Cybersecurity Administrator at Q.E.D. Systems, Inc. in Virginia Beach, VA
- Company: Q.E.D. Systems, Inc.
- Location: Virginia Beach, VA
- Posted: Sep 18, 2026
- Type: Full-time
- Salary: $40 - $55/hr
- Experience: 5+ years
Overview
The Cybersecurity Administrator is responsible for implementing and maintaining the security controls required for CMMC (Cybersecurity Maturity Model Certification) Level 2 across the enterprise, in accordance with NIST SP 800-171, Protecting Controlled Unclassified Information. The administrator wi…
Job description
- The Cybersecurity Administrator is responsible for implementing and maintaining the security controls required for CMMC (Cybersecurity Maturity Model Certification) Level 2 across the enterprise, in accordance with NIST SP 800-171, Protecting Controlled Unclassified Information. The administrator will maintain and improve the organization’s System Security Plan (SSP) and Plan of Action and Milestones (POA&M), support assessment readiness with the company’s C3PAO and DIBCAC, and help sustain the security of Controlled Unclassified Information (CUI).
- The Cybersecurity Administrator shall have experience with boundary defense techniques, commercial off-the-shelf (COTS) security products, and cloud services used to meet the enterprise’s system security objectives.
Responsibilities
- Plan, develop, implement, test, and document security controls to meet CMMC Level 2 (NIST SP 800-171) requirements
- Develop and enforce information security policy
- Perform IT risk and security assessments and support risk mitigation efforts
- Assess flow-down of DFARS requirements to subcontractors and support vendor/supply-chain risk reviews
- Develop approaches to mitigate vulnerabilities and recommend changes to systems or components as needed
- Facilitate an IT business continuity plan
- Perform internal security control assessments and self-assessments, including SPRS scoring support
- Identify information protection needs for the computing and network environments
- Develop, maintain, and analyze the System Security Plan (SSP) and associated cybersecurity risk analysis
- Advise network, system, and software engineers on the results of cybersecurity risk analysis
- Execute and support network security initiatives
- Conduct vulnerability scanning
- Ensure patch compliance
- Support incident response and remediation efforts
- Participate in assessment activities, including interviews, documentation requests, and artifact requests
- Review responses and deliverables for accuracy and assist with interpreting assessment requests
- Review assessment findings and assist management in developing responses and remediation plans
- Create, track, and provide status updates on Plan of Action and Milestones (POA&M) items
- Develop, update, and maintain metric/KPI status reports on a defined schedule for IT initiatives
- Respond to requests for clarification and information
- Oversee and provide technical guidance to Cybersecurity Analysts
Requirements
- Experience implementing controls to meet NIST SP 800-171 requirements
- Experience designing and maintaining a System Security Plan (SSP)
- Experience performing security audits with and without specialized SIEM tools
- Experience certifying or validating compliance of information systems
- Current certification compatible with IAT Level III in accordance with DoD 8140 (formerly DoD 8570.01-M), or the ability to obtain one within six months of hire
- Comprehensive understanding of computer security and the ability to communicate clearly and succinctly in written and oral presentations
- Working knowledge of a vulnerability management system
- Experience utilizing MS Purview and Data Loss Prevention (DLP) policies
- Experience securing cloud-based security controls
- Bachelor’s degree in computer science, Information Technology, Computer Information Systems, or a related field and 5 years of experience in the field or a related area; or a Master’s degree in a related field and 2 years of experience in the field or a related area. Active industry cybersecurity certifications (ISC2, CompTIA, Cisco, Microsoft) may substitute for some years of experience depending on the certification.
- Requires U.S. citizenship and the ability to obtain a DoD Secret clearance.
- Current ISC2 CISSP certification
- Experience developing and testing an Incident Response Plan
- Mobile Device Management (MDM) administration
- Experience with network administration
- Experience with system administration
- Experience implementing or managing FedRAMP-authorized vendor products (e.g., GCC High)
- Experience in a classified environment
Skills
Preferred
- Current ISC2 CISSP certification
- Experience with network administration
- Experience with system administration
- Experience in a classified environment
Benefits
- Q.E.D. offers competitive benefits such as: Paid Leave, Medical, Dental, Vision, Short/Long-Term Disability, 401(k) retirement plan, Basic Life Insurance, supplemental insurance, and an Employee Assistance Program.