Home / Military to civilian jobs / Army / 35Q

ArmyMOS 35Q

Cryptologic Cyberspace Intelligence Collector/Analyst

That is Army MOS 35Q. Civilian jobs, federal paths, and how the work reads on a resume.

What is in this guide

Salary range
$67K to $170K
Career paths
15
Federal GS series
7
Companies hiring
14
Resume examples
10
Certification paths
8
Questions answered
11

What the translation looks like

How it reads in service

Performed cryptologic SIGINT collection against priority adversary networks producing 200+ reports.

How a hiring manager reads it

Conducted advanced network traffic analysis and adversary signal intelligence, producing 200+ structured intelligence reports informing operational decisions.


Roles this background maps to

  • Cyber Threat Intelligence Analyst$140,000
  • Information Security Analyst$124,910
  • SOC Analyst (Cleared)$110,000

Median pay, BLS OEWS May 2024

Build a resume for a real job

You pick the job. We write it from your 35Q experience. Free to start.

Brad TachiNavy Diver · BMR founder

After the Navy he was hired into six federal career fields and tech sales, and sat on federal hiring panels along the way. The last two years went into rebuilding all of it into BMR, tuned for how resumes get screened today. 71,892 resumes built so far.

Get a free 35Q Cryptologic Cyberspace Intelligence Collector/Analyst sample resume

One page, built in our template, with the military experience translated into the civilian terms hiring managers and screening software read. Use it as a reference for your own. Leave an email and the download link comes to you.

Free. Occasional job-search tips come with it. Unsubscribe anytime.

What the job actually is

Army 35Qs sit at the intersection of signals intelligence collection and cyberspace operations. The MOS exists because modern adversaries do not separate radio frequency and IP traffic the way the older 35-series job tree did, so the Army built one role to handle target development, network analysis, cyber threat reporting, and integrated SIGINT/cyber collection inside the same workflow. If you are reading this, you already know that "cyberspace intelligence collector/analyst" is shorthand for a deep stack of TTPs, tooling, and reporting workflows you cannot fully describe on a resume.

The pipeline is long and selective. You started with 10 weeks of Basic Combat Training, then moved to the U.S. Army Intelligence Center of Excellence at Goodfellow AFB in San Angelo, Texas for roughly 30+ weeks of initial training, followed by additional cyber-focused instruction depending on follow-on assignment. Expect to come out the other end with TS/SCI eligibility, an active polygraph in many cases, hands-on experience with cryptologic SIGINT systems, and exposure to cyberspace operations alongside NSA elements, Cyber Mission Force teams, and joint cryptologic activities.

Day to day, 35Qs do the unglamorous parts of cyber intelligence: target development on adversary networks, traffic analysis, malware and TTP reporting, fusion of SIGINT with all-source intel, and supporting offensive and defensive cyber operations. That work translates directly into the cleared private sector and into federal civilian positions at 35N SIGINT analyst and 17C Cyber Operations Specialist destinations, but the 35Q angle skews more toward NSA, US Cyber Command, and DoD cyber contractors than the broader analyst tracks. The challenge is reframing 35Q-specific tooling and tradecraft into civilian language that does not leak classified specifics. The military-to-civilian career crosswalk is a fast way to scope salary ranges and federal series before you sit down to write anything.

For deeper context on how the broader 35-series translates, the military intelligence 35-series civilian careers guide covers the cross-MOS overlap with NSA, DIA, and the cleared contractor space.

BMR has built more than 55,000 resumes across every MOS, and 35Qs sit at one of the most undersupplied corners of the cleared cyber market. The combination of credentialed SIGINT collection, cyberspace intelligence training, and active TS/SCI is exactly the package NSA, US Cyber Command, and DoD cyber contractors compete for. The challenge is reframing 35Q-specific tooling and tradecraft into civilian language without leaking what cannot be discussed. — Brad Tachi, Navy Diver veteran & BMR founder

Security clearance
Top Secret/SCI
ASVAB requirement
GT: 110, ST: 112
Training
10 weeks Basic Combat Training (Fort Jackson, Fort Sill, or Fort Moore); ~30+ weeks initial SIGINT/cyber intelligence training at Goodfellow AFB, TX (U.S. Army Intelligence Center of Excellence); follow-on cyber-focused training depending on assignment; ongoing skill identifier and advanced training throughout career
Certs earned in service
Active TS/SCI security clearance with polygraph (in many cases), Cryptologic SIGINT collection and analysis training, Cyberspace intelligence operations training, Some may earn industry certifications during service depending on command

Pay reality check

The number that decides most of this: how does civilian pay compare to what the paycheck looks like now?

Army mid-career

$58K to $82K

E-5 to E-7 total comp: base plus BAH, BAS and the tax advantage.

Civilian Cryptologic Cyberspace Intelligence Collector/Analyst

$110K to $140K

BLS median across the direct-match civilian roles on this page.

Federal, GS-9 to GS-13

$58K to $120K

7 matching GS series, plus locality pay and step increases.

About 82% higher on average

Civilian roles for Cryptologic Cyberspace Intelligence Collector/Analysts pay about $57K more than mid-career enlisted total comp.

Military comp is approximate and moves with location and dependents. Civilian is the BLS median. Federal includes locality pay. The real number depends on duty station, family status, GS step and overtime.

Private sector career paths

Civilian demand for cleared cyber intelligence backgrounds is structural, not cyclical. The cleared talent pool stays small because clearances take 12-18 months to adjudicate from a cold start, and employers who already have cleared contracts cannot wait that long. A separating 35Q with active TS/SCI and a polygraph walks into that market with leverage most civilian candidates never have.

Information Security Analyst

BLS OEWS May 2024 reports a median wage of $124,910 for Information Security Analysts (15-1212.00), with the top 10% above $182,000. Demand is projected to grow 33% through 2033 (BLS Employment Projections), one of the fastest growth rates BLS tracks. 35Qs land in this category at threat intelligence analyst, SOC analyst, and detection engineering roles. Companies running cleared SOCs (NSA contracts, DoD cyber contracts, intelligence community support) actively recruit for SIGINT-trained analysts because the analytical workflow is the same as commercial threat hunting, just with different sensors.

Cyber Threat Intelligence Analyst

Threat intel as a discipline is the closest civilian analog to cyberspace SIGINT collection. Mandiant (now part of Google Cloud), CrowdStrike, Recorded Future, and the threat intel arms of large MSSPs all hire 35Qs into roles that map their SIGINT target development experience to adversary tracking and attribution. BLS rolls these into the Information Security Analyst category, but compensation skews higher when clearance and IC experience are required (commonly $140K-$180K base for cleared CTI roles).

Penetration Tester / Red Team Operator

Penetration Testers fall under the same BLS occupation (15-1212.00) but represent a different pivot. Some 35Qs cross over into red team work, especially those who came out of the cyberspace operations side of the house. Cleared red team contracts at Booz Allen, Leidos, and Mandiant frequently require TS/SCI plus offensive cyber experience.

Computer Network Architect

BLS reports a median of $129,840 for Computer Network Architects (15-1241.00). 35Qs with strong network analysis backgrounds shift into network design and architecture, particularly for cleared environments where SCIF-grade network design is a specialized discipline.

Intelligence Analyst (Non-Cyber)

BLS does not break out "intelligence analyst" separately, so the data sits under Miscellaneous Social Scientists (19-3099) or Management Analysts (13-1111) depending on the role. For all-source intel analyst roles in the IC and contractor space, the salary band is $90K-$140K depending on clearance and specialty. 35Qs who want the cyber sensor work to recede in favor of broader analytical roles often pivot into all-source intel — see the 35F Intelligence Analyst transition page for adjacent paths.

Cross-Branch Civilian Overlap

Your closest counterparts in other services include Navy CTNs, Air Force 1B4X1 Cyber Warfare Operations, and Marine 0651 Cyber Network Operators. They compete for the same civilian roles, so understanding what they bring to the market helps you position yourself.

Geography matters more than most veterans expect. The cleared cyber market concentrates around Fort Meade/Annapolis Junction, Northern Virginia, San Antonio, Hawaii, Augusta GA (Fort Eisenhower), and Colorado Springs. Remote-eligible cleared work exists but is limited because the work is performed inside SCIFs. If you are open to relocating to a corridor with cleared facilities, the salary numbers above are realistic. If you are tied to a non-cleared geography, expect to take a pay cut to enter a commercial cyber role and then rebuild compensation through certifications. The military-to-civilian salary guide walks through how clearance and location modify base compensation in 2026.

When you are ready to put the resume together, the military resume builder handles the SIGINT-to-civilian translation. For high-intent next steps, build your resume now.

Civilian job title translations

Civilian job titleIndustryBLS median salaryOutlookMatch
Cyber Threat Intelligence AnalystO*NET 15-1212.00Cleared Cybersecurity$140,00033% (Much faster than average)strong
Information Security AnalystO*NET 15-1212.00Cybersecurity$124,91033% (Much faster than average)strong
SOC Analyst (Cleared)O*NET 15-1212.00Cleared Cybersecurity$110,00033% (Much faster than average)strong
Penetration Tester / Red Team OperatorO*NET 15-1212.00Cybersecurity$132,00033% (Much faster than average)moderate
Computer Network ArchitectO*NET 15-1241.00IT Infrastructure$129,84013% (Faster than average)moderate
Intelligence Analyst (All-Source)O*NET 13-1199.00Defense / Intelligence$115,000Steady (BLS does not publish this category separately)strong
Detection EngineerO*NET 15-1299.00Cybersecurity$135,00033% (Much faster than average)strong
Cybersecurity EngineerO*NET 15-1212.00Cybersecurity$133,00033% (Much faster than average)moderate

Companies that hire this background

Booz Allen HamiltonMilitary Recruiting

Top employer for cleared cyber intel veterans. SkillBridge partner; runs DoD cyber and IC contracts at Fort Meade, NoVA, San Antonio.

LeidosMilitary Programs

NSA, US Cyber Command, and IC cyber contract holder. Direct hires for SIGINT-trained analysts.

PeratonVeteran Hiring

Major IC and DoD cyber contractor (formed from former Northrop Grumman federal IT and ManTech). Strong fit for cyber intel veterans.

SAICVeteran Careers

NSA and DIA cyber contracts. Programs for transitioning service members with cleared cyber backgrounds.

CACI InternationalMilitary Hiring

Heavy IC contract presence; cleared cyber, SIGINT, and intel analyst pipelines.

Lockheed MartinMilitary Veteran Hiring

Cyber and SIGINT systems integration work; SkillBridge partner.

Northrop GrummanMilitary Programs

Major cyber and SIGINT systems contractor with cleared engineering and analyst roles.

BAE SystemsMilitary Veteran Careers

Cleared cyber and intelligence systems contracts; intel analyst pipelines.

L3Harris TechnologiesVeteran Hiring

SIGINT systems builder; strong fit for 35Qs with hardware/RF exposure.

RTX (Raytheon)Military Recruiting

Cyber Intel Group runs offensive and defensive cyber contracts; cleared analyst and operator roles.

General Dynamics IT (GDIT)Military Hiring

Largest IC IT services contractor; significant cleared cyber and SIGINT presence at Fort Meade and NoVA.

Mandiant (Google Cloud)Veteran Hiring

Threat intel and incident response leader. Recruits cleared and non-cleared cyber intel analysts.

CrowdStrikeVeterans Program

Threat intel (Falcon OverWatch, Counter Adversary Operations) hires SIGINT-trained analysts.

AmentumMilitary Hiring

Cleared services contractor across DoD and IC including cyber intelligence support.

See a salary you want? Build a resume aimed at it.

BMR rewrites your 35Q experience for any of the roles above, in the language the people reading actually scan for.

Free to start. 2 tailored resumes included.

Build My Resume Free

Already have a resume? Get it graded straight.

Upload it and get a number in about a minute, plus the 35Q lines a civilian hiring manager will not follow. No account. Sign up and BMR writes the fix.

Free. Your file is never stored.

Score my resume free

A Army story from the same road

Taranjeet, success story
I am still getting compliments on my resume. Still getting interviews left and right, and now I have to say no. Very grateful to have so many options suddenly.

Taranjeet · Sergeant (E-5) · Army · Program Management

Read the full story

Federal career paths

Federal civilian work is where many 35Qs land first because the security clearance carries forward without re-adjudication, the work is genuinely similar to active duty, and Veterans' Preference plus the 30% or more disabled hiring authority make the GS pipeline faster than commercial pivots for some applicants. The federal cyber and intelligence ecosystem is built around the same mission you supported in uniform, just under a different chain.

GS-0132 Intelligence Specialist

The 0132 series is the primary federal home for SIGINT and cyber-intel-trained veterans. NSA, DIA, Army G-2, INSCOM, and the broader IC hire 0132s at GS-9 through GS-13 entry points. With 35Q AIT plus operational experience, GS-9 is realistic out of the gate, GS-11 if you served as a senior collector or analyst with documented production. The 0132 qualification standard accepts specialized experience at the next-lower grade, so a 35Q E-5 with 4+ years of analytical work generally qualifies for GS-9.

GS-2210 Information Technology Management

The 2210 series is the IT management family that covers cybersecurity work outside of a pure intelligence role. Most cyber-focused 2210 positions sit in INFOSEC, Network Services, or Systems Analysis parentheticals (e.g., 2210/INFOSEC). Grade levels run GS-7 through GS-15. CompTIA Security+ or higher is normally required for cyber-coded 2210 positions under DoD 8140 — see the DoD 8140 certification guide for what each work role actually requires.

GS-1550 Computer Science

The 1550 series exists for positions that require formal computer science training (typically a bachelor's in CS or equivalent coursework). 35Qs with a CS degree from in-service education or post-service GI Bill use can qualify here. NSA, NIWC, and DARPA-adjacent labs hire 1550s for research-grade work that goes deeper than 2210 IT operational roles.

GS-0855 Electronics Engineering

The 0855 series fits 35Qs whose follow-on assignments included signals collection systems engineering, RF/SIGINT platform development, or cryptologic hardware work. NSA Engineering Directorate and INSCOM technical positions sit here. Requires an engineering degree or qualifying coursework (10 hours of calculus + foundational engineering classes per OPM standards).

GS-1515 Operations Research

For 35Qs who developed strong analytical methodology — quantitative reporting, modeling adversary behavior, statistical analysis of collected traffic — the 1515 series is a high-paying fit. NSA's research arm and Army Research Lab hire 1515s into modeling and analysis roles with grade ladders that hit GS-15 quickly.

GS-0301 Miscellaneous Administration and Program

The 0301 series catches the program management and operations roles that don't fit neatly into 0132 or 2210 — cyber program managers, intelligence program officers, mission management positions. Grade levels GS-9 through GS-15, with veterans' preference applying.

GS-0080 Security Administration

For 35Qs interested in industrial security, SCIF management, or security operations rather than collection, the 0080 series at DCSA, DoD components, and federal contractors is a clean fit. SCIF management experience documented from operational tours qualifies for GS-9 to GS-12.

Veterans' Preference and Special Hiring Authorities

5-point preference applies to honorable discharge with qualifying service. 10-point preference applies to disabled veterans (any rating) and Purple Heart recipients. The 30% or More Disabled Veteran hiring authority allows agencies to hire you non-competitively up to GS-11. Schedule A and the VRA appointment authority are additional pathways most 35Qs don't know exist. USAJobs filters for veterans-only postings let you skip the broad public competition entirely.

Federal resume formatting is its own skill. The federal resume builder handles GS-coded specialized experience formatting and KSA mapping. When you are ready to start the federal application, you can get started here.

Federal series and position matches

SeriesFederal job titleTypical gradesMatchExplore
GS-2210Information Technology ManagementGS-9, GS-11, GS-12, GS-135 of 5View details
GS-0132IntelligenceGS-11, GS-12, GS-135 of 5View details
GS-1515Operations ResearchGS-11, GS-12, GS-13, GS-144 of 5View details
GS-1550Computer ScienceGS-9, GS-11, GS-12, GS-134 of 5View details
GS-0855Electronics EngineeringGS-9, GS-11, GS-123 of 5View details
GS-0301Miscellaneous Administration and ProgramGS-11, GS-12, GS-133 of 5View details
GS-0080Security AdministrationGS-9, GS-11, GS-123 of 5View details

Federal resumes follow different rules. We know them.

Federal raters match your record against the announcement's specialized experience statement. BMR writes the federal format for any GS series above, with the hours per week and supervisor detail a rater looks for.

Free to start. Federal and private sector formats included.

Build My Federal Resume Free

Want to change careers entirely?

Not everyone stays in a related field. These paths run on the transferable half of the job: leadership, risk, logistics, planning.

Data Analyst$83,640 median · Technology / Analytics · O*NET 15-2051.00

SIGINT analysis develops the same statistical and pattern-recognition muscles commercial data analysts use daily. Less classification overhead, broader employer base.

Transfers: quantitative analysis, pattern recognition, SQL/scripting, reporting to stakeholders.

How to get there: Pick up SQL and a BI tool (Tableau or Power BI). Many 35Qs already use scripting and database query work in their daily collection workflow.

BLS OEWS May 2024 · 23% (Much faster than average)

Software Engineer (Security-focused)$132,270 median · Software / Tech · O*NET 15-1252.00

35Qs who built collection scripts and analytics tooling in service have a head start on security-focused dev work.

Transfers: scripting (Python, Bash), systems thinking, protocol analysis, automation.

How to get there: Build a portfolio (GitHub) showing automation, parsing, or detection tooling. Combine with AWS or Azure cert. Bootcamps and CS degrees both work.

BLS OEWS May 2024 · 17% (Much faster than average)

Cloud Security Engineer$135,000 median · Cloud / SaaS · O*NET 15-1212.00

Cloud-hosted IC environments mean many 35Qs already have working knowledge of AWS GovCloud, Azure Government, and similar architectures.

Transfers: network security, threat modeling, SIEM/EDR, cloud architecture.

How to get there: AWS Certified Security Specialty or Azure AZ-500. Combine with 1-2 years of hands-on commercial cloud experience to clear typical job requirements.

BLS OEWS May 2024 · 33% (Much faster than average)

Cybersecurity Consultant$105,000 median · Consulting · O*NET 13-1199.00

Briefing senior commanders on adversary cyber threats translates to briefing CISOs and CIOs on enterprise risk.

Transfers: client communication, risk assessment, technical writing, executive briefings.

How to get there: Big-4 consulting and cleared consulting firms (Deloitte, Booz Allen, Accenture Federal) hire transitioning cyber intel veterans into consultant roles regularly.

BLS OEWS May 2024 · 14% (Faster than average)

Information Security Manager$169,510 median · Cybersecurity Management · O*NET 11-3021.00

Senior 35Qs (E-7+) routinely managed multi-team operations, mission planning, and personnel readiness — direct overlap with civilian security management.

Transfers: team leadership, risk management, compliance, program governance.

How to get there: Combine military leadership experience with CISSP or CISM. Mid-career path; usually requires 8+ years of cyber experience plus management background.

BLS OEWS May 2024 · 17% (Much faster than average)

Technical Recruiter (Cleared Cyber)$67,440 median · Talent / HR · O*NET 13-1071.00

Some separating 35Qs leverage their network and industry knowledge to recruit other cleared cyber professionals. Reasonable salary plus commission.

Transfers: network of cleared professionals, technical screening, industry knowledge.

How to get there: Cleared staffing firms (Insight Global, ClearedJobs, ClearanceJobs employers) hire former cleared veterans into technical recruiter roles for cyber talent.

BLS OEWS May 2024 · 6% (Faster than average)

Operations Research Analyst$83,640 median · Defense / Analytics · O*NET 15-2031.00

Strong analytical methodology and familiarity with quantitative frameworks make 35Qs a clean fit for operations research roles, especially in defense analytics.

Transfers: quantitative modeling, statistical analysis, adversary behavior modeling.

How to get there: Federal GS-1515 series is an entry path. Master's preferred but not required when specialized experience is documented through military service.

BLS OEWS May 2024 · 23% (Much faster than average)

Pivoting industries does not mean starting from scratch.

The skills behind the specialty carry further than the specialty. BMR rewrites your bullets for any of the paths above without making it sound like you have never done the work.

Free to start. Try as many angles as you want.

Tailor My Resume to a New Career

Skills translation guide

If you are staying in the cleared cyber and SIGINT world, your terminology translates directly. NSA hiring managers know what cryptologic SIGINT collection means. Booz Allen recruiters working DoD cyber contracts know what target development is. This section is for 35Qs targeting commercial cybersecurity, threat intelligence, or analytical roles outside the IC, where SIGINT and cyber-collection vocabulary does not register.

Term Mappings

  • Cryptologic SIGINT collection → Network traffic analysis and signal intelligence gathering on adversary infrastructure
  • Target development → Adversary profiling, threat actor research, pattern-of-life analysis
  • Cyberspace intelligence reporting → Threat intelligence reporting, indicator-of-compromise documentation, structured analytic products
  • SIGINT geospatial analysis (SGA) → Signal-derived geolocation analysis, RF-based target tracking
  • All-source fusion → Multi-source intelligence correlation, cross-discipline analytic synthesis
  • Tradecraft → Analytical methodology, structured analysis techniques (ACH, key assumptions check)
  • Adversary TTPs → Threat actor tactics, techniques, and procedures (mapped to MITRE ATT&CK)
  • Cyber Mission Force (CMF) → Specialized cyber operations team supporting national defense missions
  • SCIF → Secure facility for handling classified information
  • JWICS / SIPRNet → Classified network systems (do not name in unclassified resumes)
  • Polygraph (CI / Full-scope) → Counterintelligence polygraph or expanded scope polygraph (cleared employer language)
  • RFI (Request for Information) → Customer intelligence requirement, analytic tasking

Resume Bullet Translation Examples

Before (military): "Performed cryptologic SIGINT collection and target development on priority adversary networks, producing 200+ intelligence reports supporting NSA and US Cyber Command operations."

After (commercial cyber threat intel): "Conducted advanced network traffic analysis and adversary profiling against priority threat actors, producing 200+ structured intelligence reports informing operational decisions for senior stakeholders. Methodology aligned with MITRE ATT&CK and Diamond Model frameworks."

Before (military): "Led 6-person SIGINT collection team conducting 24/7 cyberspace operations support across 3 mission sets, producing 40+ time-sensitive reports per month."

After (SOC / detection engineering): "Led 6-analyst team running 24/7 detection and response operations across 3 simultaneous mission lines. Produced 40+ time-sensitive incident reports per month, with average alert-to-report time under 90 minutes."

Before (military): "Fused SIGINT with all-source intelligence to develop adversary TTPs, briefing daily intelligence summary to O-6 commander and supporting joint operations planning."

After (commercial threat intel): "Synthesized multi-source intelligence to map adversary tactics, techniques, and procedures. Briefed daily threat assessment to senior leadership, informing strategic security decisions and incident response planning."

For broader military-to-civilian translation patterns, the 50 military terms civilian equivalents glossary covers terminology beyond the SIGINT/cyber lane. The military resume builder uses these translation patterns automatically when you select a target civilian role. Ready to start? Build your resume now.

Resume bullet examples

Before, in service

Performed cryptologic SIGINT collection against priority adversary networks producing 200+ reports.

After, on the resume

Conducted advanced network traffic analysis and adversary signal intelligence, producing 200+ structured intelligence reports informing operational decisions.

Before, in service

Led target development on 5 priority adversary cyber actors over 18 months.

After, on the resume

Led adversary profiling and threat actor research on 5 priority cyber threat groups over 18 months, mapping infrastructure and TTPs.

Before, in service

Authored 60+ cyberspace intelligence reports for higher headquarters consumption.

After, on the resume

Authored 60+ structured threat intelligence reports including IoC documentation and mitigation recommendations for senior stakeholders.

Before, in service

Performed all-source fusion of SIGINT, GEOINT, and HUMINT for analytic products.

After, on the resume

Synthesized multi-source intelligence including signals, geospatial, and human-derived inputs to produce integrated analytic products.

Before, in service

Tracked adversary TTPs across 3 priority threat groups during 24-month deployment.

After, on the resume

Tracked threat actor tactics, techniques, and procedures across 3 priority threat groups, mapping behavior to MITRE ATT&CK framework.

Before, in service

Served as Mission Manager for 6-person SIGINT team across 24/7 operations.

After, on the resume

Served as senior analyst and team lead for 6-analyst detection and response team operating 24/7.

Before, in service

Resolved 80+ RFIs from senior leadership over 12 months.

After, on the resume

Resolved 80+ customer intelligence requirements from senior leadership stakeholders over 12 months.

Before, in service

Applied SIGINT tradecraft including target development and traffic analysis.

After, on the resume

Applied structured analytic techniques and intelligence methodology including network analysis, link analysis, and behavioral profiling.

Before, in service

Held TS/SCI w/ CI Poly for 6 years.

After, on the resume

Holds active TS/SCI security clearance with counterintelligence polygraph; eligible for full-scope poly.

Before, in service

Assigned to Cyber Mission Force Combat Mission Team supporting USCYBERCOM operations.

After, on the resume

Assigned to specialized cyber operations team supporting national cyber defense missions in coordination with senior commands.

Get bullets like these written from your own record.

BMR turns your 35Q duties and accomplishments into civilian bullets aimed at the job you are applying for. No manual translation.

Free to start. Tailored to each posting.

Generate My Resume Bullets

Certifications by career path

Which ones you need depends on where you are headed.

Cloud Computing

AWS Certified Security SpecialtyAmazon Web Services

RecommendedCost $300 examTime 2-3 months prepGI Bill eligibleCloud security depth for 35Qs targeting commercial or hybrid-cloud roles.

Azure Security Engineer (AZ-500)Microsoft

RecommendedCost $165 examTime 2-3 months prepGI Bill eligibleMicrosoft cloud security cred. Fits 35Qs working in Microsoft-centric DoD environments.

Cybersecurity

CompTIA Security+CompTIA

RequiredCost $400 examTime 4-8 weeksGI Bill eligibleDoD 8140 baseline for most cyber-coded positions. Subsidized through Ed Centers and FedVTE.

GIAC GCIH (Certified Incident Handler)SANS / GIAC

Highly RecommendedCost $8,000+ (course + cert)Time 6-month prepGI Bill eligibleStandard cred for incident response and SOC analyst senior roles.

GIAC GCFA (Forensic Analyst)SANS / GIAC

RecommendedCost $8,000+ (course + cert)Time 6-month prepGI Bill eligibleForensics and incident investigation. Strong fit for 35Qs pivoting to DFIR work.

CompTIA CySA+CompTIA

RecommendedCost $400 examTime 4-8 weeksGI Bill eligibleCybersecurity Analyst cert focused on threat detection and behavioral analytics.

CISSP(ISC)2

Senior CareerCost $750 exam + maintenanceTime 3-6 months prepGI Bill eligibleSenior security cred. Most 35Qs hit the 5-year experience requirement post-separation; can hold Associate of (ISC)2 status until then.

OSCP (Offensive Security Certified Professional)Offensive Security

RecommendedCost $1,600 (course + exam)Time 3-6 monthsGI Bill eligibleStandard credential for penetration testing and red team roles.

Data Analytics

Splunk Certified Power User / AdminSplunk

RecommendedCost $130-$130/examTime 1-2 monthsGI Bill eligibleMajor SIEM platform across cleared SOCs. Hands-on experience translates directly.

Defense Contracting

Certified Defense Industrial Security SpecialistDCSA / NCMS

RecommendedCost VariesTime 3-6 monthsIndustrial security and SCIF management cred for 35Qs targeting GS-0080 or facility security roles.

Federal Employment

PathFinder / NSA Cyber PathwaysNSA

Highly RecommendedCost FreeTime VariesNSA-sponsored direct hire and skills-based pathways for transitioning service members.

Intelligence & Analysis

GIAC GCTI (Cyber Threat Intelligence)SANS / GIAC

Highly RecommendedCost $8,000+ (course + cert)Time 6-month prepGI Bill eligiblePremier cyber threat intel cert. SANS courses are GI Bill eligible at most chapters.

IT & Networking

CCNA Cyber Ops / CyberOps AssociateCisco

RecommendedCost $300 examTime 2-4 monthsGI Bill eligibleNetwork-side cyber operations cred. Useful for 35Qs targeting SOC analyst roles.

CompTIA Network+CompTIA

FoundationCost $370 examTime 4-6 weeksGI Bill eligibleNetworking foundation. Often a prerequisite for higher-level cyber certs.

Project Management

PMP (Project Management Professional)PMI

RecommendedCost $405-$555 examTime 3-6 months prepGI Bill eligibleFor 35Qs pivoting into cyber program management or federal 0301/0343 roles.

Got a cert? Do not bury it.

Placement decides whether a screener ever sees it. BMR knows where each one ranks, what to call it, and how to frame it.

Free to start. Built around your real certs and clearance.

Build My Resume the Right Way

Transition resources

For Veterans Staying in Cleared Cyber/SIGINT

If your plan is NSA, US Cyber Command civilian, or cleared contractor cyber work, your runway is short and the demand is real. Focus on three things: (1) keep your clearance and polygraph current through the transition, (2) document specialized experience in language that maps to GS qualification standards or contract labor categories, (3) work the personal network you built during your service tours.

  • USAJobs — set saved searches for 0132, 2210, 1550, and 1515 series in the IC corridor (Maryland, Virginia, Colorado, Texas, Hawaii). Filter for veteran-only postings to skip public competition.
  • NSA Civilian Careers — direct hire programs for transitioning service members. The Stokes program and Cyber Summer Program are entry points if you are willing to relocate to Fort Meade.
  • SkillBridge — internships at Booz Allen, Leidos, Peraton, SAIC, and CACI in the cleared cyber space. The list of authorized partners changes; check the official DoD SkillBridge site before committing.
  • Defense contractor military hiring programs — the cleared contractor ecosystem (Booz Allen, Leidos, Peraton, SAIC, CACI, Mantech, Amentum) operates dedicated military recruiting pipelines. The defense contractor jobs guide covers how the clearance market actually works.
  • SFL-TAP — required transition assistance program. The SFL-TAP guide walks through what to actually do during your TAP window.

For Veterans Targeting Careers Outside Cleared Cyber/SIGINT

Some 35Qs leave the IC entirely after their commitment ends. Burnout from shift work, distance from family, or a desire to operate without classification handling drives the move. Commercial cybersecurity, data analytics, and software engineering are the realistic adjacent paths.

  • Commercial cybersecurity — the GIAC certification family (GCIH, GCFA, GREM, GCTI) is the credential ladder for commercial detection engineering, incident response, and threat intel roles. SANS courses are GI Bill eligible at most chapters. CompTIA Security+, CySA+, and CASP+ cover the foundation.
  • Cloud and data engineering — AWS, Azure, and GCP certifications open commercial cloud-security roles. Many 35Qs already worked in cloud-hosted intel environments and the credential just formalizes what you already know.
  • American Corporate Partners (ACP) — free 1:1 mentorship with executives in commercial cybersecurity and tech. Useful for 35Qs unsure how to position themselves outside the IC.
  • FedVTE — free DoD-funded cybersecurity training for veterans. Strong fit for closing gaps in commercial cyber knowledge before applying to non-cleared roles.

Related MOS Pages

BMR Tools

Your 30, 60, 90-day transition plan

Most people do this backwards: wait for terminal leave, then panic. This is the sequence that works. Already out? Same plan, day one is today.

Days 0 to 30

Set the foundation

  • Pull your DD-214 (request it from milConnect if you are already separated)
  • List your top three civilian roles and your top three GS series
  • Build your tailored 35Q resume, free
  • Write one strong LinkedIn headline, not "veteran seeking opportunities"
  • Gather your evals and performance reports for the accomplishments
Build my resume free

Days 30 to 60

Apply with intent

  • Apply to five to ten jobs a week, quality over volume
  • Tailor every resume to the announcement (BMR does this part for you)
  • Connect with five people a week on LinkedIn, not a spray
  • Set up a USAJOBS profile and a saved search for your GS series
  • Say your bullets out loud to a civilian friend and fix what they do not follow
Tailor my next resume

Days 60 to 90

Close the offer

  • Track every application: date, status, contact, notes
  • Follow up seven to ten days after each one
  • Prep behavioral interviews with the STAR method
  • Negotiate. The BLS median is your floor, not the offer
  • Keep applying after the first offer. Options are the leverage
Track my applications

Questions about 35Q

What is the civilian salary for an Army 35Q with TS/SCI?

BLS OEWS May 2024 reports a median of $124,910 for Information Security Analysts (15-1212.00), with the top 10% above $182,000. Cleared cyber threat intelligence roles requiring TS/SCI commonly pay $140K-$180K base plus clearance premium and bonuses. Compensation varies significantly by location — the Fort Meade and Northern Virginia corridors pay more than non-cleared geographies. Compensation also varies by polygraph status (CI poly, full-scope poly), which can add $10K-$30K to base.

What civilian jobs are best for separating 35Qs?

The strongest direct matches are Cyber Threat Intelligence Analyst, Information Security Analyst, SOC Analyst, and Detection Engineer at cleared employers like Booz Allen Hamilton, Leidos, Peraton, SAIC, CACI, Mandiant, and CrowdStrike. Federal civilian roles in the GS-0132 (Intelligence) and GS-2210 (IT Management) series at NSA, US Cyber Command, DIA, and Army G-2 are also strong fits. Pivots into commercial cybersecurity, red team operations, or cloud security are all viable with appropriate certifications.

How valuable is my TS/SCI clearance after I separate?

Highly valuable. Active TS/SCI with poly is one of the strongest negotiating levers in the cleared job market because clearances take 12-18 months to adjudicate from a cold start. Cleared employers cannot wait that long and pay premiums to candidates who already hold them. Your clearance stays active for 24 months after separation if you transfer to a sponsoring employer within that window — after that, it must be reinvestigated.

Can I work commercial cyber without a clearance?

Yes. Commercial cybersecurity at companies like CrowdStrike, Mandiant (Google Cloud), Palo Alto Networks, and most MSSPs hires non-cleared analysts. The pay is competitive but typically lower than cleared roles for equivalent seniority. If you are leaving the IC entirely, certifications matter more in the commercial space — CompTIA Security+, GIAC GCIH/GCTI/GCFA, and offensive certs like OSCP carry significant weight.

What federal GS series should a 35Q apply for?

Primary targets: GS-0132 Intelligence Specialist (NSA, DIA, Army G-2), GS-2210 Information Technology Management (cyber-coded positions), GS-1550 Computer Science (research roles), GS-0855 Electronics Engineering (signals systems), GS-1515 Operations Research (analytical methodology), GS-0301 Miscellaneous Administration (program management), and GS-0080 Security Administration (industrial security). With 35Q AIT and operational experience, GS-9 entry is realistic; GS-11 with strong production and senior collector roles.

Do I need a degree to land cleared cyber jobs?

For commercial cybersecurity and most cleared contractor roles, a degree is preferred but not required if you have strong certifications and operational experience. For federal civilian positions, degree requirements depend on the GS series. The 0132 and 2210 series do not require a specific degree; 1550 (Computer Science) and 0855 (Electronics Engineering) require relevant coursework. Use your post-9/11 GI Bill if you do not have a degree yet.

How do I describe classified work on my resume?

Stay above the classification line: describe the function, not the target. Talk about analytical methodology, frameworks (MITRE ATT&CK, Diamond Model, Cyber Kill Chain), tools by category (SIEM, traffic analysis platforms), report volume and audience, and impact in unclassified terms. Never name specific systems, targets, technical sources, or methods. Have your security manager review the resume before you send it externally — most commands offer this.

What certifications should I get during my last year in service?

Prioritize CompTIA Security+ (DoD 8140 baseline for most cyber-coded positions), then GIAC GCIH or GCTI for threat intel and incident handling work. CISSP is the senior-level credential for IT security management — most 35Qs do not hit the 5-year experience requirement for full CISSP until after separation, but Associate of (ISC)2 status counts. Many bases offer free or subsidized cert prep through Education Centers or via FedVTE.

How does Veterans Preference work for cleared federal jobs?

5-point preference applies to honorable discharge with qualifying service; 10-point preference applies to disabled veterans (any rating) and Purple Heart recipients. The 30% or More Disabled Veteran hiring authority allows agencies to hire you non-competitively up to GS-11. NSA, DIA, and other IC components apply Veterans Preference in line with their own merit hiring policies. Preference matters but does not override mission qualifications. USAJobs lets you filter for veteran-only postings.

What is the geography of cleared cyber work?

Cleared cyber concentrates around: Fort Meade/Annapolis Junction MD (NSA), Northern Virginia (CIA, DIA, ODNI, contractor HQs), San Antonio TX (NSA Texas, JBSA), Augusta GA (Fort Eisenhower, Army Cyber Center of Excellence), Hawaii (NSA Hawaii), and Colorado Springs (US Space Command, Cheyenne Mountain). Remote-eligible cleared work exists but is limited by SCIF requirements. If you are tied to a non-cleared geography, expect to either commute to a SCIF or pivot to commercial cyber for that location.

Should I stay 35Q on the civilian side or pivot to all-source intel?

Both paths are viable. Staying in cyber/SIGINT keeps you closest to the work you already do and the network you built. The salary ceiling is high and demand is structural. Pivoting to all-source intelligence (35F-style work) widens your applicable employer base and removes some of the operational shift-work pressure. The decision usually comes down to whether you want to keep the technical depth or move toward broader analytical and policy work.

Turn your 35Q Cryptologic Cyberspace Intelligence Collector/Analyst experience into a resume that gets callbacks

Stop rewriting from scratch every time you apply. BMR turns your military experience into civilian and federal resumes, tailored to each job.

2

Tailored resumes

Rewritten for each job posting

2

Cover letters

Matched to the role

LinkedIn optimization

Profile rewrite for civilian recruiters

Elevator pitch generator

For interviews and networking

2

Company research reports

Know who you are applying to

Job tracker

Every application in one place

Start My Free ResumeFree for every veteran. Built by a Navy Diver veteran, 71,892 resumes built for the military community.