Haystack
← Back to Jobs
Employee
Technology
II

Cybersecurity Risk & Exposure Analyst II with Security Clearance

Invictus International ConsultingAlexandria, VA🇺🇸United StatesPosted 7 Sept 2026

Why This Role Stands Out

Leverage your expertise in cybersecurity risk analysis within a hybrid environment at Invictus International Consulting, where you'll directly contribute to national security by identifying and mitigating critical vulnerabilities. This role offers significant growth potential for mid-senior professionals possessing a TS/SCI clearance and a proactive approach to security, making it an excellent opportunity to advance your career and skills.

Quick Overview

Seniority
Mid Senior
Employment type
Employee
Work mode
Hybrid
Location
Alexandria, VA, United States
Posted
Yesterday

Job Description

Title: Cybersecurity Risk & Exposure Analyst II Location: Alexandria, VA  Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:

  • Independently perform operational vulnerability/exposure analysis and continuous-monitoring activities supporting SOC investigations, cyber risk prioritization, and system security coordination
  • Correlate ACAS/Tenable findings, runZero asset context, STIG/configuration information, system criticality, network/security telemetry, and other available data to assess the relevance and potential impact of identified weaknesses
  • Provide vulnerability, asset, configuration, and control context to Cybersecurity Operations and Threat Analysts during investigations and proactive analysis; identify known weaknesses that may contribute to exploitation or increase mission risk
  • Coordinate SOC-derived findings with system ISSOs/ISSMs, system owners, administrators, engineers, and remediation teams to validate affected assets, clarify risk, support mitigation, and determine required continuous-monitoring or RMF follow-up
  • Analyze recurring vulnerabilities, configuration weaknesses, and exposure patterns to identify remediation priorities and systemic conditions requiring escalation or broader corrective action
  • Develop and maintain repeatable checklists, procedures, and metrics for operational exposure analysis, remediation validation, SOC-to-ISSO coordination, and continuous-monitoring support
  • Maintain accurate records of findings, remediation status, risk decisions, tickets/actions, and supporting evidence in approved systems
  • Apply knowledge of network security, common protocols, system architecture, vulnerabilities, security controls, and DoD requirements to communicate technical risk in operational terms Requirements:
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum four (4) years of relevant experience in addition to education level
  • Strong written and verbal communication skills and the ability to document technical work clearly
  • Demonstrated knowledge of vulnerability management, asset and exposure analysis, DoD continuous monitoring, RMF/security controls, and technical risk assessment appropriate to the position level
  • Experience with ACAS/Tenable, runZero or comparable asset-discovery/exposure tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, security-control evidence, or comparable technologies and processes is desired
  • Ability to correlate vulnerability, asset, configuration, and system-security information and communicate operational risk to technical and compliance stakeholdersMust possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

Equal Opportunity Employer/Veteran/Disabled

Similar jobs