Cybersecurity Analyst
Company Name
**
Rosemont, IL, United States
Basic
Posted about 23 hours ago
company
About Rhodian Group
Rhodian Group helps businesses build and manage their network environments with predictably priced managed IT services so they can focus on their core strengths and growth initiatives. They also help businesses identify and reduce cybersecurity and non-compliance risks. Their combination of IT, cybersecurity, and compliance services helps businesses operate safely, while complying with industry mandates and regulatory requirements.
role
Role Overview
The Security Analyst plays a critical role in assessing and protecting client security posture across diverse environments. This role combines proactive risk assessment, incident analysis, and customer engagement to identify vulnerabilities, document findings, and guide clients toward stronger security controls. The ideal candidate is detail-oriented, communicates clearly with technical and non-technical stakeholders, and can balance the demands of assessment delivery with rapid escalation support for active security concerns.
Key Responsibilities
• Plan and coordinate security risk assessments with clients, including scheduling, stakeholder alignment, and timeline management
• Conduct comprehensive security assessments, analyzing controls, policies, and configurations against industry frameworks (NIST, ISO 27001, CIS)
• Review and evaluate evidence of control implementation, documenting findings with clarity and supporting documentation
• Identify security risks, control gaps, and areas of non-compliance; articulate business impact and remediation priorities
• Draft detailed assessment reports and executive summaries tailored to client leadership and technical teams
• Conduct kickoff and debrief meetings, explaining assessment methodology, findings, and recommended remediation actions
• Manage customer communication throughout assessment lifecycle, providing status updates and addressing questions
• Handle escalated security cases from the service desk, including incident analysis, root cause investigation, and remediation guidance
• Analyze security incidents and vulnerability findings, documenting technical details and recommended fixes
• Maintain detailed case notes, incident reports, and security documentation for client and internal records
• Collaborate with IT, engineering, and internal security teams to improve assessment quality and service delivery
• Organize client files, policies, and assessment documentation for accurate tracking and reporting
Required Qualifications
• Bachelor's degree in Information Security, Computer Science, Information Technology, or related field (or equivalent professional experience)
• Strong understanding of security controls and risk management frameworks (NIST, ISO 27001, CIS Benchmarks)
• Practical experience conducting or supporting security assessments, audits, or risk evaluations
• Working knowledge of common attack techniques, vulnerabilities, and indicators of compromise
• Excellent written and verbal communication skills; ability to explain technical concepts to non-technical audiences
• Strong organizational and time management abilities; capable of managing multiple assessments and priorities
• Proficiency with Microsoft Office (Word, Excel, Outlook) and ability to quickly learn new tools
• Attention to detail and strong documentation skills
• Ability to work effectively in both independent and collaborative environments
Preferred Qualifications
• 1-3 years of hands-on experience in information security, risk management, IT audit, or related role
• Experience in an MSP or MSSP multi-tenant environment
• Familiarity with GRC (Governance, Risk, and Compliance) tools and platforms
• Experience with vulnerability scanning tools (Qualys, Nessus, Rapid7)
• Basic log analysis or query experience (KQL, SPL, SQL, PowerShell)
• Familiarity with the MITRE ATT&CK framework
• Relevant certifications: CompTIA Security+, CySA+, or CCSK
What Success Looks Like
• Assessments are completed on schedule with clear, actionable findings and evidence
• Clients receive well-organized reports that effectively communicate risk, impact, and remediation priorities
• Escalated security cases are analyzed thoroughly with detailed investigation notes and remediation recommendations
• Customer feedback reflects strong engagement, clarity in assessment communication, and confidence in recommendations
• Assessment quality improves over time through consistent documentation, feedback, and process refinement
• Strong collaboration with SOC, IT, and senior security teams enhances overall MSSP service delivery
Mid-level Cybersecurity Engineer / RMF Specialist
Company Name
**
Herndon, VA / Remote
Basic
Posted 3 days ago
Dark Wolf Solutions is seeking a Mid-level Cybersecurity Engineer / Risk Management Framework (RMF) Specialist to will lead and execute the security authorization process for our systems and applications in compliance with NIST guidelines and DoD regulations. This individual will be responsible for navigating the RMF lifecycle, developing security documentation, conducting risk assessments, and ensuring that our systems meet the highest standards of security and compliance. This position offers a critical opportunity for a motivated and detail-oriented security professional to leverage their RMF expertise, contribute to the protection of sensitive information, and play a vital role in securing our nation's critical infrastructure.
Key Responsibilities:
Responsible for concentrating on overall technical and operational effectiveness of capabilities in coordination with the COTR and Sponsor Staff management.
Cyber Security teams are responsible for providing recommendations on continuous improvement of the processes and architectures supporting the overall Cyber Defense operational activities including, but not limited to: analysis, incident handling and reporting products, and the reporting lifecycle.
Ensures the effective operations of Agency IT systems and network defenses, providing effective incident response capabilities, usable and effective reports that address overall situational awareness.
This individual works to maximize the use of existing tools to correlate information and synthesize data into usable and actionable events.
Identifies and provides an agile approach to the automation of any manual and inefficient processes that exist across the cyber defense program and to work with the Sponsor to recommend and implement technical solutions designed to return time to mission.
Required Qualifications:
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical field
3 years minimum of relevant experience
Experience in security risk assessment and management in cloud environments (GCP preferred)
Experience building authorization packages
US Citizenship required with an active Secret clearance or interim Secret clearance
This role is primarily remote. The compensation for this role is estimated to be between $120,000-$150,000, commensurate on experience.
We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
Chief Engineer / Technical Director
Company Name
**
Arlington, VA, US
Basic
Posted 3 days ago
Description
Quantum Sky is searching for a Chief Engineer / Technical Director that serves as the technical authority for a large, multi-site Department of Defense IT and Cybersecurity program in support of the F-35 Lightning II Joint Program Office (JPO). This role owns solution integrity and engineering governance across enterprise architecture, systems engineering, network and cloud infrastructure, cybersecurity, and mission applications, ensuring secure, reliable delivery of services within the Joint Virtual Environment (JVE).
The position requires executive-level advisory capability, leading cross-functional engineering teams, directing design reviews, and translating enterprise strategy into executable technical roadmaps aligned to DoDAF and program priorities. Onsite presence in Arlington, VA is required; travel may be necessary to support CONUS/OCONUS sites.
Responsibilities:
Own the technical baseline, architecture standards, and exception decisions; chair design reviews and Technical Review Boards to maintain solution integrity.
Lead enterprise architecture development and maintenance, delivering “as-is” and “to-be” artifacts, roadmaps, and accurate network diagrams in compliance with DoDAF and TOGAF practices.
Direct systems engineering lifecycle activities including requirements traceability, interface management, configuration control, risk management, test planning, verification, and validation.
Integrate cybersecurity into engineering decisions, aligning with RMF/JSIG; ensure continuous monitoring with ACAS, STIGs, and ESS; govern POA&M management within eMASS.
Oversee NOSC-aligned operations engineering for confidentiality, integrity, and availability of critical/less-critical services; drive automation for detection and response.
Establish engineering metrics, SLAs/SLOs, KPIs and operational dashboards; analyze trends and lead corrective actions and continual service improvement (CSI).
Guide infrastructure modernization (hybrid cloud, zero trust, observability, automation), application modernization and data migration/repatriation initiatives.
Advise senior executives; convert complex technical concepts into actionable plans and investment priorities; communicate risks, trade-offs, and decisions transparently.
Ensure accurate configuration baselines and remediation of configuration drift; embed change management and knowledge management throughout the lifecycle.
Support place-of-performance needs across Arlington, VA and distributed Tier 1–3 sites; enable readiness for special projects and emerging capability requests.
Performance Metrics & Success Criteria:
Service Availability: Critical services ≥95% monthly uptime; less-critical services ≥90% during operational hours (excluding external outages).
Continuous Monitoring: ACAS scan rate ≥98% monthly; ESS ≥95% in all measured areas at least 90% of the time; STIG reviews conducted quarterly.
Risk Governance: POA&M updates weekly with quarterly artifact uploads in eMASS; Security Dashboard updated weekly meeting ≥75% update compliance (monthly measure).
Quality & Satisfaction: Accurate, complete, on-time deliverables; rapid corrective actions; open communications across COR/TPOC governance.
Qualifications
Required:
Education: MA/MS; substitution allowed with BA/BS and 12+ years of relevant experience.
Certifications: Cisco CCNP or equivalent (CompTIA Network+)
Experience: 10+ years leading enterprise architecture, systems engineering, or technical integration for complex enterprise IT environments.
Demonstrated prior experience owning the technical baseline, establishing architecture standards, and making exception decisions; must have previously chaired design reviews and Technical Review Boards to ensure solution integrity.
Proven track record leading enterprise architecture development and maintenance, including delivery of “as-is” and “to-be” artifacts, roadmaps, and accurate network diagrams in compliance with DoDAF and TOGAF practices.
Previous experience directing systems engineering lifecycle activities such as requirements traceability, interface management, configuration control, risk management, test planning, verification, and validation.
Prior involvement integrating cybersecurity into engineering decisions, aligning with RMF/JSIG; must have overseen continuous monitoring with ACAS, STIGs, and ESS, and governed POA&M management within eMASS.
Experience overseeing NOSC-aligned operations engineering for confidentiality, integrity, and availability of critical/less-critical services; must have driven automation for detection and response.
Established record of setting engineering metrics, SLAs/SLOs, KPIs and operational dashboards; must have analyzed trends and led corrective actions and continual service improvement (CSI).
Desired:
Modernization: Hybrid cloud, zero trust, enterprise networks, automation, observability, and legacy system modernization. Previous experience with TOGAF and DOD Architecture Framework.
CCIE, CISSP, INCOSE Certification
AWS Certified Solutions Architect – Associate (SAA‑C03) or AWS Certified Solutions Architect – Professional (SAP‑C02)
Azure Solutions Architect Expert certification
ITSM/CSI: Metrics-driven service improvement, CAB/TRB governance, and platform experience (Helix preferred).
Clearance:
Top Secret at time of submission (SCI eligibility may be required).
Location:
Arlington, VA; onsite presence required with willingness to travel to CONUS/OCONUS sites as needed (estimated 25%).
About Tyto Athene
Compensation:
Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between 200-240K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.
Benefits:
Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.
The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.
At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?
Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.
is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.
Cybersecurity / Information Assurance Lead
Company Name
**
Arlington, VA, US
Basic
Posted 3 days ago
Description
Quantum Sky is searching for a Cybersecurity / Information Assurance Lead that serves as the senior authority for enterprise cybersecurity and information assurance across the Joint Virtual Environment (JVE) in support of the F-35 Lightning II Joint Program Office (JPO).
This role owns the cybersecurity strategy and governance for on‑premises and Azure IL‑5 environments, leads Risk Management Framework (RMF) execution and assessment & authorization (A&A) artifacts, directs continuous monitoring (ACAS, STIGs, ESS), and orchestrates incident response to ensure confidentiality, integrity, authenticity, non‑repudiation, and availability of mission services. Onsite presence in Arlington, VA is required; travel may be necessary to support CONUS/OCONUS Tier sites.
Responsibilities:
Govern cybersecurity governance and policy: develop, maintain, and annually update security policies, standards, controls, and compliance aligned to DoDI 8500.01, DoDI 8510.01 (RMF), NIST SP 800‑53, CNSS, CCRI criteria, and program directives.
Lead RMF and A&A lifecycle: coordinate system categorization, control selection, implementation, assessment, and authorization; produce and maintain the System Security Plan (SSP), Security Assessment Report (SAR), Security Control Traceability Matrix (SCTM), and Plan of Action and Milestones (POA&M) in eMASS.
Own continuous monitoring program: ensure monthly ACAS vulnerability scanning (≥98% scan rate), quarterly STIG reviews, and Endpoint Security Services (ESS) scores ≥95% at least 90% of the time; track compliance on a weekly Security Dashboard (≥75% update compliance).
Direct vulnerability and patch management: drive remediation governance for IAVA/IAVB, benchmark compliance, and OS STIG settings; ensure timely reporting and closure across all assets.
Oversee security operations and incident response: ingest SIEM telemetry, lead detection, triage, containment, eradication, and recovery per the OCIO incident response plan; coordinate with CSSP and JFHQ‑DoDIN when thresholds are not met.
Embed security into engineering: review architectures, designs, and changes for security impacts; serve as primary liaison between Enterprise Architecture and Systems Security Engineering (ISSE/SSE) to integrate controls through the SE process.
Support Technical Design Reviews: provide personnel to participate in TDRs/SETRs/ISSEWGs; deliver Cyber Engineering Design Review Reports within 5 business days with risks, findings, and recommended actions.
Deliver capability security engineering: execute Common Cyber Modeling Process (or equivalent) and provide Cyber Engineering Capability Reports covering requirements and verification approaches for new capabilities.
Lead Zero Trust implementation: advance identity, device, network/environment, application/workload, and data security controls across JVE, coordinating configuration baselines with NOSC operations.
Champion security awareness and training: maintain ≥95% annual Cyber Awareness training compliance with certificates retrievable 100% of the time.
Provide reporting and governance to include Monthly Status Reports, POA&M status, vulnerability and eMASS summaries, and intrusion management reports in alignment with program cadence.
Performance Metrics & Success Criteria:
Service Availability: Critical services ≥95% monthly uptime; less‑critical services ≥90% during operational hours (excluding external outages).
Continuous Monitoring: ACAS scan rate ≥98% monthly; ESS ≥95% in all measured areas at least 90% of the time; STIG reviews conducted quarterly.
Risk Governance: POA&M updates weekly with quarterly artifact uploads in eMASS; Security Dashboard updated weekly meeting ≥75% update compliance (monthly measure).
Vulnerability Management: timely IAVM acknowledgments and closures; compliance tracked for OS STIG, software inventory patches, and benchmark adherence.
Quality & Reporting: accurate, complete, on‑time deliverables per CDRLs; rapid corrective actions and open communications across COR/TPOC governance.
Qualifications
Required:
Education: MA/MS; substitution allowed with BA/BS and 12+ years of relevant experience.
Certification: DoD 8140/8570‑aligned IAM Level III (e.g., CISSP, CISM, GSLC) appropriate to the position, subject to solicitation requirements.
Experience: 10+ years leading information security, cybersecurity, or information assurance programs in complex enterprise environments, including DoD RMF, NIST SP 800‑53, continuous monitoring, vulnerability management, and ATO support.
Operations & leadership: demonstrated ability to lead cybersecurity staff and coordinate with ISSMs, ISSOs, system owners, engineers, and authorizing officials; experience embedding security across the lifecycle and reviewing architectures and changes for security impacts.
Zero Trust implementation spanning identity, device, network/environment, application/workload, and data controls.
Desired:
SIEM operations (e.g., LogRhythm) and advanced incident response playbooks integrating threat intelligence.
ATO leadership for hybrid/on‑prem and Cloud IL‑5 environments with eMASS body of evidence management.
Participation in CyWGs, CTTs, CVPAs, and adversarial assessments; delivering actionable findings and remediation guidance.
Clearance:
Top Secret at time of submission (SCI eligibility may be required).
Location:
Arlington, VA; onsite presence required with willingness to travel to CONUS/OCONUS Tier sites.
About Tyto Athene
Compensation:
Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between 140-175K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.
Benefits:
Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.
The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.
At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?
Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.
is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.
Cloud Cybersecurity Analyst
Company Name
**
Washington DC Metro Area
Basic
Posted about 1 month ago
Dark Wolf is seeking Cloud Cybersecurity Analyst to join a collaborative team to design, defend, and continuously evaluate the enterprise security architecture and government accreditation posture for critical IT networks through active threat modeling, incident response, continuous audit monitoring, vulnerability remediation, and strict regulatory compliance This position will be based out of the Washington DC Metro area with hybrid schedule opportunity. Job responsibilities include but are not limited to:
Utilizing COTS/GOTS and enterprise scanning tools to identify, analyze, and track network, system, and application-level vulnerabilities
Coordinating with IT teams to support the containment, mitigation, and remediation of identified vulnerabilities and intrusions
Supporting threat modeling exercises and assisting senior staff in evaluating security incidents to prevent future occurrences
Assisting in validating established security requirements, assessing operational risks, and recommending baseline safeguards
Participating in formal Security Test and Evaluation (ST&E) preparations, assist during testing, and aid in drafting post-test analysis reports
Periodically reviewing system audit logs, tracking open findings, and monitoring corrective action plans until all issues are resolved
Assisting in configuring, hardening, and maintaining secure operating systems, network access controls, and security applications
Required Qualifications:
Bachelor’s Degree in Computer Science or related field
2-5+ years of relevant Cyber experience
Experience as a Cyber Analyst, RMF Engineer, ISSO, Information Assurance Engineer, Vulnerability Manager, POA&M Manager
Hands-on Tool experience associated to role
Experience with NIST 800-53 and CNSSI 1253
Experience with risk management policies/procedures, to include DODI 8510.01
Ability to communicate on technical subjects using clear, concise, non-technical language to include strong written communications, ability to provide written feedback on documents, and ability to prepare briefings
Experience using vulnerability and compliance assessment tools such as Nessus, SCAP, or App Detective
At least one (1) of the following cyber security certifications: Security+ CE, SSCP, CAP, CISM, CASP, CISSP, GSEC, GICSP, GSLC, CEH, CDNA, CSSLP
Experience assessing technical environments and translating implemented security controls into clear NIST SP 800-53 control narratives and supporting Authorization to Operate (ATO) documentation
Cloud Platform familiarity with at least one service offering from AWS, Azure, or Google GCP
US Citizenship and have a Secret security clearance
The salary range for this position is estimated to be between $100,000.00 - $145,000.00, commensurate on experience and technical skillset.
We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.