Cybersecurity Risk & Exposure Analyst III

Invictus International Consulting, LLC

Colorado Springs (CO)

On-site

USD 149,000 - 182,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Invictus International Consulting, LLC is seeking a Senior Cybersecurity Risk & Exposure Analyst III in Colorado Springs to lead complex risk analysis for DoD systems. You will correlate vulnerability data, asset discovery, and SOC findings to identify exposures with the greatest operational risk.

A TS/SCI clearance with CI poly is required. The role supports RMF activities, coordinates with ISSOs/ISSMs, and mentors junior analysts while developing robust exposure-analysis procedures and

Qualifications

  • Bachelor's degree in a technical discipline with 4 years of experience allowed as substitution.
  • Minimum six years of relevant experience beyond education.
  • Knowledge of vulnerability and exposure management, threat-informed risk analysis, RMF and security controls, network/system security, and technical risk assessment.
  • Experience with ACAS/Tenable, runZero or similar tools, DoD STIG/SCAP, and POA&M processes; coordination with SOC/IR and ISSO/ISSM functions.
  • Proven ability to lead complex exposure or vulnerability analyses and translate findings into RMF actions.
  • Current DoD 8570 IAT II or IAM II certification required.
  • Experience in a DoD or IC environment is preferred.
  • Active TS/SCI clearance with ability to obtain/maintain CI polygraph.

Responsibilities

  • Lead complex operational cyber risk and exposure analysis supporting SOC investigations and vulnerability prioritization across DoD systems.
  • Correlate vulnerability data, asset discovery, system criticality, and SOC findings to identify high-risk exposures.
  • Analyze vulnerabilities in context, including exploitation paths, attacker TTPs, and mission impact.
  • Serve as senior technical resource to Cybersecurity Operations and Threat Analysts during investigations and hunting.
  • Coordinate with ISSOs/ISSMs, system owners, engineers, and remediation teams to translate findings into actionable mitigation and RMF follow-up.
  • Develop and maintain exposure-analysis procedures, risk-prioritization methods, and technical checklists to improve decision quality.
  • Review remediation evidence and metrics to identify systemic risk and drive closure or escalation.
  • Support RMF and assessment activities affecting security-control effectiveness and authorization posture.

Skills

Vulnerability management
Risk analysis
RMF & security controls
DoD/IC experience
Exposure/asset discovery
Threat-informed analysis
Incident response coordination
Mentoring

Education

Bachelor's degree

Tools

ACAS/Tenable
runZero
STIG Viewer/SCAP
POA&M processes

Job description

Title: Senior Cybersecurity Risk & Exposure Analyst III
Location: Colorado Springs, CO
Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph

Job Details
  • Lead complex operational cyber risk and exposure analysis supporting SOC investigations, threat-informed vulnerability prioritization, continuous monitoring, and remediation activities across DoD systems and sites
  • Correlate vulnerability data, asset discovery, system criticality, network reachability, security configuration, known controls, threat activity, and SOC findings to identify exposures that present the greatest operational or mission risk
  • Analyze vulnerabilities and configuration weaknesses in context, including plausible exploitation paths, adversary TTPs, affected technologies, compensating controls, mission/availability impact, and evidence from active or historical SOC investigations
  • Serve as a senior technical resource to Cybersecurity Operations and Threat Analysts for vulnerability, asset, control, and system-security context during complex investigations and proactive hunting activities
  • Coordinate with system ISSOs/ISSMs, system owners, engineers, administrators, authorization personnel, and remediation teams to translate SOC-derived findings into actionable mitigation, continuous-monitoring, POA&M, or RMF follow-up as applicable
  • Develop and maintain operational exposure-analysis procedures, risk-prioritization methods, technical checklists, TTPs, guides, briefings, and other products that improve consistency and decision quality
  • Review remediation evidence, recurring findings, exposure trends, POA&M-related items, and metrics to identify systemic risk, validate corrective actions, and drive closure or escalation
  • Support RMF and assessment activities where SOC findings or operational exposure data affect security-control effectiveness, system risk, or authorization posture, while coordinating with the responsible system security personnel
  • Mentor Level I and II personnel and review analytical work products for technical accuracy, risk context, completeness, and clear communication
Requirements
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum six (6) years of relevant experience in addition to education level
  • Demonstrated knowledge of vulnerability/exposure management, threat-informed risk analysis, DoD continuous monitoring, RMF/security controls, network/system security, and technical risk assessment
  • Experience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and coordination with SOC/incident-response and ISSO/ISSM functions is desired
  • Demonstrated experience leading complex exposure or vulnerability analysis, prioritizing technical risk, coordinating remediation, and translating cyber findings into continuous-monitoring or RMF actions is strongly desired
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph
Equal Opportunity Employer/Veteran/Disabled
Salary: $165000 per year
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Risk & Exposure Analyst III
Cybersecurity Risk & Exposure Analyst III

Invictus International • Colorado Springs (CO)

On-site
USD 95,000 - 125,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 160,000
Cybersecurity Risk & Exposure Analyst III
Cybersecurity Risk & Exposure Analyst III

Invictus International • Alexandria (VA)

On-site
USD 120,000 - 180,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International • Colorado Springs (CO)

On-site
USD 140,000 - 190,000
Cybersecurity Risk & Exposure Analyst III
Cybersecurity Risk & Exposure Analyst III

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 150,000 - 190,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International • Alexandria (VA)

On-site
USD 140,000 - 190,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 120,000 - 150,000
Senior Cybersecurity Defense Analyst III
Senior Cybersecurity Defense Analyst III

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 140,000 - 180,000
Senior DoD Cyber Risk & Exposure Analyst (TS/SCI)
Senior DoD Cyber Risk & Exposure Analyst (TS/SCI)

Invictus International • Colorado Springs (CO)

On-site
USD 95,000 - 125,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International • Colorado Springs (CO)

On-site
USD 130,000 - 180,000