×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity ​/ Information Assurance Lead

Job in Northern, Floyd County, Kentucky, USA
Listing for: Tyto Athene, LLC
Full Time position
Listed on 2026-08-21
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 140000 - 175000 USD Yearly USD 140000.00 175000.00 YEAR
Job Description & How to Apply Below
Location: Northern

Description

Quantum Sky is searching for a Cybersecurity / Information Assurance Lead that serves as the senior authority for enterprise cybersecurity and information assurance across the Joint Virtual Environment (JVE) in support of the F-35 Lightning II Joint Program Office (JPO).

This role owns the cybersecurity strategy and governance for on‑premises and Azure IL‑5 environments, leads Risk Management Framework (RMF) execution and assessment & authorization (A&A) artifacts, directs continuous monitoring (ACAS, STIGs, ESS), and orchestrates incident response to ensure confidentiality, integrity, authenticity, non‑repudiation, and availability of mission services. Onsite presence in Arlington, VA is required; travel may be necessary to support CONUS/OCONUS Tier sites.

Responsibilities:

  • Govern cybersecurity governance and policy: develop,maintain, and annually update security policies, standards, controls, and compliance aligned to DoDI 8500.01, DoDI 8510.01 (RMF), NIST SP 800‑53, CNSS, CCRI criteria, and program directives.
  • Lead RMF and A&A lifecycle: coordinate system categorization, control selection, implementation, assessment, and authorization; produce and maintain the System Security Plan (SSP), Security Assessment Report (SAR), Security Control Traceability Matrix (SCTM), and Plan of Action and Milestones (POA&M) ineMASS.
  • Own continuous monitoring program: ensure monthly ACAS vulnerability scanning (≥98% scan rate), quarterly STIG reviews, and Endpoint Security Services (ESS) scores ≥95% at least 90% of the time; track compliance on a weekly Security Dashboard (≥75% update compliance).
  • Direct vulnerability and patch management: drive remediation governance for IAVA/IAVB, benchmark compliance, and OS STIG settings; ensuretimelyreporting and closure across all assets.
  • Oversee security operations and incident response: ingest SIEM telemetry, lead detection, triage, containment, eradication, and recovery per the OCIO incident response plan; coordinate with CSSP and JFHQ‑DoDIN when thresholds are not met.
  • Embed security into engineering: review architectures, designs, and changes for security impacts; serve as primary liaison between Enterprise Architecture and Systems Security Engineering (ISSE/SSE) to integrate controls through the SE process.
  • Support Technical Design Reviews: provide personnel toparticipatein TDRs/SETRs/ISSEWGs; deliver Cyber Engineering Design Review Reports within 5 business days with risks, findings, and recommended actions.
  • Deliver capability security engineering: execute Common Cyber Modeling Process (or equivalent) and provide Cyber Engineering Capability Reports covering requirements and verification approaches for new capabilities.
  • Lead Zero Trust implementation: advance identity, device, network/environment, application/workload, and data security controls across JVE, coordinating configuration baselines with NOSC operations.
  • Champion security awareness and training:maintain≥95% annual Cyber Awareness training compliance with certificates retrievable 100% of the time.
  • Provide reporting and governance to include

    Monthly Status Reports, POA&M status, vulnerability andeMASSsummaries, and intrusion management reports in alignment with program cadence.

Performance Metrics & Success Criteria:

  • Service Availability:
    Critical services ≥95% monthly uptime; less‑critical services ≥90% during operational hours (excluding external outages).
  • Continuous Monitoring: ACAS scan rate ≥98% monthly; ESS ≥95% in all measured areas at least 90% of the time; STIG reviews conducted quarterly.
  • Risk Governance: POA&M updates weekly with quarterly artifact uploads ineMASS;
    Security Dashboard updated weekly meeting ≥75% update compliance (monthly measure).
  • Vulnerability Management:timelyIAVM acknowledgments and closures; compliance tracked for OS STIG, software inventory patches, and benchmark adherence.
  • Quality & Reporting:accurate, complete, on‑time deliverables per CDRLs; rapid corrective actions and open communications across COR/TPOC governance.
Qualifications

Required:

  • Education:

    MA/MS; substitution allowed with BA/BS and 12+ years of relevant experience.
  • Certification:
    DoD 8140/8570‑aligned IAM Level III…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary