerability management, and ATO support.
  • Operations & leadership: demonstrated ability to lead cybersecurity staff and coordinate with ISSMs, ISSOs, system owners, engineers, and authorizing officials; experience embedding security across the lifecycle and reviewing architectures and changes for security impacts.
  • Zero Trust implementation spanning identity, device, network/environment, application/workload, and data controls.

Responsibilities

  • Govern cybersecurity governance and policy: develop, maintain, and annually update security policies, standards, controls, and compliance aligned to DoDI 8500.01, DoDI 8510.01 (RMF), NIST SP 800-53, CNSS, CCRI criteria, and program directives.
  • Lead RMF and A&A lifecycle: coordinate system categorization, control selection, implementation, assessment, and authorization; produce and maintain the SSP, SAR, SCTM, and POA&M in eMASS.
  • Own continuous monitoring program: ensure monthly ACAS vulnerability scanning (≥98% scan rate), quarterly STIG reviews, and ESS scores ≥95% at least 90% of the time; track compliance on a weekly Security Dashboard (≥75% update).
  • Direct vulnerability and patch management: drive remediation governance for IAVA/IAVB, benchmark compliance, and OS STIG settings; ensure timely reporting and closure across all assets.
  • Oversee security operations and incident response: ingest SIEM telemetry, lead detection, triage, containment, eradication, and recovery per the OCIO incident response plan; coordinate with CSSP and JFHQ-DoDIN when thresholds are not met.
  • Embed security into engineering: review architectures, designs, and changes for security impacts; liaison between Enterprise Architecture and ISSE/SSE to integrate controls through the SE process.

Skills

RMF & A&A
Continuous Monitoring
Vulnerability Management
Security Governance
Zero Trust

Education

MA/MS (or BA/BS + 12+ yrs)

Tools

eMASS
ACAS
STIGs
SIEM (LogRhythm)

Job description

Description

Quantum Sky is searching for a Cybersecurity / Information Assurance Lead that serves as the senior authority for enterprise cybersecurity and information assurance across the Joint Virtual Environment (JVE) in support of the F-35 Lightning II Joint Program Office (JPO).

This role owns the cybersecurity strategy and governance for on‑premises and Azure IL‑5 environments, leads Risk Management Framework (RMF) execution and assessment & authorization (A&A) artifacts, directs continuous monitoring (ACAS, STIGs, ESS), and orchestrates incident response to ensure confidentiality, integrity, authenticity, non‑repudiation, and availability of mission services. Onsite presence in Arlington, VA isrequired; travel may be necessary to support CONUS/OCONUS Tier sites.

Responsibilities:

  • Govern cybersecurity governance and policy: develop,maintain, and annually update security policies, standards, controls, and compliance aligned to DoDI 8500.01, DoDI 8510.01 (RMF), NIST SP 800‑53, CNSS, CCRI criteria, and program directives.
  • Lead RMF and A&A lifecycle: coordinate system categorization, control selection, implementation, assessment, and authorization; produce and maintain the System Security Plan (SSP), Security Assessment Report (SAR), Security Control Traceability Matrix (SCTM), and Plan of Action and Milestones (POA&M) ineMASS.
  • Own continuous monitoring program: ensure monthly ACAS vulnerability scanning (≥98% scan rate), quarterly STIG reviews, and Endpoint Security Services (ESS) scores ≥95% at least 90% of the time; track compliance on a weekly Security Dashboard (≥75% update compliance).
  • Direct vulnerability and patch management: drive remediation governance for IAVA/IAVB, benchmark compliance, and OS STIG settings; ensuretimelyreporting and closure across all assets.
  • Oversee security operations and incident response: ingest SIEM telemetry, lead detection, triage, containment, eradication, and recovery per the OCIO incident response plan; coordinate with CSSP and JFHQ‑DoDIN when thresholds are not met.
  • Embed security into engineering: review architectures, designs, and changes for security impacts; serve as primary liaison between Enterprise Architecture and Systems Security Engineering (ISSE/SSE) to integrate controls through the SE process.
  • Support Technical Design Reviews: provide personnel toparticipatein TDRs/SETRs/ISSEWGs; deliver Cyber Engineering Design Review Reports within 5 business days with risks, findings, and recommended actions.
  • Deliver capability security engineering: execute Common Cyber Modeling Process (or equivalent) and provide Cyber Engineering Capability Reports covering requirements and verification approaches for new capabilities.
  • Lead Zero Trust implementation: advance identity, device, network/environment, application/workload, and data security controls across JVE, coordinating configuration baselines with NOSC operations.
  • Champion security awareness and training:maintain≥95% annual Cyber Awareness training compliance with certificates retrievable 100% of the time.
  • Provide reporting and governanceto includeMonthly Status Reports, POA&M status, vulnerability andeMASSsummaries, and intrusion management reports in alignment with program cadence.

Performance Metrics & Success Criteria:

  • Service Availability: Critical services ≥95% monthly uptime; less‑critical services ≥90% during operational hours (excluding external outages).
  • Continuous Monitoring: ACAS scan rate ≥98% monthly; ESS ≥95% in all measured areas at least 90% of the time; STIG reviews conducted quarterly.
  • Risk Governance: POA&M updates weekly with quarterly artifact uploads ineMASS; Security Dashboard updated weekly meeting ≥75% update compliance (monthly measure).
  • Vulnerability Management:timelyIAVM acknowledgments and closures; compliance tracked for OS STIG, software inventory patches, and benchmark adherence.
  • Quality & Reporting:accurate, complete, on‑time deliverables per CDRLs; rapid corrective actions and open communications across COR/TPOC governance.
Qualifications

Required:

  • Education: MA/MS; substitution allowed with BA/BS and 12+ years of relevant experience.
  • Certification: DoD 8140/8570‑aligned IAM Level III (e.g., CISSP, CISM, GSLC)appropriate tothe position, subject to solicitation requirements.
  • Experience: 10+ years leading information security, cybersecurity, or information assurance programs in complex enterprise environments, including DoD RMF, NIST SP 800‑53, continuous monitoring, vulnerability management, and ATO support.
  • Operations & leadership:demonstratedability to lead cybersecurity staff and coordinate with ISSMs, ISSOs, system owners, engineers, and authorizing officials; experience embedding security across the lifecycle and reviewing architectures and changes for security impacts.
  • Zero Trust implementation spanning identity, device, network/environment, application/workload, and data controls.

Desired:

  • SIEM operations (e.g., LogRhythm) and advanced incident response playbooks integrating threat intelligence.
  • ATO leadership for hybrid/on‑prem and Cloud IL‑5 environments witheMASSbody of evidence management.
  • Participation inCyWGs, CTTs, CVPAs, and adversarial assessments; delivering actionable findings and remediation guidance.

Clearance:

  • Top Secret at time of submission (SCI eligibility may berequired).

Location:

  • Arlington, VA; onsite presence required with willingness to travel to CONUS/OCONUS Tier sites.
About Tyto Athene

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between 140-175K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity / Information Assurance Lead
Cybersecurity / Information Assurance Lead

Tyto Athene, LLC • Arlington (VA), Northern (KY)

Hybrid
USD 140,000 - 175,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Deputy Program Manager
Deputy Program Manager

Quantum Sky • Arlington (VA)

On-site
USD 150,000 - 175,000
Health/Dental/Vision
401(k) match
Paid Time Off
Deputy Program Manager
Deputy Program Manager

Tyto Athene, LLC • Arlington (VA), Northern (KY)

Hybrid
USD 150,000 - 175,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Chief Engineer / Technical Director
Chief Engineer / Technical Director

Quantum Sky • Arlington (VA)

On-site
USD 200,000 - 240,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Chief Engineer / Technical Director
Chief Engineer / Technical Director

Tyto Athene, LLC • Arlington (VA), Northern (KY)

Hybrid
USD 200,000 - 240,000
Health/Dental/Vision
401(k) match
Paid Time Off
+2
Senior Cyber Lead
Senior Cyber Lead

Quantum Sky • Linthicum (MD)

On-site
USD 170,000 - 230,000
Cybersecurity Program Manager
Cybersecurity Program Manager

Quantum Sky • Linthicum (MD)

Hybrid
USD 175,000 - 250,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Program Manager
Program Manager

Tyto Athene, LLC • Arlington (VA), Northern (KY)

Hybrid
USD 175,000 - 225,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Program Manager
Program Manager

Quantum Sky • Arlington (VA)

On-site
USD 175,000 - 225,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Enterprise ITSM & Continual Service Improvement (CSI) Lead
Enterprise ITSM & Continual Service Improvement (CSI) Lead

Tyto Athene, LLC • Arlington (VA), Northern (KY)

Hybrid
USD 175,000 - 225,000
Health/Dental/Vision
401(k) match
Paid Time Off
+3