Remote or hybrid or in office Lone Tree, CO Remote Full time R SNC can only hire in these states: AL, AK, AZ, CA, CO, FL, GA, HI, ID, IL, IN, KS, KY, LA, MD, MA, MI, MN, MS, MO, MT, NE, NV, NH, NJ, NM, NC, OH, OK, OR, PA, SC, TN, TX, UT, VA, WA, WV, WI. Sierra Nevada Company (SNC) is seeking a Senior Business Development Manager - Cyber to lead commercial growth for SNC Defensible Security, our defense-grade Security Operations Center-as-a-Service (SOCaaS) offering. Defensible Security delivers fully compliant, U.S.-based, U.S. Persons-only, 24x7 cybersecurity monitoring, alerting, and response purpose-built for the Defense Industrial Base (DIB) and federally regulated organizations. This role is the anchor leadership hire for Defensible's commercial go to market (GTM) motion - responsible for shaping and executing the strategy required to convert a substantial market opportunity into a scaled cybersecurity business. This senior commercial leader will build the pipeline, advance opportunities to close, grow the partner ecosystem, strengthen brand presence, and establish the operating discipline and team needed to drive Defensible Security's long term growth. The Cybersecurity Maturity Model Certification (CMMC) compliance wave is accelerating ahead of the formal Department of Defense (DoD) enforcement calendar, with prime contractors already imposing requirements across their supply chains. SNC's defense heritage, cleared status, and trusted security reputation position Defensible to win where heritage and compliance matter most. The Senior Business Development Manager will help drive the strategy and execution that captures this demand across priority customer cohorts. While Defensible Security is the primary focus, the role's scope spans SNC's commercial cyber portfolio, positioning the company to extend the same GTM motion to adjacent cyber offerings over time. The ISR (Intelligence, Surveillance & Reconnaissance), Aviation, and Security (IAS) business area is a leader in ISR and aviation, it is a leading prime manned and unmanned aircraft systems integrator for innovative, high-performance ISR and aviation systems. Its end-to-end Command, Control, Computers, Communications and Intelligence, Surveillance & Reconnaissance (C4ISR) capabilities encompass design, integration, test, certification, ground/flight training and complete logistics support. IAS tailors solutions to customer cost, performance, and schedule requirements and designs to consistently exceed expectations - with an unrivaled record of on time and on (or under) budget deliveries. Responsibilities: Own commercial GTM strategy. Define and execute the go-to-market strategy for Defensible Security across priority DIB and regulated-commercial cohorts, translating market opportunities into a prioritized pipeline and a credible bookings forecast. Drive revenue and pipeline. Carry the most senior selling responsibility directly - prospecting, qualifying, advancing, and closing opportunities - while building the demand-generation engine that produces marketing-sourced pipeline. Engage prime contractors and the DIB. Build executive relationships across prime contractors, defense manufacturers, the Intelligence Community, and cleared subcontractors, positioning Defensible as the trusted compliance-aligned cybersecurity partner. Build the partner and channel ecosystem. Develop and manage Managed Service Provider (MSP) / Managed Security Service Provider (MSSP), prime contractor, cloud, and advisory partnerships, including channel programs that unlock the SMB and mid-market DIB segments. Capitalize on the CMMC demand wave. Align messaging, offers, and partner motions to CMMC Phase 2/3 timelines and prime-driven flow-down requirements, ensuring Defensible is present before customers make their selections. Stand up GTM operating discipline. Establish forecasting cadence, pipeline analytics, operational dashboards, and GTM playbooks that improve predictability and execution velocity, and monitor the competitive landscape and customer needs to sharpen positioning - in partnership with the Director, Cybersecurity who owns pricing, cost, and performance models. Shape brand and demand generation. Direct marketing, content, events, and account-based marketing programs - working with shared SNC marketing and corporate communications and external agencies - to build awareness and a market-leading commercial cyber brand. Build and lead the team. Recruit, structure, and lead the dedicated Defensible commercial organization (marketing, partnerships, and sales) as the business scales through phased, milestone-gated investment. Represent SNC externally. Serve as a public face for Defensible through executive briefings, conferences, webinars, and industry working groups. Qualifications You Must Have: Bachelor's degree in Business, Marketing, Engineering, or a related field. 11+ years of experience in business development, sales, or a related field. Relevant experience can be considered as a substitute for the required educational qualifications. In the absence of a degree, a minimum of 15 years of related experience is required. Higher level relevant degree may substitute for experience. Advanced knowledge of US Department of Defense Military programs, Foreign Military Sales, and acquisition procedure. Ability to understand, analyze customer requirements and operations concepts and interpret, translate, and explain detailed technical ideas to a technical and non-technical audience. Progressive experience with technical marketing, proposal development, and program management or engineering design. Excellent written and oral communication skills and the ability to motivate/work with others. Mastery of Microsoft Office Suite. Substantial track record selling cybersecurity, managed security, compliance, or technology solutions. Proven success building partner and channel ecosystems (MSP/MSSP, prime contractor, cloud, or advisory) to expand indirect revenue. Experience developing account plans and capture plans for new business opportunities. Demonstrated ability to work with senior business and government leaders and to provide leadership within the workplace. Exceptional leadership, communication, and strategic planning skills. Working knowledge of the CMMC / Controlled Unclassified Information (CUI) compliance landscape and the Defense Industrial Base. Exceptional leadership, communication, and strategic planning skills. Availability to travel monthly for conferences, customer, and partner engagements. Ability to obtain and maintain a Secret U.S. Security Clearance; U.S. citizenship is required. Qualifications We Prefer: Direct leadership of a CMMC go-to-market program, or deep, hands-on involvement in the CMMC ecosystem since its inception. Experience marketing and selling SOCaaS, MSSP, or regulated/secure cloud offerings to defense and federally regulated customers. Established relationships across prime contractors, the DIB, federal stakeholders, and relevant industry associations or standards bodies. Experience scaling a cybersecurity revenue portfolio and building high-performing GTM organizations. Cyber AB Registered Practitioner (RP), Certified CMMC Professional (CCP/CCA), CISSP, or comparable industry credentials (held or in progress). Recognized thought leadership - speaking engagements, executive briefings, and industry committee participation. Familiarity with marketing-automation and sales-intelligence platforms (e.g., HubSpot/Marketo, 6sense, ZoomInfo) and analyst insights to inform strategy. Exposure to proposal coordination to ensure proposals are staffed and supported to achieve success. Essential Functions: Ability to sit at a desk and work on a computer for extended periods. Regular use of hand/finger dexterity for typing and writing. Ability to travel is required. Capability to work in an office or hybrid environment. This posting will be open for application for a minimum of 5 days and may be extended based on business needs. Estimated Starting Salary Range: $165,010.21 - $226,889.04. Compensation varies depending on a wide array of factors, such as candidates' key skills, relevant work experience, and education/training/certifications. The disclosed range estimate may be adjusted for any applicable geographic differential associated with the location at which the position may be filled. SNC offers annual incentive pay based upon performance that is commensurate with the level of the position. SNC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with 150% match up to 6%, life insurance, 3 weeks paid time off, tuition reimbursement, and more () . IMPORTANT NOTICE: This position requires the ability to obtain and maintain a Secret U.S. Security Clearance. U.S. Citizenship status is required as this position needs an active U.S. Security Clearance for employment. Non-U.S. citizens may not be eligible to obtain a security clearance. The Department of Defense Consolidated Adjudications Facility (DoD CAF), a federal government agency, handles the adjudicative aspects of the security clearance eligibility process for industry applicants . click apply for full job details
09/10/2026
Full time
Remote or hybrid or in office Lone Tree, CO Remote Full time R SNC can only hire in these states: AL, AK, AZ, CA, CO, FL, GA, HI, ID, IL, IN, KS, KY, LA, MD, MA, MI, MN, MS, MO, MT, NE, NV, NH, NJ, NM, NC, OH, OK, OR, PA, SC, TN, TX, UT, VA, WA, WV, WI. Sierra Nevada Company (SNC) is seeking a Senior Business Development Manager - Cyber to lead commercial growth for SNC Defensible Security, our defense-grade Security Operations Center-as-a-Service (SOCaaS) offering. Defensible Security delivers fully compliant, U.S.-based, U.S. Persons-only, 24x7 cybersecurity monitoring, alerting, and response purpose-built for the Defense Industrial Base (DIB) and federally regulated organizations. This role is the anchor leadership hire for Defensible's commercial go to market (GTM) motion - responsible for shaping and executing the strategy required to convert a substantial market opportunity into a scaled cybersecurity business. This senior commercial leader will build the pipeline, advance opportunities to close, grow the partner ecosystem, strengthen brand presence, and establish the operating discipline and team needed to drive Defensible Security's long term growth. The Cybersecurity Maturity Model Certification (CMMC) compliance wave is accelerating ahead of the formal Department of Defense (DoD) enforcement calendar, with prime contractors already imposing requirements across their supply chains. SNC's defense heritage, cleared status, and trusted security reputation position Defensible to win where heritage and compliance matter most. The Senior Business Development Manager will help drive the strategy and execution that captures this demand across priority customer cohorts. While Defensible Security is the primary focus, the role's scope spans SNC's commercial cyber portfolio, positioning the company to extend the same GTM motion to adjacent cyber offerings over time. The ISR (Intelligence, Surveillance & Reconnaissance), Aviation, and Security (IAS) business area is a leader in ISR and aviation, it is a leading prime manned and unmanned aircraft systems integrator for innovative, high-performance ISR and aviation systems. Its end-to-end Command, Control, Computers, Communications and Intelligence, Surveillance & Reconnaissance (C4ISR) capabilities encompass design, integration, test, certification, ground/flight training and complete logistics support. IAS tailors solutions to customer cost, performance, and schedule requirements and designs to consistently exceed expectations - with an unrivaled record of on time and on (or under) budget deliveries. Responsibilities: Own commercial GTM strategy. Define and execute the go-to-market strategy for Defensible Security across priority DIB and regulated-commercial cohorts, translating market opportunities into a prioritized pipeline and a credible bookings forecast. Drive revenue and pipeline. Carry the most senior selling responsibility directly - prospecting, qualifying, advancing, and closing opportunities - while building the demand-generation engine that produces marketing-sourced pipeline. Engage prime contractors and the DIB. Build executive relationships across prime contractors, defense manufacturers, the Intelligence Community, and cleared subcontractors, positioning Defensible as the trusted compliance-aligned cybersecurity partner. Build the partner and channel ecosystem. Develop and manage Managed Service Provider (MSP) / Managed Security Service Provider (MSSP), prime contractor, cloud, and advisory partnerships, including channel programs that unlock the SMB and mid-market DIB segments. Capitalize on the CMMC demand wave. Align messaging, offers, and partner motions to CMMC Phase 2/3 timelines and prime-driven flow-down requirements, ensuring Defensible is present before customers make their selections. Stand up GTM operating discipline. Establish forecasting cadence, pipeline analytics, operational dashboards, and GTM playbooks that improve predictability and execution velocity, and monitor the competitive landscape and customer needs to sharpen positioning - in partnership with the Director, Cybersecurity who owns pricing, cost, and performance models. Shape brand and demand generation. Direct marketing, content, events, and account-based marketing programs - working with shared SNC marketing and corporate communications and external agencies - to build awareness and a market-leading commercial cyber brand. Build and lead the team. Recruit, structure, and lead the dedicated Defensible commercial organization (marketing, partnerships, and sales) as the business scales through phased, milestone-gated investment. Represent SNC externally. Serve as a public face for Defensible through executive briefings, conferences, webinars, and industry working groups. Qualifications You Must Have: Bachelor's degree in Business, Marketing, Engineering, or a related field. 11+ years of experience in business development, sales, or a related field. Relevant experience can be considered as a substitute for the required educational qualifications. In the absence of a degree, a minimum of 15 years of related experience is required. Higher level relevant degree may substitute for experience. Advanced knowledge of US Department of Defense Military programs, Foreign Military Sales, and acquisition procedure. Ability to understand, analyze customer requirements and operations concepts and interpret, translate, and explain detailed technical ideas to a technical and non-technical audience. Progressive experience with technical marketing, proposal development, and program management or engineering design. Excellent written and oral communication skills and the ability to motivate/work with others. Mastery of Microsoft Office Suite. Substantial track record selling cybersecurity, managed security, compliance, or technology solutions. Proven success building partner and channel ecosystems (MSP/MSSP, prime contractor, cloud, or advisory) to expand indirect revenue. Experience developing account plans and capture plans for new business opportunities. Demonstrated ability to work with senior business and government leaders and to provide leadership within the workplace. Exceptional leadership, communication, and strategic planning skills. Working knowledge of the CMMC / Controlled Unclassified Information (CUI) compliance landscape and the Defense Industrial Base. Exceptional leadership, communication, and strategic planning skills. Availability to travel monthly for conferences, customer, and partner engagements. Ability to obtain and maintain a Secret U.S. Security Clearance; U.S. citizenship is required. Qualifications We Prefer: Direct leadership of a CMMC go-to-market program, or deep, hands-on involvement in the CMMC ecosystem since its inception. Experience marketing and selling SOCaaS, MSSP, or regulated/secure cloud offerings to defense and federally regulated customers. Established relationships across prime contractors, the DIB, federal stakeholders, and relevant industry associations or standards bodies. Experience scaling a cybersecurity revenue portfolio and building high-performing GTM organizations. Cyber AB Registered Practitioner (RP), Certified CMMC Professional (CCP/CCA), CISSP, or comparable industry credentials (held or in progress). Recognized thought leadership - speaking engagements, executive briefings, and industry committee participation. Familiarity with marketing-automation and sales-intelligence platforms (e.g., HubSpot/Marketo, 6sense, ZoomInfo) and analyst insights to inform strategy. Exposure to proposal coordination to ensure proposals are staffed and supported to achieve success. Essential Functions: Ability to sit at a desk and work on a computer for extended periods. Regular use of hand/finger dexterity for typing and writing. Ability to travel is required. Capability to work in an office or hybrid environment. This posting will be open for application for a minimum of 5 days and may be extended based on business needs. Estimated Starting Salary Range: $165,010.21 - $226,889.04. Compensation varies depending on a wide array of factors, such as candidates' key skills, relevant work experience, and education/training/certifications. The disclosed range estimate may be adjusted for any applicable geographic differential associated with the location at which the position may be filled. SNC offers annual incentive pay based upon performance that is commensurate with the level of the position. SNC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with 150% match up to 6%, life insurance, 3 weeks paid time off, tuition reimbursement, and more () . IMPORTANT NOTICE: This position requires the ability to obtain and maintain a Secret U.S. Security Clearance. U.S. Citizenship status is required as this position needs an active U.S. Security Clearance for employment. Non-U.S. citizens may not be eligible to obtain a security clearance. The Department of Defense Consolidated Adjudications Facility (DoD CAF), a federal government agency, handles the adjudicative aspects of the security clearance eligibility process for industry applicants . click apply for full job details
Senior Business Development Manager - Cyber Sierra Nevada Company (SNC) is seeking a Senior Business Development Manager - Cyber to lead commercial growth for SNC Defensible Security, our defense-grade Security Operations Center-as-a-Service (SOCaaS) offering. Defensible Security delivers fully compliant, U.S.-based, U.S. Persons-only, 24x7 cybersecurity monitoring, alerting, and response purpose-built for the Defense Industrial Base (DIB) and federally regulated organizations. This role is the anchor leadership hire for Defensible's commercial go to market (GTM) motion - responsible for shaping and executing the strategy required to convert a substantial market opportunity into a scaled cybersecurity business. This senior commercial leader will build the pipeline, advance opportunities to close, grow the partner ecosystem, strengthen brand presence, and establish the operating discipline and team needed to drive Defensible Security's long term growth. The Cybersecurity Maturity Model Certification (CMMC) compliance wave is accelerating ahead of the formal Department of Defense (DoD) enforcement calendar, with prime contractors already imposing requirements across their supply chains. SNC's defense heritage, cleared status, and trusted security reputation position Defensible to win where heritage and compliance matter most. The Senior Business Development Manager will help drive the strategy and execution that captures this demand across priority customer cohorts. While Defensible Security is the primary focus, the role's scope spans SNC's commercial cyber portfolio, positioning the company to extend the same GTM motion to adjacent cyber offerings over time. Responsibilities: Own commercial GTM strategy. Define and execute the go-to-market strategy for Defensible Security across priority DIB and regulated-commercial cohorts, translating market opportunities into a prioritized pipeline and a credible bookings forecast. Drive revenue and pipeline. Carry the most senior selling responsibility directly - prospecting, qualifying, advancing, and closing opportunities - while building the demand-generation engine that produces marketing-sourced pipeline. Engage prime contractors and the DIB. Build executive relationships across prime contractors, defense manufacturers, the Intelligence Community, and cleared subcontractors, positioning Defensible as the trusted compliance-aligned cybersecurity partner. Build the partner and channel ecosystem. Develop and manage Managed Service Provider (MSP) / Managed Security Service Provider (MSSP), prime contractor, cloud, and advisory partnerships, including channel programs that unlock the SMB and mid-market DIB segments. Capitalize on the CMMC demand wave. Align messaging, offers, and partner motions to CMMC Phase 2/3 timelines and prime-driven flow-down requirements, ensuring Defensible is present before customers make their selections. Stand up GTM operating discipline. Establish forecasting cadence, pipeline analytics, operational dashboards, and GTM playbooks that improve predictability and execution velocity, and monitor the competitive landscape and customer needs to sharpen positioning - in partnership with the Director, Cybersecurity who owns pricing, cost, and performance models. Shape brand and demand generation. Direct marketing, content, events, and account-based marketing programs - working with shared SNC marketing and corporate communications and external agencies - to build awareness and a market-leading commercial cyber brand. Build and lead the team. Recruit, structure, and lead the dedicated Defensible commercial organization (marketing, partnerships, and sales) as the business scales through phased, milestone-gated investment. Represent SNC externally. Serve as a public face for Defensible through executive briefings, conferences, webinars, and industry working groups. Qualifications You Must Have: Bachelor's degree in Business, Marketing, Engineering, or a related field. 11+ years of experience in business development, sales, or a related field. Relevant experience can be considered as a substitute for the required educational qualifications. In the absence of a degree, a minimum of 15 years of related experience is required. Higher level relevant degree may substitute for experience. Advanced knowledge of US Department of Defense Military programs, Foreign Military Sales, and acquisition procedure. Ability to understand, analyze customer requirements and operations concepts and interpret, translate, and explain detailed technical ideas to a technical and non-technical audience. Progressive experience with technical marketing, proposal development, and program management or engineering design. Excellent written and oral communication skills and the ability to motivate/work with others. Mastery of Microsoft Office Suite. Substantial track record selling cybersecurity, managed security, compliance, or technology solutions. Proven success building partner and channel ecosystems (MSP/MSSP, prime contractor, cloud, or advisory) to expand indirect revenue. Experience developing account plans and capture plans for new business opportunities. Demonstrated ability to work with senior business and government leaders and to provide leadership within the workplace. Exceptional leadership, communication, and strategic planning skills. Working knowledge of the CMMC / Controlled Unclassified Information (CUI) compliance landscape and the Defense Industrial Base. Exceptional leadership, communication, and strategic planning skills. Availability to travel monthly for conferences, customer, and partner engagements. Ability to obtain and maintain a Secret U.S. Security Clearance; U.S. citizenship is required. Qualifications We Prefer: Direct leadership of a CMMC go-to-market program, or deep, hands-on involvement in the CMMC ecosystem since its inception. Experience marketing and selling SOCaaS, MSSP, or regulated/secure cloud offerings to defense and federally regulated customers. Established relationships across prime contractors, the DIB, federal stakeholders, and relevant industry associations or standards bodies. Experience scaling a cybersecurity revenue portfolio and building high-performing GTM organizations. Cyber AB Registered Practitioner (RP), Certified CMMC Professional (CCP/CCA), CISSP, or comparable industry credentials (held or in progress). Recognized thought leadership - speaking engagements, executive briefings, and industry committee participation. Familiarity with marketing-automation and sales-intelligence platforms (e.g., HubSpot/Marketo, 6sense, ZoomInfo) and analyst insights to inform strategy. Exposure to proposal coordination to ensure proposals are staffed and supported to achieve success. Essential Functions: Ability to sit at a desk and work on a computer for extended periods. Regular use of hand/finger dexterity for typing and writing. Ability to travel is required. Capability to work in an office or hybrid environment. This posting will be open for application for a minimum of 5 days and may be extended based on business needs. Estimated Starting Salary Range: $165,010.21 - $226,889.04. Compensation varies depending on a wide array of factors, such as candidates' key skills, relevant work experience, and education/training/certifications. The disclosed range estimate may be adjusted for any applicable geographic differential associated with the location at which the position may be filled. SNC offers annual incentive pay based upon performance that is commensurate with the level of the position. SNC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with 150% match up to 6%, life insurance, 3 weeks paid time off, tuition reimbursement, and more. IMPORTANT NOTICE: This position requires the ability to obtain and maintain a Secret U.S. Security Clearance. U.S. Citizenship status is required as this position needs an active U.S. Security Clearance for employment. Non-U.S. citizens may not be eligible to obtain a security clearance. The Department of Defense Consolidated Adjudications Facility (DoD CAF), a federal government agency, handles the adjudicative aspects of the security clearance eligibility process for industry applicants. Adjudicative factors which affect the outcome of the eligibility determination include, but are not limited to, allegiance to the U.S., foreign influence, foreign preference, criminal conduct, security violations and illegal drug use. Learn more about the background check process for Security Clearances. SNC is a global leader in aerospace and national security committed to moving the American Dream forward. We're known and respected for our mission and execution focus, agility, and disruptive and rapid innovation. We provide leading edge technologies and transformative solutions that support our nation's most critical security needs. If you are mission-focused, thrive in collaborative environments, and want to make our country stronger with state-of-the-art technologies that safeguard freedom, join our team! SNC is an Equal Opportunity Employer committed to an environment free of discrimination. Employment decisions are made based on merit without regard to race, color, age, religion, sex, national origin, disability, status as a protected veteran or other characteristics
09/10/2026
Full time
Senior Business Development Manager - Cyber Sierra Nevada Company (SNC) is seeking a Senior Business Development Manager - Cyber to lead commercial growth for SNC Defensible Security, our defense-grade Security Operations Center-as-a-Service (SOCaaS) offering. Defensible Security delivers fully compliant, U.S.-based, U.S. Persons-only, 24x7 cybersecurity monitoring, alerting, and response purpose-built for the Defense Industrial Base (DIB) and federally regulated organizations. This role is the anchor leadership hire for Defensible's commercial go to market (GTM) motion - responsible for shaping and executing the strategy required to convert a substantial market opportunity into a scaled cybersecurity business. This senior commercial leader will build the pipeline, advance opportunities to close, grow the partner ecosystem, strengthen brand presence, and establish the operating discipline and team needed to drive Defensible Security's long term growth. The Cybersecurity Maturity Model Certification (CMMC) compliance wave is accelerating ahead of the formal Department of Defense (DoD) enforcement calendar, with prime contractors already imposing requirements across their supply chains. SNC's defense heritage, cleared status, and trusted security reputation position Defensible to win where heritage and compliance matter most. The Senior Business Development Manager will help drive the strategy and execution that captures this demand across priority customer cohorts. While Defensible Security is the primary focus, the role's scope spans SNC's commercial cyber portfolio, positioning the company to extend the same GTM motion to adjacent cyber offerings over time. Responsibilities: Own commercial GTM strategy. Define and execute the go-to-market strategy for Defensible Security across priority DIB and regulated-commercial cohorts, translating market opportunities into a prioritized pipeline and a credible bookings forecast. Drive revenue and pipeline. Carry the most senior selling responsibility directly - prospecting, qualifying, advancing, and closing opportunities - while building the demand-generation engine that produces marketing-sourced pipeline. Engage prime contractors and the DIB. Build executive relationships across prime contractors, defense manufacturers, the Intelligence Community, and cleared subcontractors, positioning Defensible as the trusted compliance-aligned cybersecurity partner. Build the partner and channel ecosystem. Develop and manage Managed Service Provider (MSP) / Managed Security Service Provider (MSSP), prime contractor, cloud, and advisory partnerships, including channel programs that unlock the SMB and mid-market DIB segments. Capitalize on the CMMC demand wave. Align messaging, offers, and partner motions to CMMC Phase 2/3 timelines and prime-driven flow-down requirements, ensuring Defensible is present before customers make their selections. Stand up GTM operating discipline. Establish forecasting cadence, pipeline analytics, operational dashboards, and GTM playbooks that improve predictability and execution velocity, and monitor the competitive landscape and customer needs to sharpen positioning - in partnership with the Director, Cybersecurity who owns pricing, cost, and performance models. Shape brand and demand generation. Direct marketing, content, events, and account-based marketing programs - working with shared SNC marketing and corporate communications and external agencies - to build awareness and a market-leading commercial cyber brand. Build and lead the team. Recruit, structure, and lead the dedicated Defensible commercial organization (marketing, partnerships, and sales) as the business scales through phased, milestone-gated investment. Represent SNC externally. Serve as a public face for Defensible through executive briefings, conferences, webinars, and industry working groups. Qualifications You Must Have: Bachelor's degree in Business, Marketing, Engineering, or a related field. 11+ years of experience in business development, sales, or a related field. Relevant experience can be considered as a substitute for the required educational qualifications. In the absence of a degree, a minimum of 15 years of related experience is required. Higher level relevant degree may substitute for experience. Advanced knowledge of US Department of Defense Military programs, Foreign Military Sales, and acquisition procedure. Ability to understand, analyze customer requirements and operations concepts and interpret, translate, and explain detailed technical ideas to a technical and non-technical audience. Progressive experience with technical marketing, proposal development, and program management or engineering design. Excellent written and oral communication skills and the ability to motivate/work with others. Mastery of Microsoft Office Suite. Substantial track record selling cybersecurity, managed security, compliance, or technology solutions. Proven success building partner and channel ecosystems (MSP/MSSP, prime contractor, cloud, or advisory) to expand indirect revenue. Experience developing account plans and capture plans for new business opportunities. Demonstrated ability to work with senior business and government leaders and to provide leadership within the workplace. Exceptional leadership, communication, and strategic planning skills. Working knowledge of the CMMC / Controlled Unclassified Information (CUI) compliance landscape and the Defense Industrial Base. Exceptional leadership, communication, and strategic planning skills. Availability to travel monthly for conferences, customer, and partner engagements. Ability to obtain and maintain a Secret U.S. Security Clearance; U.S. citizenship is required. Qualifications We Prefer: Direct leadership of a CMMC go-to-market program, or deep, hands-on involvement in the CMMC ecosystem since its inception. Experience marketing and selling SOCaaS, MSSP, or regulated/secure cloud offerings to defense and federally regulated customers. Established relationships across prime contractors, the DIB, federal stakeholders, and relevant industry associations or standards bodies. Experience scaling a cybersecurity revenue portfolio and building high-performing GTM organizations. Cyber AB Registered Practitioner (RP), Certified CMMC Professional (CCP/CCA), CISSP, or comparable industry credentials (held or in progress). Recognized thought leadership - speaking engagements, executive briefings, and industry committee participation. Familiarity with marketing-automation and sales-intelligence platforms (e.g., HubSpot/Marketo, 6sense, ZoomInfo) and analyst insights to inform strategy. Exposure to proposal coordination to ensure proposals are staffed and supported to achieve success. Essential Functions: Ability to sit at a desk and work on a computer for extended periods. Regular use of hand/finger dexterity for typing and writing. Ability to travel is required. Capability to work in an office or hybrid environment. This posting will be open for application for a minimum of 5 days and may be extended based on business needs. Estimated Starting Salary Range: $165,010.21 - $226,889.04. Compensation varies depending on a wide array of factors, such as candidates' key skills, relevant work experience, and education/training/certifications. The disclosed range estimate may be adjusted for any applicable geographic differential associated with the location at which the position may be filled. SNC offers annual incentive pay based upon performance that is commensurate with the level of the position. SNC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with 150% match up to 6%, life insurance, 3 weeks paid time off, tuition reimbursement, and more. IMPORTANT NOTICE: This position requires the ability to obtain and maintain a Secret U.S. Security Clearance. U.S. Citizenship status is required as this position needs an active U.S. Security Clearance for employment. Non-U.S. citizens may not be eligible to obtain a security clearance. The Department of Defense Consolidated Adjudications Facility (DoD CAF), a federal government agency, handles the adjudicative aspects of the security clearance eligibility process for industry applicants. Adjudicative factors which affect the outcome of the eligibility determination include, but are not limited to, allegiance to the U.S., foreign influence, foreign preference, criminal conduct, security violations and illegal drug use. Learn more about the background check process for Security Clearances. SNC is a global leader in aerospace and national security committed to moving the American Dream forward. We're known and respected for our mission and execution focus, agility, and disruptive and rapid innovation. We provide leading edge technologies and transformative solutions that support our nation's most critical security needs. If you are mission-focused, thrive in collaborative environments, and want to make our country stronger with state-of-the-art technologies that safeguard freedom, join our team! SNC is an Equal Opportunity Employer committed to an environment free of discrimination. Employment decisions are made based on merit without regard to race, color, age, religion, sex, national origin, disability, status as a protected veteran or other characteristics
SNC can only hire in these states: AL, AK, AZ, CA, CO, FL, GA, HI, ID, IL, IN, KS, KY, LA, MD, MA, MI, MN, MS, MO, MT, NE, NV, NH, NJ, NM, NC, OH, OK, OR, PA, SC, TN, TX, UT, VA, WA, WV, WI. Sierra Nevada Company (SNC) is seeking a Senior Business Development Manager - Cyber to lead commercial growth for SNC Defensible Security, our defense-grade Security Operations Center-as-a-Service (SOCaaS) offering. Defensible Security delivers fully compliant, U.S.-based, U.S. Persons-only, 24x7 cybersecurity monitoring, alerting, and response purpose-built for the Defense Industrial Base (DIB) and federally regulated organizations. This role is the anchor leadership hire for Defensible's commercial go to market (GTM) motion - responsible for shaping and executing the strategy required to convert a substantial market opportunity into a scaled cybersecurity business. This senior commercial leader will build the pipeline, advance opportunities to close, grow the partner ecosystem, strengthen brand presence, and establish the operating discipline and team needed to drive Defensible Security's long term growth. The Cybersecurity Maturity Model Certification (CMMC) compliance wave is accelerating ahead of the formal Department of Defense (DoD) enforcement calendar, with prime contractors already imposing requirements across their supply chains. SNC's defense heritage, cleared status, and trusted security reputation position Defensible to win where heritage and compliance matter most. The Senior Business Development Manager will help drive the strategy and execution that captures this demand across priority customer cohorts. While Defensible Security is the primary focus, the role's scope spans SNC's commercial cyber portfolio, positioning the company to extend the same GTM motion to adjacent cyber offerings over time. The ISR (Intelligence, Surveillance & Reconnaissance), Aviation, and Security (IAS) business area is a leader in ISR and aviation, it is a leading prime manned and unmanned aircraft systems integrator for innovative, high-performance ISR and aviation systems. Its end-to-end Command, Control, Computers, Communications and Intelligence, Surveillance & Reconnaissance (C4ISR) capabilities encompass design, integration, test, certification, ground/flight training and complete logistics support. IAS tailors solutions to customer cost, performance, and schedule requirements and designs to consistently exceed expectations - with an unrivaled record of on time and on (or under) budget deliveries. Responsibilities: Own commercial GTM strategy. Define and execute the go-to-market strategy for Defensible Security across priority DIB and regulated-commercial cohorts, translating market opportunities into a prioritized pipeline and a credible bookings forecast. Drive revenue and pipeline. Carry the most senior selling responsibility directly - prospecting, qualifying, advancing, and closing opportunities - while building the demand-generation engine that produces marketing-sourced pipeline. Engage prime contractors and the DIB. Build executive relationships across prime contractors, defense manufacturers, the Intelligence Community, and cleared subcontractors, positioning Defensible as the trusted compliance-aligned cybersecurity partner. Build the partner and channel ecosystem. Develop and manage Managed Service Provider (MSP) / Managed Security Service Provider (MSSP), prime contractor, cloud, and advisory partnerships, including channel programs that unlock the SMB and mid-market DIB segments. Capitalize on the CMMC demand wave. Align messaging, offers, and partner motions to CMMC Phase 2/3 timelines and prime-driven flow-down requirements, ensuring Defensible is present before customers make their selections. Stand up GTM operating discipline. Establish forecasting cadence, pipeline analytics, operational dashboards, and GTM playbooks that improve predictability and execution velocity, and monitor the competitive landscape and customer needs to sharpen positioning - in partnership with the Director, Cybersecurity who owns pricing, cost, and performance models. Shape brand and demand generation. Direct marketing, content, events, and account-based marketing programs - working with shared SNC marketing and corporate communications and external agencies - to build awareness and a market-leading commercial cyber brand. Build and lead the team. Recruit, structure, and lead the dedicated Defensible commercial organization (marketing, partnerships, and sales) as the business scales through phased, milestone-gated investment. Represent SNC externally. Serve as a public face for Defensible through executive briefings, conferences, webinars, and industry working groups. Qualifications You Must Have: Bachelor's degree in Business, Marketing, Engineering, or a related field. 11+ years of experience in business development, sales, or a related field. Relevant experience can be considered as a substitute for the required educational qualifications. In the absence of a degree, a minimum of 15 years of related experience is required. Higher level relevant degree may substitute for experience. Advanced knowledge of US Department of Defense Military programs, Foreign Military Sales, and acquisition procedure. Ability to understand, analyze customer requirements and operations concepts and interpret, translate, and explain detailed technical ideas to a technical and non-technical audience. Progressive experience with technical marketing, proposal development, and program management or engineering design. Excellent written and oral communication skills and the ability to motivate/work with others. Mastery of Microsoft Office Suite. Substantial track record selling cybersecurity, managed security, compliance, or technology solutions. Proven success building partner and channel ecosystems (MSP/MSSP, prime contractor, cloud, or advisory) to expand indirect revenue. Experience developing account plans and capture plans for new business opportunities. Demonstrated ability to work with senior business and government leaders and to provide leadership within the workplace. Exceptional leadership, communication, and strategic planning skills. Working knowledge of the CMMC / Controlled Unclassified Information (CUI) compliance landscape and the Defense Industrial Base. Exceptional leadership, communication, and strategic planning skills. Availability to travel monthly for conferences, customer, and partner engagements. Ability to obtain and maintain a Secret U.S. Security Clearance; U.S. citizenship is required. Qualifications We Prefer: Direct leadership of a CMMC go-to-market program, or deep, hands-on involvement in the CMMC ecosystem since its inception. Experience marketing and selling SOCaaS, MSSP, or regulated/secure cloud offerings to defense and federally regulated customers. Established relationships across prime contractors, the DIB, federal stakeholders, and relevant industry associations or standards bodies. Experience scaling a cybersecurity revenue portfolio and building high-performing GTM organizations. Cyber AB Registered Practitioner (RP), Certified CMMC Professional (CCP/CCA), CISSP, or comparable industry credentials (held or in progress). Recognized thought leadership - speaking engagements, executive briefings, and industry committee participation. Familiarity with marketing-automation and sales-intelligence platforms (e.g., HubSpot/Marketo, 6sense, ZoomInfo) and analyst insights to inform strategy. Exposure to proposal coordination to ensure proposals are staffed and supported to achieve success. Essential Functions: Ability to sit at a desk and work on a computer for extended periods. Regular use of hand/finger dexterity for typing and writing. Ability to travel is required. Capability to work in an office or hybrid environment. This posting will be open for application for a minimum of 5 days and may be extended based on business needs. Estimated Starting Salary Range: $165,010.21 - $226,889.04. Compensation varies depending on a wide array of factors, such as candidates' key skills, relevant work experience, and education/training/certifications. The disclosed range estimate may be adjusted for any applicable geographic differential associated with the location at which the position may be filled. SNC offers annual incentive pay based upon performance that is commensurate with the level of the position. SNC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with 150% match up to 6%, life insurance, 3 weeks paid time off, tuition reimbursement, and more. IMPORTANT NOTICE: This position requires the ability to obtain and maintain a Secret U.S. Security Clearance. U.S. Citizenship status is required as this position needs an active U.S. Security Clearance for employment. Non-U.S. citizens may not be eligible to obtain a security clearance. The Department of Defense Consolidated Adjudications Facility (DoD CAF), a federal government agency, handles the adjudicative aspects of the security clearance eligibility process for industry applicants. Adjudicative factors which affect the outcome of the eligibility determination include, but are not limited to, allegiance to the U.S., foreign influence . click apply for full job details
09/10/2026
Full time
SNC can only hire in these states: AL, AK, AZ, CA, CO, FL, GA, HI, ID, IL, IN, KS, KY, LA, MD, MA, MI, MN, MS, MO, MT, NE, NV, NH, NJ, NM, NC, OH, OK, OR, PA, SC, TN, TX, UT, VA, WA, WV, WI. Sierra Nevada Company (SNC) is seeking a Senior Business Development Manager - Cyber to lead commercial growth for SNC Defensible Security, our defense-grade Security Operations Center-as-a-Service (SOCaaS) offering. Defensible Security delivers fully compliant, U.S.-based, U.S. Persons-only, 24x7 cybersecurity monitoring, alerting, and response purpose-built for the Defense Industrial Base (DIB) and federally regulated organizations. This role is the anchor leadership hire for Defensible's commercial go to market (GTM) motion - responsible for shaping and executing the strategy required to convert a substantial market opportunity into a scaled cybersecurity business. This senior commercial leader will build the pipeline, advance opportunities to close, grow the partner ecosystem, strengthen brand presence, and establish the operating discipline and team needed to drive Defensible Security's long term growth. The Cybersecurity Maturity Model Certification (CMMC) compliance wave is accelerating ahead of the formal Department of Defense (DoD) enforcement calendar, with prime contractors already imposing requirements across their supply chains. SNC's defense heritage, cleared status, and trusted security reputation position Defensible to win where heritage and compliance matter most. The Senior Business Development Manager will help drive the strategy and execution that captures this demand across priority customer cohorts. While Defensible Security is the primary focus, the role's scope spans SNC's commercial cyber portfolio, positioning the company to extend the same GTM motion to adjacent cyber offerings over time. The ISR (Intelligence, Surveillance & Reconnaissance), Aviation, and Security (IAS) business area is a leader in ISR and aviation, it is a leading prime manned and unmanned aircraft systems integrator for innovative, high-performance ISR and aviation systems. Its end-to-end Command, Control, Computers, Communications and Intelligence, Surveillance & Reconnaissance (C4ISR) capabilities encompass design, integration, test, certification, ground/flight training and complete logistics support. IAS tailors solutions to customer cost, performance, and schedule requirements and designs to consistently exceed expectations - with an unrivaled record of on time and on (or under) budget deliveries. Responsibilities: Own commercial GTM strategy. Define and execute the go-to-market strategy for Defensible Security across priority DIB and regulated-commercial cohorts, translating market opportunities into a prioritized pipeline and a credible bookings forecast. Drive revenue and pipeline. Carry the most senior selling responsibility directly - prospecting, qualifying, advancing, and closing opportunities - while building the demand-generation engine that produces marketing-sourced pipeline. Engage prime contractors and the DIB. Build executive relationships across prime contractors, defense manufacturers, the Intelligence Community, and cleared subcontractors, positioning Defensible as the trusted compliance-aligned cybersecurity partner. Build the partner and channel ecosystem. Develop and manage Managed Service Provider (MSP) / Managed Security Service Provider (MSSP), prime contractor, cloud, and advisory partnerships, including channel programs that unlock the SMB and mid-market DIB segments. Capitalize on the CMMC demand wave. Align messaging, offers, and partner motions to CMMC Phase 2/3 timelines and prime-driven flow-down requirements, ensuring Defensible is present before customers make their selections. Stand up GTM operating discipline. Establish forecasting cadence, pipeline analytics, operational dashboards, and GTM playbooks that improve predictability and execution velocity, and monitor the competitive landscape and customer needs to sharpen positioning - in partnership with the Director, Cybersecurity who owns pricing, cost, and performance models. Shape brand and demand generation. Direct marketing, content, events, and account-based marketing programs - working with shared SNC marketing and corporate communications and external agencies - to build awareness and a market-leading commercial cyber brand. Build and lead the team. Recruit, structure, and lead the dedicated Defensible commercial organization (marketing, partnerships, and sales) as the business scales through phased, milestone-gated investment. Represent SNC externally. Serve as a public face for Defensible through executive briefings, conferences, webinars, and industry working groups. Qualifications You Must Have: Bachelor's degree in Business, Marketing, Engineering, or a related field. 11+ years of experience in business development, sales, or a related field. Relevant experience can be considered as a substitute for the required educational qualifications. In the absence of a degree, a minimum of 15 years of related experience is required. Higher level relevant degree may substitute for experience. Advanced knowledge of US Department of Defense Military programs, Foreign Military Sales, and acquisition procedure. Ability to understand, analyze customer requirements and operations concepts and interpret, translate, and explain detailed technical ideas to a technical and non-technical audience. Progressive experience with technical marketing, proposal development, and program management or engineering design. Excellent written and oral communication skills and the ability to motivate/work with others. Mastery of Microsoft Office Suite. Substantial track record selling cybersecurity, managed security, compliance, or technology solutions. Proven success building partner and channel ecosystems (MSP/MSSP, prime contractor, cloud, or advisory) to expand indirect revenue. Experience developing account plans and capture plans for new business opportunities. Demonstrated ability to work with senior business and government leaders and to provide leadership within the workplace. Exceptional leadership, communication, and strategic planning skills. Working knowledge of the CMMC / Controlled Unclassified Information (CUI) compliance landscape and the Defense Industrial Base. Exceptional leadership, communication, and strategic planning skills. Availability to travel monthly for conferences, customer, and partner engagements. Ability to obtain and maintain a Secret U.S. Security Clearance; U.S. citizenship is required. Qualifications We Prefer: Direct leadership of a CMMC go-to-market program, or deep, hands-on involvement in the CMMC ecosystem since its inception. Experience marketing and selling SOCaaS, MSSP, or regulated/secure cloud offerings to defense and federally regulated customers. Established relationships across prime contractors, the DIB, federal stakeholders, and relevant industry associations or standards bodies. Experience scaling a cybersecurity revenue portfolio and building high-performing GTM organizations. Cyber AB Registered Practitioner (RP), Certified CMMC Professional (CCP/CCA), CISSP, or comparable industry credentials (held or in progress). Recognized thought leadership - speaking engagements, executive briefings, and industry committee participation. Familiarity with marketing-automation and sales-intelligence platforms (e.g., HubSpot/Marketo, 6sense, ZoomInfo) and analyst insights to inform strategy. Exposure to proposal coordination to ensure proposals are staffed and supported to achieve success. Essential Functions: Ability to sit at a desk and work on a computer for extended periods. Regular use of hand/finger dexterity for typing and writing. Ability to travel is required. Capability to work in an office or hybrid environment. This posting will be open for application for a minimum of 5 days and may be extended based on business needs. Estimated Starting Salary Range: $165,010.21 - $226,889.04. Compensation varies depending on a wide array of factors, such as candidates' key skills, relevant work experience, and education/training/certifications. The disclosed range estimate may be adjusted for any applicable geographic differential associated with the location at which the position may be filled. SNC offers annual incentive pay based upon performance that is commensurate with the level of the position. SNC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with 150% match up to 6%, life insurance, 3 weeks paid time off, tuition reimbursement, and more. IMPORTANT NOTICE: This position requires the ability to obtain and maintain a Secret U.S. Security Clearance. U.S. Citizenship status is required as this position needs an active U.S. Security Clearance for employment. Non-U.S. citizens may not be eligible to obtain a security clearance. The Department of Defense Consolidated Adjudications Facility (DoD CAF), a federal government agency, handles the adjudicative aspects of the security clearance eligibility process for industry applicants. Adjudicative factors which affect the outcome of the eligibility determination include, but are not limited to, allegiance to the U.S., foreign influence . click apply for full job details
Invictus International Consulting, LLC
Colorado Springs, Colorado
Job Description Job Description Title: Senior Cybersecurity Threat Hunter III Location: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Lead complex, hypothesis-driven threat hunts across multiple enterprise data sources and enclaves to identify sophisticated or previously undetected adversary activityProactively analyze security telemetry to identify indicators of compromise, anomalous behavior, and adversary activity that has not met an incident threshold or has evaded automated security controlsAssess and correlate data from multiple sources, including network, endpoint, identity, SIEM, threat intelligence, vulnerability, and other available security dataDocument hunt activity, findings, evidence, and recommended follow-on actions in authorized systems and initiate or support incident-response processes when malicious activity is identifiedProvide relevant findings and trends for SOC operational reporting, significant-activity reporting, and defensive awarenessDevelop and prioritize hunt campaigns based on threat intelligence, mission risk, adversary TTPs, detection coverage, incident lessons learned, and environmental changesPerform advanced behavioral analysis and identify patterns indicative of persistence, credential abuse, lateral movement, command and control, collection, or other adversary activityServe as an escalation point for junior threat analysts and provide technical guidance on hunt methodology, analytical pivots, and evidence validationTranslate successful hunt findings into actionable requirements for detection engineering, watch operations, security engineering, and incident responseDevelop reusable hunt playbooks, queries, analytic methods, documentation standards, and training materialsMentor junior personnel and support exercises, knowledge sharing, and assessment of threat-analysis proficiency Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum six (6) years of relevant experience in addition to education level Significant hands-on experience conducting threat hunting, advanced cyber analysis, or adversary-focused investigationsStrong knowledge of MITRE ATT&CK, adversary TTPs, threat intelligence application, and network/host/identity security telemetryExperience developing hunt hypotheses and converting analytical findings into detection or defensive improvementsExperience mentoring analysts or leading complex analytical effortsMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
09/10/2026
Full time
Job Description Job Description Title: Senior Cybersecurity Threat Hunter III Location: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Lead complex, hypothesis-driven threat hunts across multiple enterprise data sources and enclaves to identify sophisticated or previously undetected adversary activityProactively analyze security telemetry to identify indicators of compromise, anomalous behavior, and adversary activity that has not met an incident threshold or has evaded automated security controlsAssess and correlate data from multiple sources, including network, endpoint, identity, SIEM, threat intelligence, vulnerability, and other available security dataDocument hunt activity, findings, evidence, and recommended follow-on actions in authorized systems and initiate or support incident-response processes when malicious activity is identifiedProvide relevant findings and trends for SOC operational reporting, significant-activity reporting, and defensive awarenessDevelop and prioritize hunt campaigns based on threat intelligence, mission risk, adversary TTPs, detection coverage, incident lessons learned, and environmental changesPerform advanced behavioral analysis and identify patterns indicative of persistence, credential abuse, lateral movement, command and control, collection, or other adversary activityServe as an escalation point for junior threat analysts and provide technical guidance on hunt methodology, analytical pivots, and evidence validationTranslate successful hunt findings into actionable requirements for detection engineering, watch operations, security engineering, and incident responseDevelop reusable hunt playbooks, queries, analytic methods, documentation standards, and training materialsMentor junior personnel and support exercises, knowledge sharing, and assessment of threat-analysis proficiency Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum six (6) years of relevant experience in addition to education level Significant hands-on experience conducting threat hunting, advanced cyber analysis, or adversary-focused investigationsStrong knowledge of MITRE ATT&CK, adversary TTPs, threat intelligence application, and network/host/identity security telemetryExperience developing hunt hypotheses and converting analytical findings into detection or defensive improvementsExperience mentoring analysts or leading complex analytical effortsMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
Invictus International Consulting, LLC
Colorado Springs, Colorado
Job Description Job Description Title: Senior Cyber Defense Analyst IIILocation: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Perform and lead advanced investigation of complex security events and incidents across network, endpoint, identity, firewall, vulnerability, and other available telemetryPerform cyber defense incident triage, including validation, enrichment, determination of scope, urgency, potential impact, and appropriate escalationSupport incident handling across detection, investigation, analysis, containment/remediation coordination, recovery, and reporting in accordance with established authorities and proceduresCorrelate incident and security data across multiple sources to identify affected systems, users, vulnerabilities, adversary activity, and related eventsCollect and preserve relevant intrusion artifacts and investigative evidence in accordance with established proceduresCommunicate incident status, findings, risk, and recommended actions to SOC personnel, technical teams, management, and government stakeholders as appropriateServe as a senior technical escalation point to less expereinced team members and provide hands-on guidance during complex investigationsLead portions of incident response activities, including scoping, evidence analysis, containment recommendations, technical coordination, and post-incident reviewConduct proactive analysis and threat hunting when warranted to identify related or previously undetected activityDevelop, maintain, and improve analyst runbooks, investigative procedures, escalation criteria, incident playbooks, and shift-turnover practicesPartner with threat analysts and engineering personnel to identify telemetry gaps, detection gaps, false positives, and opportunities for improved enrichment or automationMentor junior analysts, support analyst qualification and exercises, and perform quality review of investigations and case documentationTranslate incident lessons learned into improved detections, procedures, training, and defensive recommendations Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum six (6) years of relevant experience in addition to education level Significant hands-on experience conducting cybersecurity investigations and incident response in enterprise environments.Strong knowledge of network and host-based investigation, common adversary tactics, techniques, and procedures, and the MITRE ATT&CK frameworkExperience developing or improving SOC procedures, incident playbooks, runbooks, or analyst training materialsExperience serving as an escalation point, technical lead, or mentor for cyber defense analystsMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
09/10/2026
Full time
Job Description Job Description Title: Senior Cyber Defense Analyst IIILocation: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Perform and lead advanced investigation of complex security events and incidents across network, endpoint, identity, firewall, vulnerability, and other available telemetryPerform cyber defense incident triage, including validation, enrichment, determination of scope, urgency, potential impact, and appropriate escalationSupport incident handling across detection, investigation, analysis, containment/remediation coordination, recovery, and reporting in accordance with established authorities and proceduresCorrelate incident and security data across multiple sources to identify affected systems, users, vulnerabilities, adversary activity, and related eventsCollect and preserve relevant intrusion artifacts and investigative evidence in accordance with established proceduresCommunicate incident status, findings, risk, and recommended actions to SOC personnel, technical teams, management, and government stakeholders as appropriateServe as a senior technical escalation point to less expereinced team members and provide hands-on guidance during complex investigationsLead portions of incident response activities, including scoping, evidence analysis, containment recommendations, technical coordination, and post-incident reviewConduct proactive analysis and threat hunting when warranted to identify related or previously undetected activityDevelop, maintain, and improve analyst runbooks, investigative procedures, escalation criteria, incident playbooks, and shift-turnover practicesPartner with threat analysts and engineering personnel to identify telemetry gaps, detection gaps, false positives, and opportunities for improved enrichment or automationMentor junior analysts, support analyst qualification and exercises, and perform quality review of investigations and case documentationTranslate incident lessons learned into improved detections, procedures, training, and defensive recommendations Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum six (6) years of relevant experience in addition to education level Significant hands-on experience conducting cybersecurity investigations and incident response in enterprise environments.Strong knowledge of network and host-based investigation, common adversary tactics, techniques, and procedures, and the MITRE ATT&CK frameworkExperience developing or improving SOC procedures, incident playbooks, runbooks, or analyst training materialsExperience serving as an escalation point, technical lead, or mentor for cyber defense analystsMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
Invictus International Consulting, LLC
Colorado Springs, Colorado
Job Description Job Description Title: Senior Cybersecurity Risk & Exposure Analyst III Location: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Lead complex operational cyber risk and exposure analysis supporting SOC investigations, threat-informed vulnerability prioritization, continuous monitoring, and remediation activities across DoD systems and sitesCorrelate vulnerability data, asset discovery, system criticality, network reachability, security configuration, known controls, threat activity, and SOC findings to identify exposures that present the greatest operational or mission riskAnalyze vulnerabilities and configuration weaknesses in context, including plausible exploitation paths, adversary TTPs, affected technologies, compensating controls, mission/availability impact, and evidence from active or historical SOC investigationsServe as a senior technical resource to Cybersecurity Operations and Threat Analysts for vulnerability, asset, control, and system-security context during complex investigations and proactive hunting activitiesCoordinate with system ISSOs/ISSMs, system owners, engineers, administrators, authorization personnel, and remediation teams to translate SOC-derived findings into actionable mitigation, continuous-monitoring, POA&M, or RMF follow-up as applicableDevelop and maintain operational exposure-analysis procedures, risk-prioritization methods, technical checklists, TTPs, guides, briefings, and other products that improve consistency and decision qualityReview remediation evidence, recurring findings, exposure trends, POA&M-related items, and metrics to identify systemic risk, validate corrective actions, and drive closure or escalationSupport RMF and assessment activities where SOC findings or operational exposure data affect security-control effectiveness, system risk, or authorization posture, while coordinating with the responsible system security personnelMentor Level I and II personnel and review analytical work products for technical accuracy, risk context, completeness, and clear communication Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum six (6) years of relevant experience in addition to education level Demonstrated knowledge of vulnerability/exposure management, threat-informed risk analysis, DoD continuous monitoring, RMF/security controls, network/system security, and technical risk assessmentExperience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and coordination with SOC/incident-response and ISSO/ISSM functions is desiredDemonstrated experience leading complex exposure or vulnerability analysis, prioritizing technical risk, coordinating remediation, and translating cyber findings into continuous-monitoring or RMF actions is strongly desiredMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
09/10/2026
Full time
Job Description Job Description Title: Senior Cybersecurity Risk & Exposure Analyst III Location: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Lead complex operational cyber risk and exposure analysis supporting SOC investigations, threat-informed vulnerability prioritization, continuous monitoring, and remediation activities across DoD systems and sitesCorrelate vulnerability data, asset discovery, system criticality, network reachability, security configuration, known controls, threat activity, and SOC findings to identify exposures that present the greatest operational or mission riskAnalyze vulnerabilities and configuration weaknesses in context, including plausible exploitation paths, adversary TTPs, affected technologies, compensating controls, mission/availability impact, and evidence from active or historical SOC investigationsServe as a senior technical resource to Cybersecurity Operations and Threat Analysts for vulnerability, asset, control, and system-security context during complex investigations and proactive hunting activitiesCoordinate with system ISSOs/ISSMs, system owners, engineers, administrators, authorization personnel, and remediation teams to translate SOC-derived findings into actionable mitigation, continuous-monitoring, POA&M, or RMF follow-up as applicableDevelop and maintain operational exposure-analysis procedures, risk-prioritization methods, technical checklists, TTPs, guides, briefings, and other products that improve consistency and decision qualityReview remediation evidence, recurring findings, exposure trends, POA&M-related items, and metrics to identify systemic risk, validate corrective actions, and drive closure or escalationSupport RMF and assessment activities where SOC findings or operational exposure data affect security-control effectiveness, system risk, or authorization posture, while coordinating with the responsible system security personnelMentor Level I and II personnel and review analytical work products for technical accuracy, risk context, completeness, and clear communication Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum six (6) years of relevant experience in addition to education level Demonstrated knowledge of vulnerability/exposure management, threat-informed risk analysis, DoD continuous monitoring, RMF/security controls, network/system security, and technical risk assessmentExperience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and coordination with SOC/incident-response and ISSO/ISSM functions is desiredDemonstrated experience leading complex exposure or vulnerability analysis, prioritizing technical risk, coordinating remediation, and translating cyber findings into continuous-monitoring or RMF actions is strongly desiredMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
Invictus International Consulting, LLC
Colorado Springs, Colorado
Job Description Job Description Title: Lead Cybersecurity Risk & Exposure Subject Matter Expert IV Location: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Serve as the senior SME for operational cyber risk, vulnerability/exposure analysis, and continuous monitoring supporting a DoD cyber defense missionEstablish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize the exposures most likely to create operational or mission riskLead complex exposure and impact assessments, including development of plausible exploitation scenarios, attack paths, affected-system analysis, compensating-control considerations, and risk-informed courses of actionProvide expert vulnerability, asset, architecture, and security-control context to SOC leadership, Cybersecurity Operations Analysts, Threat Analysts, incident responders, and engineering teams during significant investigations and proactive defensive activityLead analysis of ACAS/Tenable results, runZero asset information, STIG/configuration findings, system documentation, and other approved data to identify systemic weaknesses, exploitable conditions, and remediation prioritiesOwn the SOC-side process for coordinating material cyber findings with affected system ISSOs/ISSMs, system owners, administrators, engineers, and authorization stakeholders; ensure operational findings are translated into appropriate mitigation, continuous-monitoring, POA&M, or RMF actions without duplicating system ISSO responsibilitiesEstablish and maintain checklists, TTPs, guides, procedures, quality standards, and reporting methods for exposure analysis, risk prioritization, remediation validation, and SOC-to-system-security coordinationLead review of remediation evidence, recurring vulnerabilities, exposure trends, control weaknesses, and SOC-derived findings to identify systemic risk and recommend enterprise or site-level corrective actionsDevelop briefings, executive summaries, risk assessments, metrics, dashboards, and technical products that communicate operational exposure, remediation progress, control effectiveness, and mission impact to technical and leadership audiencesAdvise SOC leadership on vulnerability/exposure trends, high-risk assets, recurring security weaknesses, remediation priorities, and opportunities to improve the integration of vulnerability management, threat information, and cyber defense operationsMentor senior and developing analysts and provide technical quality review of exposure assessments, risk conclusions, remediation recommendations, and stakeholder coordination productsExperience integrating vulnerability management, continuous monitoring, RMF/ISSO processes, and SOC or incident-response operations in a DoD/IC or similarly complex enterprise environment is highly desired Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum of eight (8) years of relevant experience in addition to education level Demonstrated expert knowledge of vulnerability/exposure management, threat-informed risk analysis, DoD continuous monitoring, RMF/security controls, network/system security, and technical risk assessmentExperience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desiredDemonstrated experience establishing exposure-analysis methodology, leading complex risk assessments, prioritizing remediation, and translating operational cyber findings into continuous-monitoring or RMF actions is strongly desiredMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environmentCurrent active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
09/10/2026
Full time
Job Description Job Description Title: Lead Cybersecurity Risk & Exposure Subject Matter Expert IV Location: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Serve as the senior SME for operational cyber risk, vulnerability/exposure analysis, and continuous monitoring supporting a DoD cyber defense missionEstablish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize the exposures most likely to create operational or mission riskLead complex exposure and impact assessments, including development of plausible exploitation scenarios, attack paths, affected-system analysis, compensating-control considerations, and risk-informed courses of actionProvide expert vulnerability, asset, architecture, and security-control context to SOC leadership, Cybersecurity Operations Analysts, Threat Analysts, incident responders, and engineering teams during significant investigations and proactive defensive activityLead analysis of ACAS/Tenable results, runZero asset information, STIG/configuration findings, system documentation, and other approved data to identify systemic weaknesses, exploitable conditions, and remediation prioritiesOwn the SOC-side process for coordinating material cyber findings with affected system ISSOs/ISSMs, system owners, administrators, engineers, and authorization stakeholders; ensure operational findings are translated into appropriate mitigation, continuous-monitoring, POA&M, or RMF actions without duplicating system ISSO responsibilitiesEstablish and maintain checklists, TTPs, guides, procedures, quality standards, and reporting methods for exposure analysis, risk prioritization, remediation validation, and SOC-to-system-security coordinationLead review of remediation evidence, recurring vulnerabilities, exposure trends, control weaknesses, and SOC-derived findings to identify systemic risk and recommend enterprise or site-level corrective actionsDevelop briefings, executive summaries, risk assessments, metrics, dashboards, and technical products that communicate operational exposure, remediation progress, control effectiveness, and mission impact to technical and leadership audiencesAdvise SOC leadership on vulnerability/exposure trends, high-risk assets, recurring security weaknesses, remediation priorities, and opportunities to improve the integration of vulnerability management, threat information, and cyber defense operationsMentor senior and developing analysts and provide technical quality review of exposure assessments, risk conclusions, remediation recommendations, and stakeholder coordination productsExperience integrating vulnerability management, continuous monitoring, RMF/ISSO processes, and SOC or incident-response operations in a DoD/IC or similarly complex enterprise environment is highly desired Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum of eight (8) years of relevant experience in addition to education level Demonstrated expert knowledge of vulnerability/exposure management, threat-informed risk analysis, DoD continuous monitoring, RMF/security controls, network/system security, and technical risk assessmentExperience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desiredDemonstrated experience establishing exposure-analysis methodology, leading complex risk assessments, prioritizing remediation, and translating operational cyber findings into continuous-monitoring or RMF actions is strongly desiredMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environmentCurrent active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
Invictus International Consulting, LLC
Colorado Springs, Colorado
Job Description Job Description Title: Cybersecurity Threat Analyst Subject Matter Expert IV Location: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Serve as the senior technical authority for proactive threat hunting and adversary-focused analysis within the SOCLead development of the SOC threat-hunting methodology, hunt lifecycle, prioritization model, documentation standards, quality criteria, and integration with watch operations and engineeringProactively search across enterprise network, endpoint, identity, SIEM, and other security telemetry for indicators of compromise and behavioral evidence of malicious activity that has evaded automated detectionDevelop and direct advanced hunt campaigns based on threat intelligence, adversary TTPs, mission priorities, predictive/advanced analytics, environmental changes, incidents, and identified detection gapsAssess and validate analytical or predictive models and determine whether identified patterns represent meaningful adversary behavior, benign activity, or require additional collection and analysisLead complex analytical pivots across multiple sources and enclaves and direct expansion of scope when evidence indicates broader adversary activityEnsure actionable hunt findings are transitioned to incident response, watch operations, detection engineering, or security engineering with clear evidence and recommended actionsProvide senior technical input to daily/weekly SOC reporting, leadership briefings, threat assessments, and defensive prioritiesEstablish reusable hunt playbooks, analytical techniques, ATT&CK mappings, queries, knowledge repositories, and lessons-learned processesMentor threat analysts at all levels and provide technical leadership for exercises, training, and proficiency developmentIdentify telemetry and detection blind spots and work with engineering teams to improve collection, analytics, enrichment, and automated detection coverage Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum of eight (8) years of relevant experience in addition to education level Expert-level hands-on experience in threat hunting, adversary analysis, advanced cyber defense analysis, or closely related workDemonstrated experience leading complex hunt campaigns and identifying malicious activity not detected through routine alertingExpert knowledge of adversary TTPs, MITRE ATT&CK, threat intelligence operationalization, network/endpoint/identity telemetry, and analytical methodologiesExperience establishing or materially improving a threat-hunting or proactive cyber-defense programExperience translating hunt findings into detection engineering requirements and measurable defensive improvementsMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
09/10/2026
Full time
Job Description Job Description Title: Cybersecurity Threat Analyst Subject Matter Expert IV Location: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Serve as the senior technical authority for proactive threat hunting and adversary-focused analysis within the SOCLead development of the SOC threat-hunting methodology, hunt lifecycle, prioritization model, documentation standards, quality criteria, and integration with watch operations and engineeringProactively search across enterprise network, endpoint, identity, SIEM, and other security telemetry for indicators of compromise and behavioral evidence of malicious activity that has evaded automated detectionDevelop and direct advanced hunt campaigns based on threat intelligence, adversary TTPs, mission priorities, predictive/advanced analytics, environmental changes, incidents, and identified detection gapsAssess and validate analytical or predictive models and determine whether identified patterns represent meaningful adversary behavior, benign activity, or require additional collection and analysisLead complex analytical pivots across multiple sources and enclaves and direct expansion of scope when evidence indicates broader adversary activityEnsure actionable hunt findings are transitioned to incident response, watch operations, detection engineering, or security engineering with clear evidence and recommended actionsProvide senior technical input to daily/weekly SOC reporting, leadership briefings, threat assessments, and defensive prioritiesEstablish reusable hunt playbooks, analytical techniques, ATT&CK mappings, queries, knowledge repositories, and lessons-learned processesMentor threat analysts at all levels and provide technical leadership for exercises, training, and proficiency developmentIdentify telemetry and detection blind spots and work with engineering teams to improve collection, analytics, enrichment, and automated detection coverage Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum of eight (8) years of relevant experience in addition to education level Expert-level hands-on experience in threat hunting, adversary analysis, advanced cyber defense analysis, or closely related workDemonstrated experience leading complex hunt campaigns and identifying malicious activity not detected through routine alertingExpert knowledge of adversary TTPs, MITRE ATT&CK, threat intelligence operationalization, network/endpoint/identity telemetry, and analytical methodologiesExperience establishing or materially improving a threat-hunting or proactive cyber-defense programExperience translating hunt findings into detection engineering requirements and measurable defensive improvementsMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
Invictus International Consulting, LLC
Colorado Springs, Colorado
Job Description Job Description Title: Cybersecurity Watch Operations Subject Matter Expert IVLocation: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Serve as the senior hands-on technical authority for SOC watch operations and a founding operational SME for the establishment and maturation of a new DoD SOCLead the most complex cyber defense investigations and incident-response activities and provide technical direction when scope, impact, evidence, or response options are uncertainPerform advanced forensic and security analysis of digital information, host and network telemetry, firewall and IDS/IPS data, authentication activity, intrusion artifacts, and other relevant evidenceEstablish and continuously improve investigative methodology, triage standards, severity and escalation criteria, evidence requirements, incident workflows, case-quality standards, and shift-turnover practicesProvide senior technical guidance to SOC management on watch readiness, investigative quality, operational risk, staffing proficiency, capability gaps, and response considerationsServe as the highest-level operational escalation point for Cybersecurity Operations Analysts and mentor senior and developing personnel through complex investigations and exercisesCoordinate complex incidents with government stakeholders, incident response organizations, system owners, administrators, network/security engineers, and other agencies as requiredPartner with cybersecurity engineering personnel to translate watch-operations requirements into actionable telemetry, SIEM/SOAR, network monitoring, firewall, endpoint, enrichment, and automation capabilitiesIdentify systemic visibility, detection, workflow, tooling, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security postureLead development and validation of SOPs, runbooks, incident-response playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions.Conduct or direct proactive threat hunting and advanced analysis to identify malicious activity not detected by automated controls and to validate the effectiveness of existing defensesAnalyze trends across incidents and investigations and provide technical input to operational metrics, significant-activity reporting, leadership briefings, and defensive prioritiesApply network forensics, host analysis, malware-analysis concepts, vulnerability context, and threat-informed defense techniques as appropriate to complex investigations; advanced malware reverse engineering or penetration-testing experience is beneficial but not required Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum of eight (8) years of relevant experience in addition to education level Expert-level hands-on experience in SOC operations, cyber defense analysis, incident investigation, and incident response in complex enterprise environmentsDemonstrated experience leading complex investigations while remaining technically hands-on.Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, incident workflows, or analyst qualification/training programsStrong knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, and adversary TTPsExperience collaborating with SIEM/SOAR, detection, network-security, endpoint, vulnerability, and other cybersecurity engineering teamsExperience helping establish, transform, or mature a SOC, CSIRT, or cyber defense capability is highly desiredMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
09/10/2026
Full time
Job Description Job Description Title: Cybersecurity Watch Operations Subject Matter Expert IVLocation: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Serve as the senior hands-on technical authority for SOC watch operations and a founding operational SME for the establishment and maturation of a new DoD SOCLead the most complex cyber defense investigations and incident-response activities and provide technical direction when scope, impact, evidence, or response options are uncertainPerform advanced forensic and security analysis of digital information, host and network telemetry, firewall and IDS/IPS data, authentication activity, intrusion artifacts, and other relevant evidenceEstablish and continuously improve investigative methodology, triage standards, severity and escalation criteria, evidence requirements, incident workflows, case-quality standards, and shift-turnover practicesProvide senior technical guidance to SOC management on watch readiness, investigative quality, operational risk, staffing proficiency, capability gaps, and response considerationsServe as the highest-level operational escalation point for Cybersecurity Operations Analysts and mentor senior and developing personnel through complex investigations and exercisesCoordinate complex incidents with government stakeholders, incident response organizations, system owners, administrators, network/security engineers, and other agencies as requiredPartner with cybersecurity engineering personnel to translate watch-operations requirements into actionable telemetry, SIEM/SOAR, network monitoring, firewall, endpoint, enrichment, and automation capabilitiesIdentify systemic visibility, detection, workflow, tooling, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security postureLead development and validation of SOPs, runbooks, incident-response playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions.Conduct or direct proactive threat hunting and advanced analysis to identify malicious activity not detected by automated controls and to validate the effectiveness of existing defensesAnalyze trends across incidents and investigations and provide technical input to operational metrics, significant-activity reporting, leadership briefings, and defensive prioritiesApply network forensics, host analysis, malware-analysis concepts, vulnerability context, and threat-informed defense techniques as appropriate to complex investigations; advanced malware reverse engineering or penetration-testing experience is beneficial but not required Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum of eight (8) years of relevant experience in addition to education level Expert-level hands-on experience in SOC operations, cyber defense analysis, incident investigation, and incident response in complex enterprise environmentsDemonstrated experience leading complex investigations while remaining technically hands-on.Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, incident workflows, or analyst qualification/training programsStrong knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, and adversary TTPsExperience collaborating with SIEM/SOAR, detection, network-security, endpoint, vulnerability, and other cybersecurity engineering teamsExperience helping establish, transform, or mature a SOC, CSIRT, or cyber defense capability is highly desiredMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
Job Description Job Description SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense contractor that delivers advanced technologies in support of U.S. National Security and Defense. For the past forty-five plus years, we have supported Department of Defense customers by developing innovative remote sensing algorithms, tools, and techniques to deliver world-class data exploitation capabilities supporting missile defense; intelligence, surveillance, & reconnaissance; space domain awareness; and aircraft survivability missions. Important Notice: SciTec exclusively works on U.S. government contracts that require U.S. citizenship for all employees. Applicants that do not meet this requirement will not be considered. SciTec has immediate opportunities for an experienced Senior Cybersecurity Engineer to work in either our Boulder, CO or Princeton, NJ office. Responsibilities: Serve as the CrowdStrike technical lead, leading implementation and integration across virtual, physical, and cloud environments. (AWS/Azure) Harden and secure mission infrastructure assets, including servers, network devices, storage systems, and supporting platforms Provide expertise to the vulnerability management process, including but not limited to risk prioritization based on environment and remediation actions. (Tools include Tenable, NinjaOne) Collaborate with Infrastructure teams to provide cybersecurity input to system architecture, enclave segmentation, and infrastructure design decisions Serves as technical lead for CMMC/NIST 800-171 requirements Create and maintain SIEM queries in response to emerging threats around environment. Develop and maintain CrowdStrike NG-SIEM log parsing Ensure logging, monitoring, and access controls meet security and compliance requirements Identify and mitigate operational cybersecurity risks across the asset lifecycle Support incident response preparation and forensic readiness efforts Communicate cybersecurity posture, risks, and remediation plans to technical and program leadership Other duties as assigned Requirements Bachelor's degree in Cybersecurity, Computer Science, Engineering, or related field CompTIA Cybersecurity Analyst (CySa+) or similar certification 6+ years of professional experience in cybersecurity engineering 2+ years of experience using CrowdStrike EDR and NG-SIEM Professional technical experience with NIST 800-171 / CMMC controls Experience conducting vulnerability scanning and remediation Strong understanding of Linux systems security Strong understanding of Windows systems security Strong understanding of Active Directory and IAM Security Best Practices Experience with scripting languages, such as Python, PowerShell or Bash Familiarity with network security concepts and segmentation Ability to obtain and maintain a DoD security clearance Strong documentation and communication skills Proven oral and written communication skills Strong attention to detail Candidates who have any of the following skills will be preferred: Professional experience in Cloud Security (AWS / Azure) Experience integrating security into DevSecOps pipelines GIAC Certified Incident Handler (GCIH) certification CrowdStrike Certified Falcon Administrator (CCFA) certification Benefits SciTec offers a highly competitive salary and benefits package, including: 4% Safe Harbor 401(k) match 100% company paid HSA Medical insurance, with a choice of 2 buy-up options 80% company paid Dental insurance 100% company paid Vision insurance 100% company paid Life insurance 100% company paid Long-term Disability insurance 100% company paid Hospital Indemnity insurance Voluntary Accident and Critical Illness insurance Short-term Disability insurance Annual Profit-Sharing Plan Discretionary Performance Bonus Paid Parental Leave Generous Paid Time Off, including Holiday, Vacation, and Sick Pay Flexible Work Hours The pay range for this position is $124,000 - $158,000 / year. SciTec considers several factors when extending an offer of employment, including but not limited to the role and associated responsibilities, a candidate's work experience, education/training, and key skills. This is not a guarantee of compensation. SciTec is proud to be an Equal Opportunity employer. VET/Disabled.
09/09/2026
Full time
Job Description Job Description SciTec, a wholly owned subsidiary of Firefly Aerospace, is a dynamic non-traditional defense contractor that delivers advanced technologies in support of U.S. National Security and Defense. For the past forty-five plus years, we have supported Department of Defense customers by developing innovative remote sensing algorithms, tools, and techniques to deliver world-class data exploitation capabilities supporting missile defense; intelligence, surveillance, & reconnaissance; space domain awareness; and aircraft survivability missions. Important Notice: SciTec exclusively works on U.S. government contracts that require U.S. citizenship for all employees. Applicants that do not meet this requirement will not be considered. SciTec has immediate opportunities for an experienced Senior Cybersecurity Engineer to work in either our Boulder, CO or Princeton, NJ office. Responsibilities: Serve as the CrowdStrike technical lead, leading implementation and integration across virtual, physical, and cloud environments. (AWS/Azure) Harden and secure mission infrastructure assets, including servers, network devices, storage systems, and supporting platforms Provide expertise to the vulnerability management process, including but not limited to risk prioritization based on environment and remediation actions. (Tools include Tenable, NinjaOne) Collaborate with Infrastructure teams to provide cybersecurity input to system architecture, enclave segmentation, and infrastructure design decisions Serves as technical lead for CMMC/NIST 800-171 requirements Create and maintain SIEM queries in response to emerging threats around environment. Develop and maintain CrowdStrike NG-SIEM log parsing Ensure logging, monitoring, and access controls meet security and compliance requirements Identify and mitigate operational cybersecurity risks across the asset lifecycle Support incident response preparation and forensic readiness efforts Communicate cybersecurity posture, risks, and remediation plans to technical and program leadership Other duties as assigned Requirements Bachelor's degree in Cybersecurity, Computer Science, Engineering, or related field CompTIA Cybersecurity Analyst (CySa+) or similar certification 6+ years of professional experience in cybersecurity engineering 2+ years of experience using CrowdStrike EDR and NG-SIEM Professional technical experience with NIST 800-171 / CMMC controls Experience conducting vulnerability scanning and remediation Strong understanding of Linux systems security Strong understanding of Windows systems security Strong understanding of Active Directory and IAM Security Best Practices Experience with scripting languages, such as Python, PowerShell or Bash Familiarity with network security concepts and segmentation Ability to obtain and maintain a DoD security clearance Strong documentation and communication skills Proven oral and written communication skills Strong attention to detail Candidates who have any of the following skills will be preferred: Professional experience in Cloud Security (AWS / Azure) Experience integrating security into DevSecOps pipelines GIAC Certified Incident Handler (GCIH) certification CrowdStrike Certified Falcon Administrator (CCFA) certification Benefits SciTec offers a highly competitive salary and benefits package, including: 4% Safe Harbor 401(k) match 100% company paid HSA Medical insurance, with a choice of 2 buy-up options 80% company paid Dental insurance 100% company paid Vision insurance 100% company paid Life insurance 100% company paid Long-term Disability insurance 100% company paid Hospital Indemnity insurance Voluntary Accident and Critical Illness insurance Short-term Disability insurance Annual Profit-Sharing Plan Discretionary Performance Bonus Paid Parental Leave Generous Paid Time Off, including Holiday, Vacation, and Sick Pay Flexible Work Hours The pay range for this position is $124,000 - $158,000 / year. SciTec considers several factors when extending an offer of employment, including but not limited to the role and associated responsibilities, a candidate's work experience, education/training, and key skills. This is not a guarantee of compensation. SciTec is proud to be an Equal Opportunity employer. VET/Disabled.
New Directions, IT & Digital Talent Solutions
Cambridge, Massachusetts
Job Description Job Description Senior Manager G&A Shared IT Services We are currently engaged with a client who is seeking a Senior Manager G&A Shared IT Services on a full time direct employee basis. In this role, the Senior Manager G&A Shared IT Services will: Support IT for General and Administrative functions that include finance, compliance, regulatory, HR, and clinical trials organizations. Drive short, intermediate, and long-term needs for data management and process efficiencies through defining processes and tools within the IT domain. Act as the business analyst for shares services functions such as finance, HR, compliance/legal, and regulatory. Lead shared IT services that include: SAP implementation, regulatory applications support, infrastructure, cyber-security, brownfield and greenfield start-up. Lead the definition and implementation of a shared service model for a portfolio company with multiple operating companies. Provide vendor selection and management for IT vendors delivering software or services. Actively manage multiple projects and provide associated information to the PMO organization for integration into the master plan. The appropriate individual will have demonstrated experience in the following: Supporting shared services organizations from within IT in a biotech, pharma and or clinic research organization. Supporting department heads in various areas that might include finance, HR, compliance and regulatory. Driving, delivering, and supporting initial SAP implementations. Knowledge of IT infrastructure and cyber-security. Knowledge of regulatory application support practices. Brownfield / greenfield startup background in biotech, pharma and or clinical research organizations. Knowledge of RPA (preferred). Interview Now In order to arrange a preliminary interview, please forward a Word copy of your resume with your complete contact information. About Us New Directions is an Information Technology Recruiting and Staffing Firm that provides consulting; project staff augmentation and traditional hire services for: Enterprise Software; Business Intelligence and Data Warehousing; and Enterprise Web Applications Design & Development. Ranked as one of the Fastest Growing and Innovative Privately held companies for three years by the Providence Business News, our success and subsequent growth has been based on leveraging our clients' technology with talented people.
09/09/2026
Full time
Job Description Job Description Senior Manager G&A Shared IT Services We are currently engaged with a client who is seeking a Senior Manager G&A Shared IT Services on a full time direct employee basis. In this role, the Senior Manager G&A Shared IT Services will: Support IT for General and Administrative functions that include finance, compliance, regulatory, HR, and clinical trials organizations. Drive short, intermediate, and long-term needs for data management and process efficiencies through defining processes and tools within the IT domain. Act as the business analyst for shares services functions such as finance, HR, compliance/legal, and regulatory. Lead shared IT services that include: SAP implementation, regulatory applications support, infrastructure, cyber-security, brownfield and greenfield start-up. Lead the definition and implementation of a shared service model for a portfolio company with multiple operating companies. Provide vendor selection and management for IT vendors delivering software or services. Actively manage multiple projects and provide associated information to the PMO organization for integration into the master plan. The appropriate individual will have demonstrated experience in the following: Supporting shared services organizations from within IT in a biotech, pharma and or clinic research organization. Supporting department heads in various areas that might include finance, HR, compliance and regulatory. Driving, delivering, and supporting initial SAP implementations. Knowledge of IT infrastructure and cyber-security. Knowledge of regulatory application support practices. Brownfield / greenfield startup background in biotech, pharma and or clinical research organizations. Knowledge of RPA (preferred). Interview Now In order to arrange a preliminary interview, please forward a Word copy of your resume with your complete contact information. About Us New Directions is an Information Technology Recruiting and Staffing Firm that provides consulting; project staff augmentation and traditional hire services for: Enterprise Software; Business Intelligence and Data Warehousing; and Enterprise Web Applications Design & Development. Ranked as one of the Fastest Growing and Innovative Privately held companies for three years by the Providence Business News, our success and subsequent growth has been based on leveraging our clients' technology with talented people.
Job Description Job Description Description: About Us Aspis strives to make enterprise cybersecurity solutions and professional services accessible to organizations of all sizes, from small and medium-sized businesses to large enterprises, nonprofits, and municipal, state, and federal government agencies. Aspis is a HUBZone-certified small business. Our values are Integrity, Community, and Diversity. Job Description Aspis is hiring a Cybersecurity Analyst (Level I or Level II, depending on your experience) to perform cybersecurity engineering work as a subcontractor supporting a federal civilian agency's application development and modernization portfolio. You will be the security voice in the software release process - analyzing changes before they deploy, running and interpreting the scans, telling developers plainly what has to be fixed and why, and writing the analyses and recommendations that leadership uses to make decisions. This is hands-on engineering work with a heavy documentation component. If you like finding the problem but dislike writing it up, this is not the role. If you can do both - and can explain a vulnerability to a program manager in plain language - you will do well here. You do not need years of experience to be considered. We have filled this position successfully with someone who arrived with a Security+ certification, real aptitude, and no professional experience at all. If that describes you, apply - we will train you, pair you with senior review, and support your next certification. If you already have two to five years behind you, you will come in at Level II and carry the documentation deliverables sooner. This position is based in the U.S. Virgin Islands and is performed remotely from your home. See the residency requirement below before applying; it is a firm condition of this posting. Levels and Pay Level I (0-2 years): $24.00 - $27.00 per hour. CompTIA Security+ required. Work is assigned with clear direction and reviewed before client delivery. Expect structured mentoring and employer-supported progress toward an intermediate certification. Level II (2-5 years): $27.00 - $29.95 per hour. Security+ required and progress toward an intermediate certification such as CySA+, GIAC, or a cloud security credential. Carries analyses and written deliverables with light review. Level is determined at offer based on experience, certifications, and a practical exercise. Advancement from Level I to Level II is based on demonstrated capability, not tenure alone. Application security analysis and vulnerability management Perform Security Impact Analysis and vulnerability assessment before deployment to identify potential security issues, and recommend mitigations. Run scheduled and ad hoc dynamic and static software vulnerability scans using approved tools as part of the application release process, and interpret the results. Help developers and system owners interpret application vulnerability findings and modify applications to remediate them. Help automate software vulnerability scanning processes. Document and continuously improve the processes behind vulnerability scanning, Security Impact Analysis, and vulnerability assessment. Security standards, architecture, and documentation Develop and document security standards - code scanning, security impact analysis, cloud implementation, and similar - and produce documented architectural security analyses and requirements for applications in development or modernization. Prepare briefing decks, risk analyses, white papers, waiver requests, and Analyses of Alternatives, written in plain language wherever possible. Each Analysis of Alternatives must set out the pros and cons of every technology considered. Support application design so that the resulting application is secure by construction. Evaluate enterprise architecture development activities for secure practices and make recommendations across architectural domains. Contribute to code standards, waivers, SDLC models, reviews, and processes. Assessment, research, and program support Assess emerging technologies for how securely they can be integrated into the client's environments. Perform root analysis of existing systems and technologies to identify opportunities for consolidation or modernization. Produce trend analysis reports and support the risk analysis and threat analysis processes. Monitor NIST publications and assist with implementing new policy as it is issued. Assist with change control processes for agency security requirements. Coordinate the setup, deployment, and maintenance of security-specific tools. Research and recommend actions for technical solutions. What Success Looks Like This work is performed under contractual performance criteria. Deliverables are expected to be substantially free of errors, initial inquiries answered within two business days, and status communicated within two business days of completion. You will also record your time accurately in a web-based timekeeping system every day you work - on a labor-hour contract, timekeeping accuracy is a compliance obligation, not an administrative nicety. Requirements: Residency Requirement - Please Read Before Applying This position is designated to support Aspis' certification under the U.S. Small Business Administration's HUBZone program. Under 13 C.F.R. 126.200, a certified HUBZone small business must maintain at least 35 percent of its employees as HUBZone residents. The entire territory of the U.S. Virgin Islands is a qualified HUBZone. As a condition of employment, the successful candidate must reside in the U.S. Virgin Islands at the time of hire and must maintain continuous residency in the U.S. Virgin Islands for as long as they hold this position. Applicants and employees will be asked to provide documentation of residency; SBA accepts a Virgin Islands driver's license or non-driver identification card as primary evidence, and where that is unavailable may accept a lease, deed, or utility bill (13 C.F.R. 126.103, 126.200, 126.304). A change of residence outside the U.S. Virgin Islands may result in reassignment or separation, because the position would no longer serve the purpose for which it was created. Residency in the U.S. Virgin Islands is a bona fide requirement of this position, applied uniformly to every applicant for the position, and is not based on race, color, religion, sex, national origin, citizenship status, age, disability, veteran status, or any other characteristic protected by federal or Virgin Islands law. Applicants of any national origin who reside in the U.S. Virgin Islands and are legally authorized to work in the United States are encouraged to apply. Residents of St. Thomas, St. Croix, St. John, and Water Island are all eligible. This residency requirement applies to this posting only. It is a condition of this position's designation and is not a general requirement of the Cybersecurity Analyst role at Aspis. Where and How You Will Work Work is performed remotely from your home in the U.S. Virgin Islands. Aspis provides the laptop and software; you provide reliable internet and a workspace suitable for calls and focused analysis. Please note: under the governing contract, the client retains the right to direct that specific activities be performed in the Kansas City, Missouri or Washington, D.C. metropolitan areas. Occasional approved travel may therefore be required. Approved non-local travel is reimbursed in accordance with federal travel regulations and company policy. Aspis will reimburse hourly hot-desk passes at SEAT Caribbean in Charlotte Amalie, St. Thomas, or Accelerate VI Coworking in Christiansted, St. Croix, when a power or internet outage prevents work from home, with prior approval. Qualifications Zero to five years of relevant cybersecurity experience. Level I (0-2 years) and Level II (2-5 years) are both open under this posting. Associate's degree or higher in Cybersecurity, Information Technology, or a related field preferred; equivalent experience and certifications considered in lieu of a degree. CompTIA Security+ or equivalent is required at both levels. Level II candidates should additionally be working toward an intermediate certification such as CySA+, GIAC, or a cloud security credential. Aspis funds certification progression. Level II: hands-on experience running vulnerability scans and interpreting results, with familiarity with static and dynamic application security testing (SAST/DAST) tooling. Level I: exposure through coursework, labs, a home lab, or certification study is sufficient - we will train you on our tooling. Familiarity with NIST SP 800-53, the NIST Cybersecurity Framework, and the Risk Management Framework, appropriate to level. At Level I, Security+ coverage of these topics is an acceptable starting point. Understanding of the software development life cycle and where security fits into it. Demonstrated ability to write clearly. You will produce security impact analyses, white papers, waiver requests, and Analyses of Alternatives. At Level I these are drafted under senior review; a writing sample or a well-organized lab write-up counts. Ability to explain technical findings clearly to non-technical stakeholders. Aptitude and coachability. At Level I these matter more to us than a resume: we are looking for someone who takes direction well, asks good questions . click apply for full job details
09/09/2026
Full time
Job Description Job Description Description: About Us Aspis strives to make enterprise cybersecurity solutions and professional services accessible to organizations of all sizes, from small and medium-sized businesses to large enterprises, nonprofits, and municipal, state, and federal government agencies. Aspis is a HUBZone-certified small business. Our values are Integrity, Community, and Diversity. Job Description Aspis is hiring a Cybersecurity Analyst (Level I or Level II, depending on your experience) to perform cybersecurity engineering work as a subcontractor supporting a federal civilian agency's application development and modernization portfolio. You will be the security voice in the software release process - analyzing changes before they deploy, running and interpreting the scans, telling developers plainly what has to be fixed and why, and writing the analyses and recommendations that leadership uses to make decisions. This is hands-on engineering work with a heavy documentation component. If you like finding the problem but dislike writing it up, this is not the role. If you can do both - and can explain a vulnerability to a program manager in plain language - you will do well here. You do not need years of experience to be considered. We have filled this position successfully with someone who arrived with a Security+ certification, real aptitude, and no professional experience at all. If that describes you, apply - we will train you, pair you with senior review, and support your next certification. If you already have two to five years behind you, you will come in at Level II and carry the documentation deliverables sooner. This position is based in the U.S. Virgin Islands and is performed remotely from your home. See the residency requirement below before applying; it is a firm condition of this posting. Levels and Pay Level I (0-2 years): $24.00 - $27.00 per hour. CompTIA Security+ required. Work is assigned with clear direction and reviewed before client delivery. Expect structured mentoring and employer-supported progress toward an intermediate certification. Level II (2-5 years): $27.00 - $29.95 per hour. Security+ required and progress toward an intermediate certification such as CySA+, GIAC, or a cloud security credential. Carries analyses and written deliverables with light review. Level is determined at offer based on experience, certifications, and a practical exercise. Advancement from Level I to Level II is based on demonstrated capability, not tenure alone. Application security analysis and vulnerability management Perform Security Impact Analysis and vulnerability assessment before deployment to identify potential security issues, and recommend mitigations. Run scheduled and ad hoc dynamic and static software vulnerability scans using approved tools as part of the application release process, and interpret the results. Help developers and system owners interpret application vulnerability findings and modify applications to remediate them. Help automate software vulnerability scanning processes. Document and continuously improve the processes behind vulnerability scanning, Security Impact Analysis, and vulnerability assessment. Security standards, architecture, and documentation Develop and document security standards - code scanning, security impact analysis, cloud implementation, and similar - and produce documented architectural security analyses and requirements for applications in development or modernization. Prepare briefing decks, risk analyses, white papers, waiver requests, and Analyses of Alternatives, written in plain language wherever possible. Each Analysis of Alternatives must set out the pros and cons of every technology considered. Support application design so that the resulting application is secure by construction. Evaluate enterprise architecture development activities for secure practices and make recommendations across architectural domains. Contribute to code standards, waivers, SDLC models, reviews, and processes. Assessment, research, and program support Assess emerging technologies for how securely they can be integrated into the client's environments. Perform root analysis of existing systems and technologies to identify opportunities for consolidation or modernization. Produce trend analysis reports and support the risk analysis and threat analysis processes. Monitor NIST publications and assist with implementing new policy as it is issued. Assist with change control processes for agency security requirements. Coordinate the setup, deployment, and maintenance of security-specific tools. Research and recommend actions for technical solutions. What Success Looks Like This work is performed under contractual performance criteria. Deliverables are expected to be substantially free of errors, initial inquiries answered within two business days, and status communicated within two business days of completion. You will also record your time accurately in a web-based timekeeping system every day you work - on a labor-hour contract, timekeeping accuracy is a compliance obligation, not an administrative nicety. Requirements: Residency Requirement - Please Read Before Applying This position is designated to support Aspis' certification under the U.S. Small Business Administration's HUBZone program. Under 13 C.F.R. 126.200, a certified HUBZone small business must maintain at least 35 percent of its employees as HUBZone residents. The entire territory of the U.S. Virgin Islands is a qualified HUBZone. As a condition of employment, the successful candidate must reside in the U.S. Virgin Islands at the time of hire and must maintain continuous residency in the U.S. Virgin Islands for as long as they hold this position. Applicants and employees will be asked to provide documentation of residency; SBA accepts a Virgin Islands driver's license or non-driver identification card as primary evidence, and where that is unavailable may accept a lease, deed, or utility bill (13 C.F.R. 126.103, 126.200, 126.304). A change of residence outside the U.S. Virgin Islands may result in reassignment or separation, because the position would no longer serve the purpose for which it was created. Residency in the U.S. Virgin Islands is a bona fide requirement of this position, applied uniformly to every applicant for the position, and is not based on race, color, religion, sex, national origin, citizenship status, age, disability, veteran status, or any other characteristic protected by federal or Virgin Islands law. Applicants of any national origin who reside in the U.S. Virgin Islands and are legally authorized to work in the United States are encouraged to apply. Residents of St. Thomas, St. Croix, St. John, and Water Island are all eligible. This residency requirement applies to this posting only. It is a condition of this position's designation and is not a general requirement of the Cybersecurity Analyst role at Aspis. Where and How You Will Work Work is performed remotely from your home in the U.S. Virgin Islands. Aspis provides the laptop and software; you provide reliable internet and a workspace suitable for calls and focused analysis. Please note: under the governing contract, the client retains the right to direct that specific activities be performed in the Kansas City, Missouri or Washington, D.C. metropolitan areas. Occasional approved travel may therefore be required. Approved non-local travel is reimbursed in accordance with federal travel regulations and company policy. Aspis will reimburse hourly hot-desk passes at SEAT Caribbean in Charlotte Amalie, St. Thomas, or Accelerate VI Coworking in Christiansted, St. Croix, when a power or internet outage prevents work from home, with prior approval. Qualifications Zero to five years of relevant cybersecurity experience. Level I (0-2 years) and Level II (2-5 years) are both open under this posting. Associate's degree or higher in Cybersecurity, Information Technology, or a related field preferred; equivalent experience and certifications considered in lieu of a degree. CompTIA Security+ or equivalent is required at both levels. Level II candidates should additionally be working toward an intermediate certification such as CySA+, GIAC, or a cloud security credential. Aspis funds certification progression. Level II: hands-on experience running vulnerability scans and interpreting results, with familiarity with static and dynamic application security testing (SAST/DAST) tooling. Level I: exposure through coursework, labs, a home lab, or certification study is sufficient - we will train you on our tooling. Familiarity with NIST SP 800-53, the NIST Cybersecurity Framework, and the Risk Management Framework, appropriate to level. At Level I, Security+ coverage of these topics is an acceptable starting point. Understanding of the software development life cycle and where security fits into it. Demonstrated ability to write clearly. You will produce security impact analyses, white papers, waiver requests, and Analyses of Alternatives. At Level I these are drafted under senior review; a writing sample or a well-organized lab write-up counts. Ability to explain technical findings clearly to non-technical stakeholders. Aptitude and coachability. At Level I these matter more to us than a resume: we are looking for someone who takes direction well, asks good questions . click apply for full job details
Job Description Job Description Description: RMC is seeking a Senior OT Cybersecurity Analyst for a full-time hybrid position in San Diego CA, Washington D.C. or Norfolk VA! Are you ready to embark on a fulfilling and impactful career journey with Risk Mitigation Consulting (RMC)? We're in search of an exceptional Senior OT Cybersecurity Analyst to become a part of our mission-driven team, dedicated to making a difference in the federal and commercial markets. At RMC, we're all about enhancing security for both our military and global commercial partners, offering an array of services such as Risk Management, Mission Assurance, and Cybersecurity. Our team's well-being is paramount, and we reflect this commitment through our flexible work environment and exceptional company culture. By joining RMC, you become a key contributor to our mission - Assuring Tomorrow! When you join RMC, you'll experience a range of benefits, including: Comprehensive health, vision, and dental insurance plans fully covered for employees Subsidized dependent health care coverage Participation in our Annual Bonus Program Life insurance policy equivalent to 1x your annual salary. Company paid short and long-term disability Cell phone reimbursement of $65 per month 401(k) Plan with contributions A 401(k) Safe Harbor Employer Contribution Program, which includes a 3% contribution Position Summary: The Senior OT Cybersecurity Analyst provides operational technology (OT) cybersecurity subject matter support for clients including assessments, vulnerability and risk analysis, and report and presentation development. The Analyst is responsible for providing support to their assigned projects and clients by executing tasks on time and at and at high quality to accomplish project requirements. Accountability, quality of work, functional expertise, communication, teamwork, time management, creativity, training, and staying informed on operational technology types, capabilities, threats and cyber mitigations are key aspects of success in this position. Essential Functions: Perform vulnerability and risk assessments for operational technology on DoW installations or government facilities Perform vulnerability analysis using threat and hazard data and document results in reports or other client-required deliverables Identify and assess critical asset dependencies or relationships to operational technology Collaborate with other Analysts and subject matter experts on assessment teams to produce high quality products to clients Review and advise on policies, order, directives and other information sources applicable to operational technology and critical infrastructure. Participate and contribute to working groups or meetings with the project team as needed Competencies: Significant foundational knowledge of cybersecurity principles as they apply to the OT environments of RMC targeted industries (e.g., utility systems (electrical, water, gas, fuel etc.) and building automation systems) Demonstrable experience in the field of risk management, with a knack for translating complex cybersecurity requirements to actionable work plans Cyber supply chain risk knowledge as applicable to operational technology and critical infrastructure Excellent interpersonal and communication skills, capable of engaging with a spectrum of stakeholders from internal technical SMEs, executives, and administrative support staff to client decision-makers Proactive and inquisitive, committed to continual learning and adapting within fast-evolving industries Excellent writing skills, strong communication abilities, good time management and organizational skills Experience using Microsoft Office tools and applications such as Word, PowerPoint, Excel and SharePoint Work confidently in a fast-paced environment with the ability to support multiple projects Ability to work independently on multiple tasks with minimal direction to meet deadlines Good time management and organizational skills Ability to work in a team environment and take initiative to help ensure team tasks are successfully completed within required timelines Possess strong problem-solving skills and the ability to think outside-the-box Ability to perform logical analysis of complex cyber issues Familiarity with Federal and DoW Cybersecurity policy and initiatives, and NIST guidance Requirements: Education & Experience Requirements Bachelor's degree and 10+ years of experience in the industry Desired Certificates & Licenses (if any): CISSP CISM PMP Other Requirements: Security Clearance: Obtaining a DoD Secret Clearance. Applicants selected will be subject to a government security investigation and must meet eligibility requirements for clearance level required for the job. Valid Passport: Possession of a current passport with a minimum of 8 months remaining until the expiration date. Hybrid Role: This hybrid role includes monthly travel to a local designated government site to work on secure networks and maintain access. Ability to maintain and access NIPR/SIPR accounts by monthly travel to employees designated regional site. Travel Flexibility: Willingness and capability to travel, approximately 20% of the time. Telecommunication is authorized for this role. Work Environment Compliance: Commitment to maintaining a drug-free work environment, U.S. Citizenship, and possession of a valid state driver's license. Want to take the next step in your career with RMC? This Senior OT Cybersecurity Analyst role is where your skills and talents will thrive, and you'll be part of something truly meaningful. Join us today! Reasonable Accommodations Statement To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable Accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. RMC has reviewed this job description to ensure that essential functions and basic duties have been included. It is intended to provide guidelines for job expectations and the employee's ability to perform the position described. It is not intended to be construed as an exhaustive list of all functions, responsibilities, skills, and abilities. Additional functions and requirements may be assigned by your manager as deemed appropriate. This document does not represent a contract of employment, and RMC reserves the right to change this position description and/or assign tasks for the employee to perform, as RMC may deem appropriate. RMC is an Equal Opportunity Employer.
09/08/2026
Full time
Job Description Job Description Description: RMC is seeking a Senior OT Cybersecurity Analyst for a full-time hybrid position in San Diego CA, Washington D.C. or Norfolk VA! Are you ready to embark on a fulfilling and impactful career journey with Risk Mitigation Consulting (RMC)? We're in search of an exceptional Senior OT Cybersecurity Analyst to become a part of our mission-driven team, dedicated to making a difference in the federal and commercial markets. At RMC, we're all about enhancing security for both our military and global commercial partners, offering an array of services such as Risk Management, Mission Assurance, and Cybersecurity. Our team's well-being is paramount, and we reflect this commitment through our flexible work environment and exceptional company culture. By joining RMC, you become a key contributor to our mission - Assuring Tomorrow! When you join RMC, you'll experience a range of benefits, including: Comprehensive health, vision, and dental insurance plans fully covered for employees Subsidized dependent health care coverage Participation in our Annual Bonus Program Life insurance policy equivalent to 1x your annual salary. Company paid short and long-term disability Cell phone reimbursement of $65 per month 401(k) Plan with contributions A 401(k) Safe Harbor Employer Contribution Program, which includes a 3% contribution Position Summary: The Senior OT Cybersecurity Analyst provides operational technology (OT) cybersecurity subject matter support for clients including assessments, vulnerability and risk analysis, and report and presentation development. The Analyst is responsible for providing support to their assigned projects and clients by executing tasks on time and at and at high quality to accomplish project requirements. Accountability, quality of work, functional expertise, communication, teamwork, time management, creativity, training, and staying informed on operational technology types, capabilities, threats and cyber mitigations are key aspects of success in this position. Essential Functions: Perform vulnerability and risk assessments for operational technology on DoW installations or government facilities Perform vulnerability analysis using threat and hazard data and document results in reports or other client-required deliverables Identify and assess critical asset dependencies or relationships to operational technology Collaborate with other Analysts and subject matter experts on assessment teams to produce high quality products to clients Review and advise on policies, order, directives and other information sources applicable to operational technology and critical infrastructure. Participate and contribute to working groups or meetings with the project team as needed Competencies: Significant foundational knowledge of cybersecurity principles as they apply to the OT environments of RMC targeted industries (e.g., utility systems (electrical, water, gas, fuel etc.) and building automation systems) Demonstrable experience in the field of risk management, with a knack for translating complex cybersecurity requirements to actionable work plans Cyber supply chain risk knowledge as applicable to operational technology and critical infrastructure Excellent interpersonal and communication skills, capable of engaging with a spectrum of stakeholders from internal technical SMEs, executives, and administrative support staff to client decision-makers Proactive and inquisitive, committed to continual learning and adapting within fast-evolving industries Excellent writing skills, strong communication abilities, good time management and organizational skills Experience using Microsoft Office tools and applications such as Word, PowerPoint, Excel and SharePoint Work confidently in a fast-paced environment with the ability to support multiple projects Ability to work independently on multiple tasks with minimal direction to meet deadlines Good time management and organizational skills Ability to work in a team environment and take initiative to help ensure team tasks are successfully completed within required timelines Possess strong problem-solving skills and the ability to think outside-the-box Ability to perform logical analysis of complex cyber issues Familiarity with Federal and DoW Cybersecurity policy and initiatives, and NIST guidance Requirements: Education & Experience Requirements Bachelor's degree and 10+ years of experience in the industry Desired Certificates & Licenses (if any): CISSP CISM PMP Other Requirements: Security Clearance: Obtaining a DoD Secret Clearance. Applicants selected will be subject to a government security investigation and must meet eligibility requirements for clearance level required for the job. Valid Passport: Possession of a current passport with a minimum of 8 months remaining until the expiration date. Hybrid Role: This hybrid role includes monthly travel to a local designated government site to work on secure networks and maintain access. Ability to maintain and access NIPR/SIPR accounts by monthly travel to employees designated regional site. Travel Flexibility: Willingness and capability to travel, approximately 20% of the time. Telecommunication is authorized for this role. Work Environment Compliance: Commitment to maintaining a drug-free work environment, U.S. Citizenship, and possession of a valid state driver's license. Want to take the next step in your career with RMC? This Senior OT Cybersecurity Analyst role is where your skills and talents will thrive, and you'll be part of something truly meaningful. Join us today! Reasonable Accommodations Statement To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable Accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. RMC has reviewed this job description to ensure that essential functions and basic duties have been included. It is intended to provide guidelines for job expectations and the employee's ability to perform the position described. It is not intended to be construed as an exhaustive list of all functions, responsibilities, skills, and abilities. Additional functions and requirements may be assigned by your manager as deemed appropriate. This document does not represent a contract of employment, and RMC reserves the right to change this position description and/or assign tasks for the employee to perform, as RMC may deem appropriate. RMC is an Equal Opportunity Employer.
Job Description Job Description Description: This role will be based in either Chicago, IL metro area (Niles) or Pittsburgh, PA metro area (Freedom). It is a hybrid role with 3 days per week on-site and 2 days remote. The Senior Information Security Analyst protects Company organizational systems and data by supporting and enhancing security operations, risk management, and security controls. This role performs advanced analysis and responds (or leads response) to security events, drives risk reduction, supports compliance efforts, and contributes to the ongoing maturity of the organization's information security program. The position operates with a high degree of independence and collaborates across technical and business teams to identify, prioritize, and address security risks. Security Operations & Monitoring Monitors, analyzes, and responds to/leads security events and alerts across security platforms (e.g., SIEM, EDR, email security, network tools) Investigates suspicious activity, determines root cause, and coordinates remediation efforts per Company policy Tunes and optimizes detection capabilities to improve alert quality and reduce false positives Develops and implements automation to improve efficiency and consistency of security operations (e.g., scripting, workflow automation) Coordinates with security vendors to troubleshoot issues and improve tool effectiveness Incident Response Participates in/leads incident response activities, including containment, eradication, and recovery Documents incidents, actions taken, and lessons learned Assists in maintaining and improving internal incident response procedures and playbooks Coordinates with external vendors or partners as needed during incident investigations Vulnerability, Patch & Risk Management Conducts vulnerability scanning and risk assessments across systems and environments Prioritizes remediation efforts based on risk and business impact Coordinates patch management activities with IT teams to ensure timely remediation of vulnerabilities Tracks and reports on remediation progress, including vulnerability and patch status across systems Works with internal teams and external vendors to support remediation efforts Security Controls & Engineering Support Evaluates and recommends improvements to existing security controls and processes Assists in implementation, configuration, and optimization of security technologies Supports secure design and configuration of systems in partnership with IT teams Identifies opportunities to automate repetitive security tasks and improve operational efficiency Participates in evaluation and selection of security tools and vendors Governance, Risk & Compliance Supports internal and external audits (e.g., SOC 2, ISO) by gathering evidence and validating controls Develops, maintains, and updates security documentation, including policies, standards, procedures, and operational playbooks Helps ensure alignment with applicable regulatory and industry frameworks Vendor & Third-Party Coordination Manages day-to-day relationships with security vendors and service providers Serves as a point of contact for vendor support, escalations, and technical discussions Monitors vendor performance to ensure services meet organizational expectations Assists in evaluating new vendors and solutions based on risk, effectiveness, and business needs Collaboration & Communication Partners with IT, infrastructure, and business teams to identify and mitigate security risks Provides guidance on security best practices and control implementation Develops and delivers security awareness training programs to promote secure practices across the organization Additional Responsibilities Participates in security initiatives and special projects as assigned Stays current on emerging threats, vulnerabilities, and security technologies Adheres to all organizational policies, procedures, and compliance requirements Demonstrates behavior consistent with Company Values and the Code of Conduct. Learns and adheres to Company rules and established policies for workplace health and safety. Adheres to all other Company policies and procedures. Completes all required compliance training on time and in good faith. Requirements: Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience) 6+ years of experience in information security or related IT roles Understanding of IT infrastructure, including protocols, operating systems, and networks Experience with security tools such as SIEM, EDR/XDR, and vulnerability management platforms Understanding of incident response processes and security operations workflows Strong understanding of network, endpoint, and identity security principles Familiarity with patch management processes and security remediation workflows Experience with automation or scripting (e.g., PowerShell, Python) preferred Familiarity with cloud security concepts, particularly within Microsoft 365 and/or Azure environments Experience supporting audits and compliance programs Strong understanding of security frameworks such as NIST CSF, CIS Controls, or ISO 27001 Strong teaching, interpersonal, and communication skills Preferred Qualifications Relevant certifications (e.g., Security+, CySA+, CISSP, CISM, or equivalent) Familiarity with Microsoft Azure and Microsoft 365 security technology preferred Familiarity with securing Linux systems
09/08/2026
Full time
Job Description Job Description Description: This role will be based in either Chicago, IL metro area (Niles) or Pittsburgh, PA metro area (Freedom). It is a hybrid role with 3 days per week on-site and 2 days remote. The Senior Information Security Analyst protects Company organizational systems and data by supporting and enhancing security operations, risk management, and security controls. This role performs advanced analysis and responds (or leads response) to security events, drives risk reduction, supports compliance efforts, and contributes to the ongoing maturity of the organization's information security program. The position operates with a high degree of independence and collaborates across technical and business teams to identify, prioritize, and address security risks. Security Operations & Monitoring Monitors, analyzes, and responds to/leads security events and alerts across security platforms (e.g., SIEM, EDR, email security, network tools) Investigates suspicious activity, determines root cause, and coordinates remediation efforts per Company policy Tunes and optimizes detection capabilities to improve alert quality and reduce false positives Develops and implements automation to improve efficiency and consistency of security operations (e.g., scripting, workflow automation) Coordinates with security vendors to troubleshoot issues and improve tool effectiveness Incident Response Participates in/leads incident response activities, including containment, eradication, and recovery Documents incidents, actions taken, and lessons learned Assists in maintaining and improving internal incident response procedures and playbooks Coordinates with external vendors or partners as needed during incident investigations Vulnerability, Patch & Risk Management Conducts vulnerability scanning and risk assessments across systems and environments Prioritizes remediation efforts based on risk and business impact Coordinates patch management activities with IT teams to ensure timely remediation of vulnerabilities Tracks and reports on remediation progress, including vulnerability and patch status across systems Works with internal teams and external vendors to support remediation efforts Security Controls & Engineering Support Evaluates and recommends improvements to existing security controls and processes Assists in implementation, configuration, and optimization of security technologies Supports secure design and configuration of systems in partnership with IT teams Identifies opportunities to automate repetitive security tasks and improve operational efficiency Participates in evaluation and selection of security tools and vendors Governance, Risk & Compliance Supports internal and external audits (e.g., SOC 2, ISO) by gathering evidence and validating controls Develops, maintains, and updates security documentation, including policies, standards, procedures, and operational playbooks Helps ensure alignment with applicable regulatory and industry frameworks Vendor & Third-Party Coordination Manages day-to-day relationships with security vendors and service providers Serves as a point of contact for vendor support, escalations, and technical discussions Monitors vendor performance to ensure services meet organizational expectations Assists in evaluating new vendors and solutions based on risk, effectiveness, and business needs Collaboration & Communication Partners with IT, infrastructure, and business teams to identify and mitigate security risks Provides guidance on security best practices and control implementation Develops and delivers security awareness training programs to promote secure practices across the organization Additional Responsibilities Participates in security initiatives and special projects as assigned Stays current on emerging threats, vulnerabilities, and security technologies Adheres to all organizational policies, procedures, and compliance requirements Demonstrates behavior consistent with Company Values and the Code of Conduct. Learns and adheres to Company rules and established policies for workplace health and safety. Adheres to all other Company policies and procedures. Completes all required compliance training on time and in good faith. Requirements: Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience) 6+ years of experience in information security or related IT roles Understanding of IT infrastructure, including protocols, operating systems, and networks Experience with security tools such as SIEM, EDR/XDR, and vulnerability management platforms Understanding of incident response processes and security operations workflows Strong understanding of network, endpoint, and identity security principles Familiarity with patch management processes and security remediation workflows Experience with automation or scripting (e.g., PowerShell, Python) preferred Familiarity with cloud security concepts, particularly within Microsoft 365 and/or Azure environments Experience supporting audits and compliance programs Strong understanding of security frameworks such as NIST CSF, CIS Controls, or ISO 27001 Strong teaching, interpersonal, and communication skills Preferred Qualifications Relevant certifications (e.g., Security+, CySA+, CISSP, CISM, or equivalent) Familiarity with Microsoft Azure and Microsoft 365 security technology preferred Familiarity with securing Linux systems
Job Description Job Description Apply Here: & TrackId=ZipRecruiter SENIOR CYBER SECURITY ANALYST III (ISSM) This is a HYBRID position, not fully remote. Only apply if you have a current security clearance. Location: Clearfield, UT The Cybersecurity Analyst is a key member of the Cybersecurity team and works closely with our customers across functional teams to provide compliance assessments and help engineer secure solutions as they are being developed. Essential Duties and Job Functions Assist customers design, engineer, and implement technical solutions Lead teams of cybersecurity engineers and analysts in developing solutions across multiple DoD programs Coordinate with Risk Management Framework team to ensure design meets specified requirements Coordinate with DoD agencies to ensure solutions meet specific security guidelines Conduct research, review documentation and provide input for Risk Management Framework packages to the Government for review and approval Review Risk Management Framework documentation for completeness and readiness for certification analysis Coordinate with the program team to gather artifacts and assist the Government in resolving issues precluding the program from receiving an Authority To Operate Assist with FISMA compliance audits and provide status updates to the PM Perform regular STIG and vulnerability analysis in compliance with DoD guidelines Review compliance with current Cybersecurity policy, regulations, and directives to ensure secure configuration and operation of all operated and maintained IT assets, recommending corrective actions as required Assist customers developing new system to design and engineer the systems to meet current cyber security requirements and best practices Knowledge, Experience and Skills Minimum seven (7) years of experience in an Information Security position or IT Audit role with a background in performing security risk assessments Experience with system design across multiple areas of operations (AAA, Operating Systems, network layout and design ) Requirements gap analysis/traceability Proven ability to create and maintain effective documentation, including policies, processes and procedures Experience drawing Topology, Data Flow, and Boundary diagrams Strong understanding of security concepts and detailed implementation including using NIST 800-53r4 controls as a framework Deep understanding of how to tailor security implementation based on mission and threats Knowledge of security and IT general controls for application development and management Good communications skills, both verbal and written, as well as the ability to communicate well with people in a variety of positions, roles and levels Professional, self-motivated and a strong sense of urgency. Ability to provide technical direction to more junior team members Required CISSP, CISSP-ISSEP, CISSP-ISSAP Active DoD SECRET clearance (ability to gain Top Secret) Preferred BS/BA degree or an equivalent combination of education and experience Training in Risk Management or IT Audit Methodology strongly desired
09/08/2026
Full time
Job Description Job Description Apply Here: & TrackId=ZipRecruiter SENIOR CYBER SECURITY ANALYST III (ISSM) This is a HYBRID position, not fully remote. Only apply if you have a current security clearance. Location: Clearfield, UT The Cybersecurity Analyst is a key member of the Cybersecurity team and works closely with our customers across functional teams to provide compliance assessments and help engineer secure solutions as they are being developed. Essential Duties and Job Functions Assist customers design, engineer, and implement technical solutions Lead teams of cybersecurity engineers and analysts in developing solutions across multiple DoD programs Coordinate with Risk Management Framework team to ensure design meets specified requirements Coordinate with DoD agencies to ensure solutions meet specific security guidelines Conduct research, review documentation and provide input for Risk Management Framework packages to the Government for review and approval Review Risk Management Framework documentation for completeness and readiness for certification analysis Coordinate with the program team to gather artifacts and assist the Government in resolving issues precluding the program from receiving an Authority To Operate Assist with FISMA compliance audits and provide status updates to the PM Perform regular STIG and vulnerability analysis in compliance with DoD guidelines Review compliance with current Cybersecurity policy, regulations, and directives to ensure secure configuration and operation of all operated and maintained IT assets, recommending corrective actions as required Assist customers developing new system to design and engineer the systems to meet current cyber security requirements and best practices Knowledge, Experience and Skills Minimum seven (7) years of experience in an Information Security position or IT Audit role with a background in performing security risk assessments Experience with system design across multiple areas of operations (AAA, Operating Systems, network layout and design ) Requirements gap analysis/traceability Proven ability to create and maintain effective documentation, including policies, processes and procedures Experience drawing Topology, Data Flow, and Boundary diagrams Strong understanding of security concepts and detailed implementation including using NIST 800-53r4 controls as a framework Deep understanding of how to tailor security implementation based on mission and threats Knowledge of security and IT general controls for application development and management Good communications skills, both verbal and written, as well as the ability to communicate well with people in a variety of positions, roles and levels Professional, self-motivated and a strong sense of urgency. Ability to provide technical direction to more junior team members Required CISSP, CISSP-ISSEP, CISSP-ISSAP Active DoD SECRET clearance (ability to gain Top Secret) Preferred BS/BA degree or an equivalent combination of education and experience Training in Risk Management or IT Audit Methodology strongly desired
Job Description Job Description Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Senior Forensic Analyst Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred) Terms: Full-time Clearance: Active Top Secret required SalaryRange: $130-170k DOE Travel: Yes - travel to government sites as required Project Description This position supports a large-scale federal security operations program responsible for protecting enterprise networks, detecting and responding to intrusions, and conducting forensic investigations of suspected compromises. Forensic evaluations on this program are non-repetitive, fixed-duration engagements - each one is unique, consequential, and conducted under legal chain of custody requirements. The core challenge: conducting rigorous forensic evaluations of federal systems suspected of compromise - independently, under legal and evidentiary standards, with findings that inform both immediate response and broader intelligence community awareness. Position Description As a Senior Forensic Analyst at Revolutional, you conduct forensic evaluations of federal enterprise systems suspected of compromise. You are a senior practitioner operating with a high degree of independence - each engagement is distinct, and you bring the expertise to scope, execute, and deliver findings without a playbook written specifically for the situation in front of you. You maintain strict chain of custody in accordance with applicable federal and state legal requirements, conduct both host and network analysis to determine the full extent of compromise, and interface directly with the intelligence community to share and receive context that sharpens your findings. You may travel to government sites as required to support on-site forensic collection and analysis. What You Will Own End-to-end forensic evaluation of federal systems suspected of compromise Chain of custody integrity across all evidence collected and handled Host and network analysis to determine compromise scope and attacker activity Intelligence community interface and information sharing on active investigations Forensic project support across program-directed engagements On-site forensic collection and analysis at government facilities as required Responsibilities Conduct forensic evaluations of federal enterprise systems, endpoints, and media suspected of compromise; apply rigorous methodology and maintain chain of custody throughout in accordance with applicable federal and state law Perform host-based forensic analysis: disk imaging, file system examination, artifact recovery, memory analysis, and timeline reconstruction to determine attacker activity and compromise extent Conduct network forensic analysis: packet capture review, NetFlow analysis, log correlation, and lateral movement identification to establish the full scope of intrusion activity Produce thorough, legally defensible forensic reports documenting findings, methodology, evidence handling, and recommended response actions Interface with the intelligence community to share forensic findings, receive relevant threat context, and ensure investigations are informed by the current intelligence picture Support forensic projects as directed by program leadership, including surge support for high-priority or time-sensitive investigations Travel to government sites as required to conduct on-site evidence collection, system imaging, and forensic analysis Maintain current awareness of adversary TTPs, malware families, and forensic evasion techniques relevant to the federal threat landscape Contribute to development and refinement of forensic procedures, evidence handling standards, and investigation methodologies Coordinate with incident response, threat intelligence, and SOC teams to ensure forensic findings drive timely and effective response actions What You Bring (Requirements)Baseline Requirements Bachelor's degree in Computer Science, Digital Forensics, Information Security, or related field (or equivalent experience) 7 or more years of hands-on digital forensics experience, including complex investigations of suspected system compromises in federal or law enforcement environments Demonstrated experience maintaining chain of custody in accordance with federal and state legal requirements Active Top Secret clearance required Ability and willingness to travel to government sites as required Technical & Domain Capabilities Expert-level host forensics: disk and memory acquisition, file system analysis, artifact recovery, malware triage, and attack timeline reconstruction across Windows and Linux environments Hands-on network forensics: packet capture analysis, NetFlow, proxy and DNS log review, and identification of lateral movement, exfiltration, and command-and-control activity Proficiency with industry-standard forensic tools: EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent Experience conducting non-repetitive, fixed-duration forensic evaluations independently with minimal direction Established working relationships or experience interfacing with the intelligence community in the context of cybersecurity investigations Understanding of attacker TTPs, kill-chain methodology, and MITRE ATT&CK framework as applied to forensic investigations Experience producing forensic reports that meet legal and evidentiary standards for federal proceedings Core Strengths Technically expert and analytically independent - you scope and execute complex forensic investigations without needing the situation pre-defined for you Legally disciplined: chain of custody, evidence integrity, and documentation rigor are non-negotiable to you Credible intelligence community partner - you share findings with precision and incorporate external context effectively Composed under operational pressure; fixed-duration engagements with real consequences don't rattle your methodology or your output quality Certifications One or more of the following is strongly preferred: GCFE or GCFA (GIAC Forensics), EnCE (EnCase Certified Examiner), CFCE (Certified Forensic Computer Examiner), GCIH, or CISSP Nice to Have (Differentiators) GREM (GIAC Reverse Engineering Malware) or equivalent malware analysis credential Experience conducting forensic investigations at the TS/SCI level or within classified network environments Active TS/SCI clearance Prior direct experience working with or embedded in an intelligence community organization Background in mobile device forensics, cloud forensics, or industrial control system (ICS) forensics Experience supporting law enforcement actions or legal proceedings with forensic evidence and expert testimony _ Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-time SBA SBIR Tibbett's Award winner Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to Traditional and HSA- eligible medical insurance plans 100% employer-paid dental and vision insurance options 100% employer-sponsored STD, LTD, and life insurance 5% 401(k) company matching Flexible-schedules and teleworking options Paid holidays and PTO Accrual Plans Paid Parental Leave Professional development and career growth opportunities Team and company-wide events, recognition, and appreciation and so much more! Check out our Revolutional LinkedIn to find out a little more about who we are and if we are the right next step for your career! Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional . click apply for full job details
09/07/2026
Full time
Job Description Job Description Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Senior Forensic Analyst Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred) Terms: Full-time Clearance: Active Top Secret required SalaryRange: $130-170k DOE Travel: Yes - travel to government sites as required Project Description This position supports a large-scale federal security operations program responsible for protecting enterprise networks, detecting and responding to intrusions, and conducting forensic investigations of suspected compromises. Forensic evaluations on this program are non-repetitive, fixed-duration engagements - each one is unique, consequential, and conducted under legal chain of custody requirements. The core challenge: conducting rigorous forensic evaluations of federal systems suspected of compromise - independently, under legal and evidentiary standards, with findings that inform both immediate response and broader intelligence community awareness. Position Description As a Senior Forensic Analyst at Revolutional, you conduct forensic evaluations of federal enterprise systems suspected of compromise. You are a senior practitioner operating with a high degree of independence - each engagement is distinct, and you bring the expertise to scope, execute, and deliver findings without a playbook written specifically for the situation in front of you. You maintain strict chain of custody in accordance with applicable federal and state legal requirements, conduct both host and network analysis to determine the full extent of compromise, and interface directly with the intelligence community to share and receive context that sharpens your findings. You may travel to government sites as required to support on-site forensic collection and analysis. What You Will Own End-to-end forensic evaluation of federal systems suspected of compromise Chain of custody integrity across all evidence collected and handled Host and network analysis to determine compromise scope and attacker activity Intelligence community interface and information sharing on active investigations Forensic project support across program-directed engagements On-site forensic collection and analysis at government facilities as required Responsibilities Conduct forensic evaluations of federal enterprise systems, endpoints, and media suspected of compromise; apply rigorous methodology and maintain chain of custody throughout in accordance with applicable federal and state law Perform host-based forensic analysis: disk imaging, file system examination, artifact recovery, memory analysis, and timeline reconstruction to determine attacker activity and compromise extent Conduct network forensic analysis: packet capture review, NetFlow analysis, log correlation, and lateral movement identification to establish the full scope of intrusion activity Produce thorough, legally defensible forensic reports documenting findings, methodology, evidence handling, and recommended response actions Interface with the intelligence community to share forensic findings, receive relevant threat context, and ensure investigations are informed by the current intelligence picture Support forensic projects as directed by program leadership, including surge support for high-priority or time-sensitive investigations Travel to government sites as required to conduct on-site evidence collection, system imaging, and forensic analysis Maintain current awareness of adversary TTPs, malware families, and forensic evasion techniques relevant to the federal threat landscape Contribute to development and refinement of forensic procedures, evidence handling standards, and investigation methodologies Coordinate with incident response, threat intelligence, and SOC teams to ensure forensic findings drive timely and effective response actions What You Bring (Requirements)Baseline Requirements Bachelor's degree in Computer Science, Digital Forensics, Information Security, or related field (or equivalent experience) 7 or more years of hands-on digital forensics experience, including complex investigations of suspected system compromises in federal or law enforcement environments Demonstrated experience maintaining chain of custody in accordance with federal and state legal requirements Active Top Secret clearance required Ability and willingness to travel to government sites as required Technical & Domain Capabilities Expert-level host forensics: disk and memory acquisition, file system analysis, artifact recovery, malware triage, and attack timeline reconstruction across Windows and Linux environments Hands-on network forensics: packet capture analysis, NetFlow, proxy and DNS log review, and identification of lateral movement, exfiltration, and command-and-control activity Proficiency with industry-standard forensic tools: EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent Experience conducting non-repetitive, fixed-duration forensic evaluations independently with minimal direction Established working relationships or experience interfacing with the intelligence community in the context of cybersecurity investigations Understanding of attacker TTPs, kill-chain methodology, and MITRE ATT&CK framework as applied to forensic investigations Experience producing forensic reports that meet legal and evidentiary standards for federal proceedings Core Strengths Technically expert and analytically independent - you scope and execute complex forensic investigations without needing the situation pre-defined for you Legally disciplined: chain of custody, evidence integrity, and documentation rigor are non-negotiable to you Credible intelligence community partner - you share findings with precision and incorporate external context effectively Composed under operational pressure; fixed-duration engagements with real consequences don't rattle your methodology or your output quality Certifications One or more of the following is strongly preferred: GCFE or GCFA (GIAC Forensics), EnCE (EnCase Certified Examiner), CFCE (Certified Forensic Computer Examiner), GCIH, or CISSP Nice to Have (Differentiators) GREM (GIAC Reverse Engineering Malware) or equivalent malware analysis credential Experience conducting forensic investigations at the TS/SCI level or within classified network environments Active TS/SCI clearance Prior direct experience working with or embedded in an intelligence community organization Background in mobile device forensics, cloud forensics, or industrial control system (ICS) forensics Experience supporting law enforcement actions or legal proceedings with forensic evidence and expert testimony _ Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-time SBA SBIR Tibbett's Award winner Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to Traditional and HSA- eligible medical insurance plans 100% employer-paid dental and vision insurance options 100% employer-sponsored STD, LTD, and life insurance 5% 401(k) company matching Flexible-schedules and teleworking options Paid holidays and PTO Accrual Plans Paid Parental Leave Professional development and career growth opportunities Team and company-wide events, recognition, and appreciation and so much more! Check out our Revolutional LinkedIn to find out a little more about who we are and if we are the right next step for your career! Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional . click apply for full job details
Job Description Job Description ARES is seeking an experienced senior cybersecurity analyst to join our security control assessment, vulnerability assessment, software assurance, and risk assessment teams supporting our Nation's ballistic missile defense program. This individual will perform research, analysis, and data gathering activities while conducting threat, vulnerability, and capability maturity assessments. The individual will be expected to apply critical thinking, conduct gap analyses, and develop implementation plans for the improvement of cybersecurity in large, complex defense systems. This position is an onsite role in Colorado Springs, CO (Schriever AFB), and will require an active DOD clearance. Required Qualification s: Bachelor's degree in Computer Science, Information Systems or related field. Senior Cybersecurity certification: CASP+ CE, CCNP Security, CISA, CISSP, GCED, or GCIH Active DoD Clearance Required Proficient in technical services and analysis with knowledge of cybersecurity standards, principles, practices, and processes. Experience supporting key cybersecurity activities including vulnerability assessments, control development, security plan documentation, penetration testing, and the Risk Management Framework (RMF). Familiarity with cybersecurity tools such as Nessus, Burp Suite, Nmap, ACAS, and others. ARES Benefits: ARES offers a competitive compensation and benefit package. Full time employees may participate in: Medical Insurance Dental Insurance Vision Insurance HSA/FSA Accounts Life & Disability Insurance Critical Illness & Accident Insurance 401(k) Plan ESOP Paid Time Off & Holidays ARES is an equal opportunity employer and complies with E-Verify. We believe in hiring a diverse workforce and fostering an inclusive culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law. ARES shall abide by the requirements of 41 CFR 60-1.4(a), 60-300.5(a) and 60-741.5(a). Our stated salary range represents a general guideline. However, ARES considers a number of factors when determining salary offers such as current market conditions, the scope and responsibilities of the position and the candidate's experience, education, and skills. Applications are going to be accepted on an ongoing basis until the position has been filled.
09/07/2026
Full time
Job Description Job Description ARES is seeking an experienced senior cybersecurity analyst to join our security control assessment, vulnerability assessment, software assurance, and risk assessment teams supporting our Nation's ballistic missile defense program. This individual will perform research, analysis, and data gathering activities while conducting threat, vulnerability, and capability maturity assessments. The individual will be expected to apply critical thinking, conduct gap analyses, and develop implementation plans for the improvement of cybersecurity in large, complex defense systems. This position is an onsite role in Colorado Springs, CO (Schriever AFB), and will require an active DOD clearance. Required Qualification s: Bachelor's degree in Computer Science, Information Systems or related field. Senior Cybersecurity certification: CASP+ CE, CCNP Security, CISA, CISSP, GCED, or GCIH Active DoD Clearance Required Proficient in technical services and analysis with knowledge of cybersecurity standards, principles, practices, and processes. Experience supporting key cybersecurity activities including vulnerability assessments, control development, security plan documentation, penetration testing, and the Risk Management Framework (RMF). Familiarity with cybersecurity tools such as Nessus, Burp Suite, Nmap, ACAS, and others. ARES Benefits: ARES offers a competitive compensation and benefit package. Full time employees may participate in: Medical Insurance Dental Insurance Vision Insurance HSA/FSA Accounts Life & Disability Insurance Critical Illness & Accident Insurance 401(k) Plan ESOP Paid Time Off & Holidays ARES is an equal opportunity employer and complies with E-Verify. We believe in hiring a diverse workforce and fostering an inclusive culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law. ARES shall abide by the requirements of 41 CFR 60-1.4(a), 60-300.5(a) and 60-741.5(a). Our stated salary range represents a general guideline. However, ARES considers a number of factors when determining salary offers such as current market conditions, the scope and responsibilities of the position and the candidate's experience, education, and skills. Applications are going to be accepted on an ongoing basis until the position has been filled.
Job Description Job Description Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Senior Threat Hunter Analyst Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred) Terms: Full-time Salary: $125-$150k DOE Clearance: Active Top Secret required Travel: 0-10% Project Description This position supports a large-scale federal security operations program delivering 24/7/365 continuous monitoring, intrusion detection, threat hunting, incident response, and threat intelligence across a complex enterprise network environment. The threat hunting function operates at the leading edge of the program's defensive posture - finding what automated tools miss before it becomes a confirmed incident. The core challenge: proactively hunting adversary activity across a large, high-complexity enterprise network, supporting active incident response, and producing intelligence products that sharpen the program's detection and response capabilities over time. Position Description As a Senior Threat Hunter Analyst at Revolutional, you operate ahead of the threat - proactively hunting for undetected adversary activity across enterprise networks before it surfaces through automated detection. You are a technically deep practitioner who combines hunting tradecraft with malware analysis capability, incident response support, and the discipline to produce IOC reports, after-action reviews, and security metric reporting that make the program measurably better over time. You work in close coordination with the Cyber Threat Intelligence team, maintaining threat indicator feeds that keep your hunts current and your findings actionable. You conduct CND triage, support active incidents with analysis, and author finished intelligence products from open-source portals. Your output reaches both technical peers and program management. What You Will Own Proactive threat hunting across enterprise network environments for undetected adversary activity Malware analysis in support of hunt findings and incident response CND triage and analysis support for active incident response operations Threat indicator feed maintenance in coordination with the Cyber Threat Intelligence team IOC report authorship from open-source intelligence portals After-action and lessons-learned documentation for significant hunts and incidents Security event and metric reporting for program management Responsibilities Proactively hunt for undetected cyber threats across enterprise network environments using network flow, PCAP, log data, endpoint telemetry, and SIEM data; operate ahead of automated detection capabilities Conduct Computer Network Defense (CND) triage: assess alerts and anomalies, determine threat validity, and prioritize findings for response or further investigation Provide analysis support to incident response operations; contribute host and network analysis, malware triage, and attacker TTP reconstruction during active incidents Perform malware analysis on samples collected during hunts and incidents; identify behavioral indicators, persistence mechanisms, and IOCs for operationalization Maintain and update threat indicator feeds in coordination with the Cyber Threat Intelligence team; ensure hunt operations are informed by current intelligence Author IOC reports from open-source intelligence portals; package findings into finished products suitable for both technical teams and program leadership Prepare after-action reports and lessons-learned documentation following significant hunts and incidents; identify detection gaps and recommend improvements Produce security event and metric reports for program management; communicate hunt findings, detection trends, and program health in clear, data-supported terms Develop and maintain reusable hunt tactics, SIEM queries, and detection logic that improve the program's long-term detection capability Stay current on adversary TTPs, malware families, threat actor trends, and emerging attack techniques relevant to the federal enterprise environment What You Bring (Requirements)Baseline Requirements Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) 5 or more years of experience in threat hunting, security operations, or a closely related technical discipline Active Top Secret clearance required Technical & Domain Capabilities Demonstrated experience proactively hunting for adversary activity across enterprise networks using hypothesis-driven and intelligence-driven hunt methodologies Hands-on IDS/IPS experience: signature review, alert triage, anomaly identification, and tuning to reduce noise and improve detection fidelity Proficiency with SIEM platforms: search language, query development, correlation rule creation, dashboard operations, and metric reporting Malware analysis experience including behavioral analysis, static review, IOC extraction, and identification of adversary tooling and techniques Experience conducting CND triage and supporting incident response with technical analysis under operational tempo Experience authoring IOC reports and finished intelligence products from open-source intelligence (OSINT) portals Experience preparing after-action reports and lessons-learned documentation that drive concrete defensive improvements Familiarity with MITRE ATT&CK framework applied to hunt hypothesis development and TTP mapping Current knowledge of adversary TTPs, threat actor trends, and the evolving federal cybersecurity threat landscape Core Strengths Proactive and analytically driven - you hunt because you assume the adversary is already in, and you don't stop until the evidence tells you otherwise Technically fluent across hunting, malware analysis, and incident response - you shift between disciplines fluidly as the mission demands Strong written communicator: your IOC reports, after-actions, and metric reports are clear, accurate, and written for the audience Collaborative partner to threat intelligence and incident response teams - your findings feed the broader program, not just your own queue Certifications One or more of the following is strongly preferred: GCIH (GIAC Certified Incident Handler), GCIA (GIAC Certified Intrusion Analyst), GCTI (GIAC Cyber Threat Intelligence), GREM (GIAC Reverse Engineering Malware), CySA+, or equivalent Nice to Have (Differentiators) Experience threat hunting in a federal civilian, defense, or intelligence SOC environment Proficiency scripting in Python or equivalent for hunt automation and IOC enrichment workflows Experience with threat intelligence platforms (TIPs) and integrating CTI data into active hunt operations Background in advanced malware reverse engineering or exploit analysis Familiarity with cloud-native hunting across commercial or GovCloud environments _ Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-time SBA SBIR Tibbett's Award winner Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to Traditional and HSA- eligible medical insurance plans 100% employer-paid dental and vision insurance options 100% employer-sponsored STD, LTD, and life insurance 5% 401(k) company matching Flexible-schedules and teleworking options Paid holidays and PTO Accrual Plans Paid Parental Leave Professional development and career growth opportunities Team and company-wide events, recognition, and appreciation and so much more! Check out our Revolutional LinkedIn to find out a little more about who we are and if we are the right next step for your career! Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender . click apply for full job details
09/07/2026
Full time
Job Description Job Description Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Senior Threat Hunter Analyst Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred) Terms: Full-time Salary: $125-$150k DOE Clearance: Active Top Secret required Travel: 0-10% Project Description This position supports a large-scale federal security operations program delivering 24/7/365 continuous monitoring, intrusion detection, threat hunting, incident response, and threat intelligence across a complex enterprise network environment. The threat hunting function operates at the leading edge of the program's defensive posture - finding what automated tools miss before it becomes a confirmed incident. The core challenge: proactively hunting adversary activity across a large, high-complexity enterprise network, supporting active incident response, and producing intelligence products that sharpen the program's detection and response capabilities over time. Position Description As a Senior Threat Hunter Analyst at Revolutional, you operate ahead of the threat - proactively hunting for undetected adversary activity across enterprise networks before it surfaces through automated detection. You are a technically deep practitioner who combines hunting tradecraft with malware analysis capability, incident response support, and the discipline to produce IOC reports, after-action reviews, and security metric reporting that make the program measurably better over time. You work in close coordination with the Cyber Threat Intelligence team, maintaining threat indicator feeds that keep your hunts current and your findings actionable. You conduct CND triage, support active incidents with analysis, and author finished intelligence products from open-source portals. Your output reaches both technical peers and program management. What You Will Own Proactive threat hunting across enterprise network environments for undetected adversary activity Malware analysis in support of hunt findings and incident response CND triage and analysis support for active incident response operations Threat indicator feed maintenance in coordination with the Cyber Threat Intelligence team IOC report authorship from open-source intelligence portals After-action and lessons-learned documentation for significant hunts and incidents Security event and metric reporting for program management Responsibilities Proactively hunt for undetected cyber threats across enterprise network environments using network flow, PCAP, log data, endpoint telemetry, and SIEM data; operate ahead of automated detection capabilities Conduct Computer Network Defense (CND) triage: assess alerts and anomalies, determine threat validity, and prioritize findings for response or further investigation Provide analysis support to incident response operations; contribute host and network analysis, malware triage, and attacker TTP reconstruction during active incidents Perform malware analysis on samples collected during hunts and incidents; identify behavioral indicators, persistence mechanisms, and IOCs for operationalization Maintain and update threat indicator feeds in coordination with the Cyber Threat Intelligence team; ensure hunt operations are informed by current intelligence Author IOC reports from open-source intelligence portals; package findings into finished products suitable for both technical teams and program leadership Prepare after-action reports and lessons-learned documentation following significant hunts and incidents; identify detection gaps and recommend improvements Produce security event and metric reports for program management; communicate hunt findings, detection trends, and program health in clear, data-supported terms Develop and maintain reusable hunt tactics, SIEM queries, and detection logic that improve the program's long-term detection capability Stay current on adversary TTPs, malware families, threat actor trends, and emerging attack techniques relevant to the federal enterprise environment What You Bring (Requirements)Baseline Requirements Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) 5 or more years of experience in threat hunting, security operations, or a closely related technical discipline Active Top Secret clearance required Technical & Domain Capabilities Demonstrated experience proactively hunting for adversary activity across enterprise networks using hypothesis-driven and intelligence-driven hunt methodologies Hands-on IDS/IPS experience: signature review, alert triage, anomaly identification, and tuning to reduce noise and improve detection fidelity Proficiency with SIEM platforms: search language, query development, correlation rule creation, dashboard operations, and metric reporting Malware analysis experience including behavioral analysis, static review, IOC extraction, and identification of adversary tooling and techniques Experience conducting CND triage and supporting incident response with technical analysis under operational tempo Experience authoring IOC reports and finished intelligence products from open-source intelligence (OSINT) portals Experience preparing after-action reports and lessons-learned documentation that drive concrete defensive improvements Familiarity with MITRE ATT&CK framework applied to hunt hypothesis development and TTP mapping Current knowledge of adversary TTPs, threat actor trends, and the evolving federal cybersecurity threat landscape Core Strengths Proactive and analytically driven - you hunt because you assume the adversary is already in, and you don't stop until the evidence tells you otherwise Technically fluent across hunting, malware analysis, and incident response - you shift between disciplines fluidly as the mission demands Strong written communicator: your IOC reports, after-actions, and metric reports are clear, accurate, and written for the audience Collaborative partner to threat intelligence and incident response teams - your findings feed the broader program, not just your own queue Certifications One or more of the following is strongly preferred: GCIH (GIAC Certified Incident Handler), GCIA (GIAC Certified Intrusion Analyst), GCTI (GIAC Cyber Threat Intelligence), GREM (GIAC Reverse Engineering Malware), CySA+, or equivalent Nice to Have (Differentiators) Experience threat hunting in a federal civilian, defense, or intelligence SOC environment Proficiency scripting in Python or equivalent for hunt automation and IOC enrichment workflows Experience with threat intelligence platforms (TIPs) and integrating CTI data into active hunt operations Background in advanced malware reverse engineering or exploit analysis Familiarity with cloud-native hunting across commercial or GovCloud environments _ Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-time SBA SBIR Tibbett's Award winner Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to Traditional and HSA- eligible medical insurance plans 100% employer-paid dental and vision insurance options 100% employer-sponsored STD, LTD, and life insurance 5% 401(k) company matching Flexible-schedules and teleworking options Paid holidays and PTO Accrual Plans Paid Parental Leave Professional development and career growth opportunities Team and company-wide events, recognition, and appreciation and so much more! Check out our Revolutional LinkedIn to find out a little more about who we are and if we are the right next step for your career! Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender . click apply for full job details
Invictus International Consulting, LLC
Colorado Springs, Colorado
Job Description Job Description Title: Security Operations Center Technical Lead Location: Colorado Springs, CO Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Responsibilities:Serve as the senior technical authority for SOC watch operations, cyber defense analysis, threat hunting, incident response, and operational cyber risk supporting the establishment and maturation of a new DoD SOCLead the most complex cyber defense investigations, incident-response activities, threat-hunting campaigns, and exposure assessments while providing technical direction when scope, impact, evidence, or response options are uncertainPerform advanced analysis of host and network telemetry, firewall and IDS/IPS data, authentication activity, endpoint data, intrusion artifacts, vulnerabilities, configurations, and other relevant security evidenceEstablish and continuously improve SOC investigative methodologies, triage standards, severity and escalation criteria, evidence requirements, incident workflows, threat-hunting processes, case-quality standards, and shift-turnover practicesServe as the highest-level operational escalation point for SOC personnel and mentor senior and developing analysts through complex investigations, threat hunts, exercises, and defensive activitiesLead advanced threat-hunting campaigns based on threat intelligence, adversary TTPs, mission priorities, incidents, environmental changes, and identified detection gapsApply MITRE ATT&CK, threat intelligence, network forensics, host analysis, vulnerability context, adversary analysis, and threat-informed defense techniques to complex investigations and proactive defensive operationsEstablish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize operational cyber riskLead complex cyber exposure and impact assessments, including exploitation scenarios, attack paths, affected-system analysis, compensating controls, and risk-informed courses of actionCoordinate significant incidents, cyber findings, and operational risks with government stakeholders, ISSOs/ISSMs, system owners, administrators, engineers, incident-response organizations, and other agencies as requiredPartner with cybersecurity engineering teams to translate operational requirements into actionable SIEM/SOAR, network monitoring, endpoint, telemetry, analytics, enrichment, automation, and detection capabilitiesIdentify systemic visibility, detection, tooling, workflow, exposure, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security postureLead development and validation of SOPs, runbooks, incident-response and threat-hunting playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actionsProvide senior technical guidance to SOC leadership through risk assessments, threat assessments, metrics, briefings, and recommendations addressing watch readiness, threat activity, high-risk exposures, capability gaps, remediation priorities, and defensive improvements Requirements:Bachelor 's degree in a relevant discipline; four additional years of relevant experience may be substituted in lieu of a degreeMinimum 8 years of directly related cybersecurity experienceMust possess a DoD 8570 IAT Level II or IAM Level II certificationExperience supporting DoD or Intelligence Community environments is desiredExpert-level, hands-on experience in SOC operations, cyber defense analysis, incident investigation, incident response, threat hunting, adversary analysis, or closely related cybersecurity operationsDemonstrated ability to establish or materially improve SOC operating procedures, investigative standards, threat-hunting methodologies, incident workflows, or analyst qualification/training programsExpert knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, adversary TTPs, threat intelligence, vulnerability/exposure management, and threat-informed defenseStrong knowledge of MITRE ATT&CK and experience operationalizing threat intelligence in SOC, threat-hunting, or cyber defense activitiesDemonstrated experience correlating vulnerability, asset, configuration, threat, incident, and security-control data to assess operational risk and prioritize remediation or defensive actionsExperience with SIEM/SOAR, detection engineering, network-security monitoring, endpoint security, vulnerability management, asset discovery, and continuous monitoring capabilitiesExperience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desiredExperience helping establish, transform, or mature a SOC, CSIRT, threat-hunting, or cyber defense capability is highly desiredTS/SCI with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
09/07/2026
Full time
Job Description Job Description Title: Security Operations Center Technical Lead Location: Colorado Springs, CO Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Responsibilities:Serve as the senior technical authority for SOC watch operations, cyber defense analysis, threat hunting, incident response, and operational cyber risk supporting the establishment and maturation of a new DoD SOCLead the most complex cyber defense investigations, incident-response activities, threat-hunting campaigns, and exposure assessments while providing technical direction when scope, impact, evidence, or response options are uncertainPerform advanced analysis of host and network telemetry, firewall and IDS/IPS data, authentication activity, endpoint data, intrusion artifacts, vulnerabilities, configurations, and other relevant security evidenceEstablish and continuously improve SOC investigative methodologies, triage standards, severity and escalation criteria, evidence requirements, incident workflows, threat-hunting processes, case-quality standards, and shift-turnover practicesServe as the highest-level operational escalation point for SOC personnel and mentor senior and developing analysts through complex investigations, threat hunts, exercises, and defensive activitiesLead advanced threat-hunting campaigns based on threat intelligence, adversary TTPs, mission priorities, incidents, environmental changes, and identified detection gapsApply MITRE ATT&CK, threat intelligence, network forensics, host analysis, vulnerability context, adversary analysis, and threat-informed defense techniques to complex investigations and proactive defensive operationsEstablish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize operational cyber riskLead complex cyber exposure and impact assessments, including exploitation scenarios, attack paths, affected-system analysis, compensating controls, and risk-informed courses of actionCoordinate significant incidents, cyber findings, and operational risks with government stakeholders, ISSOs/ISSMs, system owners, administrators, engineers, incident-response organizations, and other agencies as requiredPartner with cybersecurity engineering teams to translate operational requirements into actionable SIEM/SOAR, network monitoring, endpoint, telemetry, analytics, enrichment, automation, and detection capabilitiesIdentify systemic visibility, detection, tooling, workflow, exposure, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security postureLead development and validation of SOPs, runbooks, incident-response and threat-hunting playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actionsProvide senior technical guidance to SOC leadership through risk assessments, threat assessments, metrics, briefings, and recommendations addressing watch readiness, threat activity, high-risk exposures, capability gaps, remediation priorities, and defensive improvements Requirements:Bachelor 's degree in a relevant discipline; four additional years of relevant experience may be substituted in lieu of a degreeMinimum 8 years of directly related cybersecurity experienceMust possess a DoD 8570 IAT Level II or IAM Level II certificationExperience supporting DoD or Intelligence Community environments is desiredExpert-level, hands-on experience in SOC operations, cyber defense analysis, incident investigation, incident response, threat hunting, adversary analysis, or closely related cybersecurity operationsDemonstrated ability to establish or materially improve SOC operating procedures, investigative standards, threat-hunting methodologies, incident workflows, or analyst qualification/training programsExpert knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, adversary TTPs, threat intelligence, vulnerability/exposure management, and threat-informed defenseStrong knowledge of MITRE ATT&CK and experience operationalizing threat intelligence in SOC, threat-hunting, or cyber defense activitiesDemonstrated experience correlating vulnerability, asset, configuration, threat, incident, and security-control data to assess operational risk and prioritize remediation or defensive actionsExperience with SIEM/SOAR, detection engineering, network-security monitoring, endpoint security, vulnerability management, asset discovery, and continuous monitoring capabilitiesExperience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desiredExperience helping establish, transform, or mature a SOC, CSIRT, threat-hunting, or cyber defense capability is highly desiredTS/SCI with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled Job Posted by ApplicantPro
Job Description Job Description ARES is seeking an experienced senior cybersecurity analyst to join our security control assessment, vulnerability assessment, software assurance, and risk assessment teams supporting our Nation's ballistic missile defense program. This individual will perform research, analysis, and data gathering activities while conducting threat, vulnerability, and capability maturity assessments. The individual will be expected to apply critical thinking, conduct gap analyses, and develop implementation plans for the improvement of cybersecurity in large, complex defense systems. This position is an onsite role in Colorado Springs, CO (Schriever AFB), and will require an active DOD clearance. Required Qualification s: Bachelor's degree in Computer Science, Information Systems or related field. Senior Cybersecurity certification: CASP+ CE, CCNP Security, CISA, CISSP, GCED, or GCIH Active DoD Clearance Required Proficient in technical services and analysis with knowledge of cybersecurity standards, principles, practices, and processes. Experience supporting key cybersecurity activities including vulnerability assessments, control development, security plan documentation, penetration testing, and the Risk Management Framework (RMF). Familiarity with cybersecurity tools such as Nessus, Burp Suite, Nmap, ACAS, and others. ARES Benefits: ARES offers a competitive compensation and benefit package. Full time employees may participate in: Medical Insurance Dental Insurance Vision Insurance HSA/FSA Accounts Life & Disability Insurance Critical Illness & Accident Insurance 401(k) Plan ESOP Paid Time Off & Holidays ARES is an equal opportunity employer and complies with E-Verify. We believe in hiring a diverse workforce and fostering an inclusive culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law. ARES shall abide by the requirements of 41 CFR 60-1.4(a), 60-300.5(a) and 60-741.5(a). Our stated salary range represents a general guideline. However, ARES considers a number of factors when determining salary offers such as current market conditions, the scope and responsibilities of the position and the candidate's experience, education, and skills. Applications are going to be accepted on an ongoing basis until the position has been filled.
09/07/2026
Full time
Job Description Job Description ARES is seeking an experienced senior cybersecurity analyst to join our security control assessment, vulnerability assessment, software assurance, and risk assessment teams supporting our Nation's ballistic missile defense program. This individual will perform research, analysis, and data gathering activities while conducting threat, vulnerability, and capability maturity assessments. The individual will be expected to apply critical thinking, conduct gap analyses, and develop implementation plans for the improvement of cybersecurity in large, complex defense systems. This position is an onsite role in Colorado Springs, CO (Schriever AFB), and will require an active DOD clearance. Required Qualification s: Bachelor's degree in Computer Science, Information Systems or related field. Senior Cybersecurity certification: CASP+ CE, CCNP Security, CISA, CISSP, GCED, or GCIH Active DoD Clearance Required Proficient in technical services and analysis with knowledge of cybersecurity standards, principles, practices, and processes. Experience supporting key cybersecurity activities including vulnerability assessments, control development, security plan documentation, penetration testing, and the Risk Management Framework (RMF). Familiarity with cybersecurity tools such as Nessus, Burp Suite, Nmap, ACAS, and others. ARES Benefits: ARES offers a competitive compensation and benefit package. Full time employees may participate in: Medical Insurance Dental Insurance Vision Insurance HSA/FSA Accounts Life & Disability Insurance Critical Illness & Accident Insurance 401(k) Plan ESOP Paid Time Off & Holidays ARES is an equal opportunity employer and complies with E-Verify. We believe in hiring a diverse workforce and fostering an inclusive culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law. ARES shall abide by the requirements of 41 CFR 60-1.4(a), 60-300.5(a) and 60-741.5(a). Our stated salary range represents a general guideline. However, ARES considers a number of factors when determining salary offers such as current market conditions, the scope and responsibilities of the position and the candidate's experience, education, and skills. Applications are going to be accepted on an ongoing basis until the position has been filled.