Invictus International Consulting, LLC

Cybersecurity Risk & Exposure Analyst III

Invictus International Consulting, LLC Alexandria, Virginia, United States

Defense and Space Manufacturing · 201-500 employees

3 d ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

Lead complex operational cyber risk and exposure analysis to support SOC investigations and threat-informed vulnerability prioritization. Coordinate with system owners and security personnel to translate findings into actionable mitigation and RMF follow-up actions.

What they look for

Cybersecurity Risk Analysis Vulnerability Management Threat Intelligence SOC Investigations Continuous Monitoring DoD RMF ACAS Tenable RunZero STIG SCAP POA&M Incident Response Network Security System Security Technical Risk Assessment

Requirements

Requires a bachelor's degree in a technical discipline or equivalent experience, plus at least six years of relevant professional experience. Candidates must possess a current TS/SCI clearance and a DoD 8570 IAT II or IAM II certification.

Full description

Title: Senior Cybersecurity Risk & Exposure Analyst III

Location: Alexandria, VA

Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph

Job Details:

  • Lead complex operational cyber risk and exposure analysis supporting SOC investigations, threat-informed vulnerability prioritization, continuous monitoring, and remediation activities across DoD systems and sites
  • Correlate vulnerability data, asset discovery, system criticality, network reachability, security configuration, known controls, threat activity, and SOC findings to identify exposures that present the greatest operational or mission risk
  • Analyze vulnerabilities and configuration weaknesses in context, including plausible exploitation paths, adversary TTPs, affected technologies, compensating controls, mission/availability impact, and evidence from active or historical SOC investigations
  • Serve as a senior technical resource to Cybersecurity Operations and Threat Analysts for vulnerability, asset, control, and system-security context during complex investigations and proactive hunting activities
  • Coordinate with system ISSOs/ISSMs, system owners, engineers, administrators, authorization personnel, and remediation teams to translate SOC-derived findings into actionable mitigation, continuous-monitoring, POA&M, or RMF follow-up as applicable
  • Develop and maintain operational exposure-analysis procedures, risk-prioritization methods, technical checklists, TTPs, guides, briefings, and other products that improve consistency and decision quality
  • Review remediation evidence, recurring findings, exposure trends, POA&M-related items, and metrics to identify systemic risk, validate corrective actions, and drive closure or escalation
  • Support RMF and assessment activities where SOC findings or operational exposure data affect security-control effectiveness, system risk, or authorization posture, while coordinating with the responsible system security personnel
  • Mentor Level I and II personnel and review analytical work products for technical accuracy, risk context, completeness, and clear communication

Requirements:

  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum six (6) years of relevant experience in addition to education level
  • Demonstrated knowledge of vulnerability/exposure management, threat-informed risk analysis, DoD continuous monitoring, RMF/security controls, network/system security, and technical risk assessment
  • Experience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and coordination with SOC/incident-response and ISSO/ISSM functions is desired
  • Demonstrated experience leading complex exposure or vulnerability analysis, prioritizing technical risk, coordinating remediation, and translating cyber findings into continuous-monitoring or RMF actions is strongly desired
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

Equal Opportunity Employer/Veteran/Disabled

Similar roles