Senior Cybersecurity Risk & Exposure Analyst III with Security Clearance
Why This Role Stands Out
This hybrid role offers significant opportunities for growth as you lead critical cybersecurity risk analysis for DoD systems, developing advanced threat-informed prioritization methods and directly impacting mission security. You'll thrive here if you possess a strong analytical mindset, enjoy complex problem-solving, and are eager to collaborate with diverse teams to mitigate high-impact exposures. Apply now to leverage your TS/SCI clearance in a role that champions impactful work and continuous learning.
Quick Overview
Job Description
Title: Senior Cybersecurity Risk & Exposure Analyst III Location: Alexandria, VA Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Description: Invictus, a Red River company, delivers technology and services supporting government and national security missions. We combine cleared mission expertise with enterprise engineering, technology partnerships and large-program execution in support of advanced modernization, cybersecurity, intelligence and systems integration. Our teams support complex operational environments across the U.S. and around the world, helping customers strengthen resilience, accelerate mission outcomes and deploy capabilities that meet demanding mission requirements. Learn more at www. InvictusIC.com.
Job Details
- Lead complex operational cyber risk and exposure analysis supporting SOC investigations, threat-informed vulnerability prioritization, continuous monitoring, and remediation activities across DoD systems and sites
- Correlate vulnerability data, asset discovery, system criticality, network reachability, security configuration, known controls, threat activity, and SOC findings to identify exposures that present the greatest operational or mission risk
- Analyze vulnerabilities and configuration weaknesses in context, including plausible exploitation paths, adversary TTPs, affected technologies, compensating controls, mission/availability impact, and evidence from active or historical SOC investigations
- Serve as a senior technical resource to Cybersecurity Operations and Threat Analysts for vulnerability, asset, control, and system-security context during complex investigations and proactive hunting activities
- Coordinate with system ISSOs/ISSMs, system owners, engineers, administrators, authorization personnel, and remediation teams to translate SOC-derived findings into actionable mitigation, continuous-monitoring, POA&M, or RMF follow-up as applicable
- Develop and maintain operational exposure-analysis procedures, risk-prioritization methods, technical checklists, TTPs, guides, briefings, and other products that improve consistency and decision quality
- Review remediation evidence, recurring findings, exposure trends, POA&M-related items, and metrics to identify systemic risk, validate corrective actions, and drive closure or escalation
- Support RMF and assessment activities where SOC findings or operational exposure data affect security-control effectiveness, system risk, or authorization posture, while coordinating with the responsible system security personnel
- Mentor Level I and II personnel and review analytical work products for technical accuracy, risk context, completeness, and clear communication Requirements:
- Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
- Minimum six (6) years of relevant experience in addition to education level
- Demonstrated knowledge of vulnerability/exposure management, threat-informed risk analysis, DoD continuous monitoring, RMF/security controls, network/system security, and technical risk assessment
- Experience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and coordination with SOC/incident-response and ISSO/ISSM functions is desired
- Demonstrated experience leading complex exposure or vulnerability analysis, prioritizing technical risk, coordinating remediation, and translating cyber findings into continuous-monitoring or RMF actions is strongly desired
- Must possess current DoD 8570 IAT II or IAM II certification
- Experience working in a DoD or IC environment
- Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph
Equal Opportunity Employer/Veteran/Disabled
Similar jobs
- TR
Vulnerability Management Analyst
NewTriosysIT Inc.
Richmond, VA🇺🇸Hybrid14 hours agoComplianceTechnology - CM
Program Security Analyst
NewComputer Merchant, Ltd., The
Boston, MA🇺🇸$95 - $100/hrHybrid14 hours agoTechnology - CI
Endpoint Security Engineer III
NewCACI International, Inc.
Springfield, VA🇺🇸$75.2k - $158.1k/yrHybrid14 hours agoAWSActive DirectoryVMwareTechnology - CI
Endpoint Security Engineer III - Nessus
NewCACI International, Inc.
Springfield, VA🇺🇸$75.2k - $158.1k/yrHybrid14 hours agoPowerShellPythonTechnology - CI
Cyber Reverse Engineer
NewCACI International, Inc.
Aberdeen, MD🇺🇸$90.3k - $189.6k/yrHybrid14 hours agoArticulateC++Java+2Technology - CI
Cybersecurity Engineer
NewCACI International, Inc.
Alexandria, VA🇺🇸$120.8k - $265.8k/yrHybrid14 hours agoDroneTechnology