CybersecurityJobs.io
← Back to all jobs

Job Description

IvoryCloud is seeking an experienced Cybersecurity Analyst to act as a technical subject matter expert for DCMA cybersecurity evaluation of product submissions. This role is based on-site at the DCMA facility in Fort Lee, Virginia, supporting cybersecurity requirements, risk management, and assessment methodologies aligned to DoW/DoD RMF.

Role Summary

In this position, you will support the Government Program by providing technical expertise related to cybersecurity requirements, technical standards, and assessment methodologies. The work focuses on evaluating candidate technologies and associated risks, including embedded systems, software, firmware, wireless communications, networking, encryption, authentication, and supply chain security.

Key Responsibilities

  • Serve as a technical subject matter expert (SME) supporting the cybersecurity evaluation of product submissions to the Program.
  • Provide technical expertise and advisory support to the Government Program regarding cybersecurity requirements, technical standards, risk management, and assessment methodologies.
  • Interpret cybersecurity assessment methodologies and technical evidence, including penetration testing results, vulnerability assessments, software assurance evaluations, firmware analyses, and related assessment data.
  • Review cybersecurity assessment reports, supporting technical documentation, and assessment evidence to evaluate completeness, technical sufficiency, and adequacy for Government technical acceptance decisions.
  • Identify cybersecurity vulnerabilities, threats, attack vectors, and residual risks that could adversely affect DoW missions, warfighter safety, national security, operational resilience, and confidentiality, integrity, and availability of Government information and systems.
  • Provide technical recommendations on cybersecurity findings, risk mitigation strategies, assessment requirements, technical acceptance decisions, and applicability of cybersecurity requirements to program candidate technologies.
  • Verify whether a company’s remediation plan sufficiently mitigates cyber vulnerabilities identified in provided assessments.
  • Maintain awareness of applicable Federal statutes, DoW policies, National Defense Authorization Act (NDAA) requirements, cybersecurity frameworks, industry best practices, and Government processes relevant to the Program.
  • Provide technical consultation and advisory support to Government personnel and stakeholders on cybersecurity matters affecting program technologies, assessments, policy implementation, and execution.
  • Monitor emerging cybersecurity threats, vulnerabilities, technologies, and policy developments affecting small unmanned systems and recommend updates supporting continued evolution of the Program.

Required Qualifications

  • U.S. Citizenship: Required, non-negotiable.
  • Clearance: Favorably adjudicated (or actively in-progress) Tier 3 background investigation required for access to Controlled Unclassified Information (CUI). Interim or final security clearance granted by the Department of War (DoW) required prior to start of performance. Current ADP/IT II clearance in the Defense Information System for Security (DISS) required.
  • Experience: Minimum 5 years of practical cybersecurity experience preferred, ideally including technology risk assessment or product security evaluation.
  • Location: Fort Lee, Virginia on-site at the DCMA facility. Initially perform work remotely until Government office space is allocated; Government will provide 30 days’ notice prior to start of on-site work.
  • Demonstrated knowledge of cybersecurity principles applicable to embedded systems, software, firmware, wireless communications, networking, encryption, authentication, and supply chain security.
  • Demonstrated expertise applying federal security directives, including NIST SP 800-53 controls and NIST SP 800-161 (Supply Chain Risk Management), and navigating DoD/DoW Risk Management Framework (RMF) to achieve an Authority to Operate (ATO).
  • Experience interpreting cybersecurity assessment methodologies, penetration testing results, vulnerability assessments, software assurance evaluations, and firmware analyses.
  • Ability to evaluate completeness, technical sufficiency, and adequacy of cybersecurity assessment reports and supporting evidence for Government technical acceptance decisions.
  • Working knowledge of applicable Federal statutes, DoW policies, NDAA requirements, and cybersecurity frameworks relevant to small unmanned systems.

Relevant Technologies and Frameworks

  • NIST SP 800-53
  • NIST SP 800-161
  • DoD/DoW Risk Management Framework (RMF)
  • Authority to Operate (ATO)
  • Defense Information System for Security (DISS)
  • CompTIA Security+
  • CISSP
  • CISM

Preferred Qualifications

  • Direct experience supporting DCMA or related programs.
  • Experience evaluating embedded systems, firmware, and supply chain security risk for commercial or defense technologies.
  • Familiarity with the DoW Risk Management Framework (RMF) and ATO process.
  • Experience reviewing third-party penetration test results and software assurance evaluations for federal acceptance decisions.
  • Active or recent industry certification such as CompTIA Security+, CISSP, or CISM.

Education

Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline.

Certifications

  • No specific certification is mandatory under current program requirements.
  • CompTIA Security+, CISSP, CISM, or an equivalent cybersecurity certification preferred.

Compensation and Benefits

Salary: USD 80,000 - 110,000 per year.

  • Participation in company and Business Development bonus programs
  • 401(k) and 401(k) matching
  • Dental insurance
  • Health insurance
  • Life insurance
  • Paid time off
  • Referral program
  • Retirement plan
  • Vision insurance

Work Location

In person

Application Screening Questions

  • Are you a US Citizen (required)?
  • Are you able to come onsite 5 days a week in Fort Lee, VA?
  • Have you passed a Tier 3 investigation (ADP/IT-II equivalent) or have an investigation in progress?

Similar Jobs