Cybersecurity Risk & Exposure Analyst II

  • Invictus International Consulting, LLC
  • Colorado Springs, Colorado
  • 09/10/2026
Full time Information Technology Telecommunications

Job Description

Job Description Job Description Title: Cybersecurity Risk & Exposure Analyst IILocation: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Independently perform operational vulnerability/exposure analysis and continuous-monitoring activities supporting SOC investigations, cyber risk prioritization, and system security coordinationCorrelate ACAS/Tenable findings, runZero asset context, STIG/configuration information, system criticality, network/security telemetry, and other available data to assess the relevance and potential impact of identified weaknessesProvide vulnerability, asset, configuration, and control context to Cybersecurity Operations and Threat Analysts during investigations and proactive analysis; identify known weaknesses that may contribute to exploitation or increase mission riskCoordinate SOC-derived findings with system ISSOs/ISSMs, system owners, administrators, engineers, and remediation teams to validate affected assets, clarify risk, support mitigation, and determine required continuous-monitoring or RMF follow-upAnalyze recurring vulnerabilities, configuration weaknesses, and exposure patterns to identify remediation priorities and systemic conditions requiring escalation or broader corrective actionDevelop and maintain repeatable checklists, procedures, and metrics for operational exposure analysis, remediation validation, SOC-to-ISSO coordination, and continuous-monitoring supportMaintain accurate records of findings, remediation status, risk decisions, tickets/actions, and supporting evidence in approved systemsApply knowledge of network security, common protocols, system architecture, vulnerabilities, security controls, and DoD requirements to communicate technical risk in operational terms Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum four (4) years of relevant experience in addition to education level Strong written and verbal communication skills and the ability to document technical work clearlyDemonstrated knowledge of vulnerability management, asset and exposure analysis, DoD continuous monitoring, RMF/security controls, and technical risk assessment appropriate to the position levelExperience with ACAS/Tenable, runZero or comparable asset-discovery/exposure tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, security-control evidence, or comparable technologies and processes is desiredAbility to correlate vulnerability, asset, configuration, and system-security information and communicate operational risk to technical and compliance stakeholdersMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environmentCurrent active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled

Job Posted by ApplicantPro