Description
Quantum Sky is searching for a Cybersecurity / Information Assurance Lead that serves as the senior authority for enterprise cybersecurity and information assurance across the Joint Virtual Environment (JVE) in support of the F-35 Lightning II Joint Program Office (JPO).
Â
This role owns the cybersecurity strategy and governance for on‑premises and Azure IL‑5 environments, leads Risk Management Framework (RMF) execution and assessment & authorization (A&A) artifacts, directs continuous monitoring (ACAS, STIGs, ESS), and orchestrates incident response to ensure confidentiality, integrity, authenticity, non‑repudiation, and availability of mission services. Onsite presence in Arlington, VA is required; travel may be necessary to support CONUS/OCONUS Tier sites.Â
Â
Responsibilities:
- Govern cybersecurity governance and policy: develop, maintain, and annually update security policies, standards, controls, and compliance aligned to DoDI 8500.01, DoDI 8510.01 (RMF), NIST SP 800‑53, CNSS, CCRI criteria, and program directives.
- Lead RMF and A&A lifecycle: coordinate system categorization, control selection, implementation, assessment, and authorization; produce and maintain the System Security Plan (SSP), Security Assessment Report (SAR), Security Control Traceability Matrix (SCTM), and Plan of Action and Milestones (POA&M) in eMASS.
- Own continuous monitoring program: ensure monthly ACAS vulnerability scanning (≥98% scan rate), quarterly STIG reviews, and Endpoint Security Services (ESS) scores ≥95% at least 90% of the time; track compliance on a weekly Security Dashboard (≥75% update compliance).
- Direct vulnerability and patch management: drive remediation governance for IAVA/IAVB, benchmark compliance, and OS STIG settings; ensure timely reporting and closure across all assets.
- Oversee security operations and incident response: ingest SIEM telemetry, lead detection, triage, containment, eradication, and recovery per the OCIO incident response plan; coordinate with CSSP and JFHQ‑DoDIN when thresholds are not met.Â
- Embed security into engineering: review architectures, designs, and changes for security impacts; serve as primary liaison between Enterprise Architecture and Systems Security Engineering (ISSE/SSE) to integrate controls through the SE process.Â
- Support Technical Design Reviews: provide personnel to participate in TDRs/SETRs/ISSEWGs; deliver Cyber Engineering Design Review Reports within 5 business days with risks, findings, and recommended actions.Â
- Deliver capability security engineering: execute Common Cyber Modeling Process (or equivalent) and provide Cyber Engineering Capability Reports covering requirements and verification approaches for new capabilities.Â
- Lead Zero Trust implementation: advance identity, device, network/environment, application/workload, and data security controls across JVE, coordinating configuration baselines with NOSC operations.Â
- Champion security awareness and training: maintain ≥95% annual Cyber Awareness training compliance with certificates retrievable 100% of the time.Â
- Provide reporting and governance to include Monthly Status Reports, POA&M status, vulnerability and eMASS summaries, and intrusion management reports in alignment with program cadence.Â
Performance Metrics & Success Criteria:
- Service Availability: Critical services ≥95% monthly uptime; less‑critical services ≥90% during operational hours (excluding external outages).Â
- Continuous Monitoring: ACAS scan rate ≥98% monthly; ESS ≥95% in all measured areas at least 90% of the time; STIG reviews conducted quarterly.Â
- Risk Governance: POA&M updates weekly with quarterly artifact uploads in eMASS; Security Dashboard updated weekly meeting ≥75% update compliance (monthly measure).Â
- Vulnerability Management: timely IAVM acknowledgments and closures; compliance tracked for OS STIG, software inventory patches, and benchmark adherence.Â
- Quality & Reporting: accurate, complete, on‑time deliverables per CDRLs; rapid corrective actions and open communications across COR/TPOC governance.Â
Qualifications
Required:
- Education: MA/MS; substitution allowed with BA/BS and 12+ years of relevant experience.Â
- Certification: DoD 8140/8570‑aligned IAM Level III (e.g., CISSP, CISM, GSLC) appropriate to the position, subject to solicitation requirements.Â
- Experience: 10+ years leading information security, cybersecurity, or information assurance programs in complex enterprise environments, including DoD RMF, NIST SP 800‑53, continuous monitoring, vulnerability management, and ATO support.Â
- Operations & leadership: demonstrated ability to lead cybersecurity staff and coordinate with ISSMs, ISSOs, system owners, engineers, and authorizing officials; experience embedding security across the lifecycle and reviewing architectures and changes for security impacts. Â
- Zero Trust implementation spanning identity, device, network/environment, application/workload, and data controls.Â
Desired:
- SIEM operations (e.g., LogRhythm) and advanced incident response playbooks integrating threat intelligence.Â
- ATO leadership for hybrid/on‑prem and Cloud IL‑5 environments with eMASS body of evidence management.Â
- Participation in CyWGs, CTTs, CVPAs, and adversarial assessments; delivering actionable findings and remediation guidance.Â
Clearance:
- Top Secret at time of submission (SCI eligibility may be required).
Location:
- Arlington, VA; onsite presence required with willingness to travel to CONUS/OCONUS Tier sites.Â
About Tyto Athene
Compensation:
- Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between 140-175K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.
Benefits:
- Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.
Â
The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.Â
Â
At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?Â
Â
Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.
is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.
Learn more about this Employer on their Career Site
