A Army story from the same road

“I am still getting compliments on my resume. Still getting interviews left and right, and now I have to say no. Very grateful to have so many options suddenly.”
Taranjeet · Sergeant (E-5) · Army · Program Management
Home / Military to civilian jobs / Army / 35Q
That is Army MOS 35Q. Civilian jobs, federal paths, and how the work reads on a resume.
What is in this guide
What the translation looks like
How it reads in service
Performed cryptologic SIGINT collection against priority adversary networks producing 200+ reports.
How a hiring manager reads it
Conducted advanced network traffic analysis and adversary signal intelligence, producing 200+ structured intelligence reports informing operational decisions.
Roles this background maps to
Median pay, BLS OEWS May 2024
Build a resume for a real jobYou pick the job. We write it from your 35Q experience. Free to start.
Brad TachiNavy Diver · BMR founder
After the Navy he was hired into six federal career fields and tech sales, and sat on federal hiring panels along the way. The last two years went into rebuilding all of it into BMR, tuned for how resumes get screened today. 71,892 resumes built so far.
One page, built in our template, with the military experience translated into the civilian terms hiring managers and screening software read. Use it as a reference for your own. Leave an email and the download link comes to you.
Free. Occasional job-search tips come with it. Unsubscribe anytime.
Army 35Qs sit at the intersection of signals intelligence collection and cyberspace operations. The MOS exists because modern adversaries do not separate radio frequency and IP traffic the way the older 35-series job tree did, so the Army built one role to handle target development, network analysis, cyber threat reporting, and integrated SIGINT/cyber collection inside the same workflow. If you are reading this, you already know that "cyberspace intelligence collector/analyst" is shorthand for a deep stack of TTPs, tooling, and reporting workflows you cannot fully describe on a resume.
The pipeline is long and selective. You started with 10 weeks of Basic Combat Training, then moved to the U.S. Army Intelligence Center of Excellence at Goodfellow AFB in San Angelo, Texas for roughly 30+ weeks of initial training, followed by additional cyber-focused instruction depending on follow-on assignment. Expect to come out the other end with TS/SCI eligibility, an active polygraph in many cases, hands-on experience with cryptologic SIGINT systems, and exposure to cyberspace operations alongside NSA elements, Cyber Mission Force teams, and joint cryptologic activities.
Day to day, 35Qs do the unglamorous parts of cyber intelligence: target development on adversary networks, traffic analysis, malware and TTP reporting, fusion of SIGINT with all-source intel, and supporting offensive and defensive cyber operations. That work translates directly into the cleared private sector and into federal civilian positions at 35N SIGINT analyst and 17C Cyber Operations Specialist destinations, but the 35Q angle skews more toward NSA, US Cyber Command, and DoD cyber contractors than the broader analyst tracks. The challenge is reframing 35Q-specific tooling and tradecraft into civilian language that does not leak classified specifics. The military-to-civilian career crosswalk is a fast way to scope salary ranges and federal series before you sit down to write anything.
For deeper context on how the broader 35-series translates, the military intelligence 35-series civilian careers guide covers the cross-MOS overlap with NSA, DIA, and the cleared contractor space.
BMR has built more than 55,000 resumes across every MOS, and 35Qs sit at one of the most undersupplied corners of the cleared cyber market. The combination of credentialed SIGINT collection, cyberspace intelligence training, and active TS/SCI is exactly the package NSA, US Cyber Command, and DoD cyber contractors compete for. The challenge is reframing 35Q-specific tooling and tradecraft into civilian language without leaking what cannot be discussed. — Brad Tachi, Navy Diver veteran & BMR founder
The number that decides most of this: how does civilian pay compare to what the paycheck looks like now?
Army mid-career
$58K to $82K
E-5 to E-7 total comp: base plus BAH, BAS and the tax advantage.
Civilian Cryptologic Cyberspace Intelligence Collector/Analyst
$110K to $140K
BLS median across the direct-match civilian roles on this page.
Federal, GS-9 to GS-13
$58K to $120K
7 matching GS series, plus locality pay and step increases.
About 82% higher on average
Civilian roles for Cryptologic Cyberspace Intelligence Collector/Analysts pay about $57K more than mid-career enlisted total comp.
Military comp is approximate and moves with location and dependents. Civilian is the BLS median. Federal includes locality pay. The real number depends on duty station, family status, GS step and overtime.
Civilian demand for cleared cyber intelligence backgrounds is structural, not cyclical. The cleared talent pool stays small because clearances take 12-18 months to adjudicate from a cold start, and employers who already have cleared contracts cannot wait that long. A separating 35Q with active TS/SCI and a polygraph walks into that market with leverage most civilian candidates never have.
BLS OEWS May 2024 reports a median wage of $124,910 for Information Security Analysts (15-1212.00), with the top 10% above $182,000. Demand is projected to grow 33% through 2033 (BLS Employment Projections), one of the fastest growth rates BLS tracks. 35Qs land in this category at threat intelligence analyst, SOC analyst, and detection engineering roles. Companies running cleared SOCs (NSA contracts, DoD cyber contracts, intelligence community support) actively recruit for SIGINT-trained analysts because the analytical workflow is the same as commercial threat hunting, just with different sensors.
Threat intel as a discipline is the closest civilian analog to cyberspace SIGINT collection. Mandiant (now part of Google Cloud), CrowdStrike, Recorded Future, and the threat intel arms of large MSSPs all hire 35Qs into roles that map their SIGINT target development experience to adversary tracking and attribution. BLS rolls these into the Information Security Analyst category, but compensation skews higher when clearance and IC experience are required (commonly $140K-$180K base for cleared CTI roles).
Penetration Testers fall under the same BLS occupation (15-1212.00) but represent a different pivot. Some 35Qs cross over into red team work, especially those who came out of the cyberspace operations side of the house. Cleared red team contracts at Booz Allen, Leidos, and Mandiant frequently require TS/SCI plus offensive cyber experience.
BLS reports a median of $129,840 for Computer Network Architects (15-1241.00). 35Qs with strong network analysis backgrounds shift into network design and architecture, particularly for cleared environments where SCIF-grade network design is a specialized discipline.
BLS does not break out "intelligence analyst" separately, so the data sits under Miscellaneous Social Scientists (19-3099) or Management Analysts (13-1111) depending on the role. For all-source intel analyst roles in the IC and contractor space, the salary band is $90K-$140K depending on clearance and specialty. 35Qs who want the cyber sensor work to recede in favor of broader analytical roles often pivot into all-source intel — see the 35F Intelligence Analyst transition page for adjacent paths.
Your closest counterparts in other services include Navy CTNs, Air Force 1B4X1 Cyber Warfare Operations, and Marine 0651 Cyber Network Operators. They compete for the same civilian roles, so understanding what they bring to the market helps you position yourself.
Geography matters more than most veterans expect. The cleared cyber market concentrates around Fort Meade/Annapolis Junction, Northern Virginia, San Antonio, Hawaii, Augusta GA (Fort Eisenhower), and Colorado Springs. Remote-eligible cleared work exists but is limited because the work is performed inside SCIFs. If you are open to relocating to a corridor with cleared facilities, the salary numbers above are realistic. If you are tied to a non-cleared geography, expect to take a pay cut to enter a commercial cyber role and then rebuild compensation through certifications. The military-to-civilian salary guide walks through how clearance and location modify base compensation in 2026.
When you are ready to put the resume together, the military resume builder handles the SIGINT-to-civilian translation. For high-intent next steps, build your resume now.
| Civilian job title | Industry | BLS median salary | Outlook | Match |
|---|---|---|---|---|
| Cyber Threat Intelligence AnalystO*NET 15-1212.00 | Cleared Cybersecurity | $140,000 | 33% (Much faster than average) | strong |
| Information Security AnalystO*NET 15-1212.00 | Cybersecurity | $124,910 | 33% (Much faster than average) | strong |
| SOC Analyst (Cleared)O*NET 15-1212.00 | Cleared Cybersecurity | $110,000 | 33% (Much faster than average) | strong |
| Penetration Tester / Red Team OperatorO*NET 15-1212.00 | Cybersecurity | $132,000 | 33% (Much faster than average) | moderate |
| Computer Network ArchitectO*NET 15-1241.00 | IT Infrastructure | $129,840 | 13% (Faster than average) | moderate |
| Intelligence Analyst (All-Source)O*NET 13-1199.00 | Defense / Intelligence | $115,000 | Steady (BLS does not publish this category separately) | strong |
| Detection EngineerO*NET 15-1299.00 | Cybersecurity | $135,000 | 33% (Much faster than average) | strong |
| Cybersecurity EngineerO*NET 15-1212.00 | Cybersecurity | $133,000 | 33% (Much faster than average) | moderate |
Top employer for cleared cyber intel veterans. SkillBridge partner; runs DoD cyber and IC contracts at Fort Meade, NoVA, San Antonio.
NSA, US Cyber Command, and IC cyber contract holder. Direct hires for SIGINT-trained analysts.
Major IC and DoD cyber contractor (formed from former Northrop Grumman federal IT and ManTech). Strong fit for cyber intel veterans.
NSA and DIA cyber contracts. Programs for transitioning service members with cleared cyber backgrounds.
Heavy IC contract presence; cleared cyber, SIGINT, and intel analyst pipelines.
Cyber and SIGINT systems integration work; SkillBridge partner.
Major cyber and SIGINT systems contractor with cleared engineering and analyst roles.
Cleared cyber and intelligence systems contracts; intel analyst pipelines.
SIGINT systems builder; strong fit for 35Qs with hardware/RF exposure.
Cyber Intel Group runs offensive and defensive cyber contracts; cleared analyst and operator roles.
Largest IC IT services contractor; significant cleared cyber and SIGINT presence at Fort Meade and NoVA.
Threat intel and incident response leader. Recruits cleared and non-cleared cyber intel analysts.
Threat intel (Falcon OverWatch, Counter Adversary Operations) hires SIGINT-trained analysts.
Cleared services contractor across DoD and IC including cyber intelligence support.
BMR rewrites your 35Q experience for any of the roles above, in the language the people reading actually scan for.
Free to start. 2 tailored resumes included.
Upload it and get a number in about a minute, plus the 35Q lines a civilian hiring manager will not follow. No account. Sign up and BMR writes the fix.
Free. Your file is never stored.

“I am still getting compliments on my resume. Still getting interviews left and right, and now I have to say no. Very grateful to have so many options suddenly.”
Taranjeet · Sergeant (E-5) · Army · Program Management
Federal civilian work is where many 35Qs land first because the security clearance carries forward without re-adjudication, the work is genuinely similar to active duty, and Veterans' Preference plus the 30% or more disabled hiring authority make the GS pipeline faster than commercial pivots for some applicants. The federal cyber and intelligence ecosystem is built around the same mission you supported in uniform, just under a different chain.
The 0132 series is the primary federal home for SIGINT and cyber-intel-trained veterans. NSA, DIA, Army G-2, INSCOM, and the broader IC hire 0132s at GS-9 through GS-13 entry points. With 35Q AIT plus operational experience, GS-9 is realistic out of the gate, GS-11 if you served as a senior collector or analyst with documented production. The 0132 qualification standard accepts specialized experience at the next-lower grade, so a 35Q E-5 with 4+ years of analytical work generally qualifies for GS-9.
The 2210 series is the IT management family that covers cybersecurity work outside of a pure intelligence role. Most cyber-focused 2210 positions sit in INFOSEC, Network Services, or Systems Analysis parentheticals (e.g., 2210/INFOSEC). Grade levels run GS-7 through GS-15. CompTIA Security+ or higher is normally required for cyber-coded 2210 positions under DoD 8140 — see the DoD 8140 certification guide for what each work role actually requires.
The 1550 series exists for positions that require formal computer science training (typically a bachelor's in CS or equivalent coursework). 35Qs with a CS degree from in-service education or post-service GI Bill use can qualify here. NSA, NIWC, and DARPA-adjacent labs hire 1550s for research-grade work that goes deeper than 2210 IT operational roles.
The 0855 series fits 35Qs whose follow-on assignments included signals collection systems engineering, RF/SIGINT platform development, or cryptologic hardware work. NSA Engineering Directorate and INSCOM technical positions sit here. Requires an engineering degree or qualifying coursework (10 hours of calculus + foundational engineering classes per OPM standards).
For 35Qs who developed strong analytical methodology — quantitative reporting, modeling adversary behavior, statistical analysis of collected traffic — the 1515 series is a high-paying fit. NSA's research arm and Army Research Lab hire 1515s into modeling and analysis roles with grade ladders that hit GS-15 quickly.
The 0301 series catches the program management and operations roles that don't fit neatly into 0132 or 2210 — cyber program managers, intelligence program officers, mission management positions. Grade levels GS-9 through GS-15, with veterans' preference applying.
For 35Qs interested in industrial security, SCIF management, or security operations rather than collection, the 0080 series at DCSA, DoD components, and federal contractors is a clean fit. SCIF management experience documented from operational tours qualifies for GS-9 to GS-12.
5-point preference applies to honorable discharge with qualifying service. 10-point preference applies to disabled veterans (any rating) and Purple Heart recipients. The 30% or More Disabled Veteran hiring authority allows agencies to hire you non-competitively up to GS-11. Schedule A and the VRA appointment authority are additional pathways most 35Qs don't know exist. USAJobs filters for veterans-only postings let you skip the broad public competition entirely.
Federal resume formatting is its own skill. The federal resume builder handles GS-coded specialized experience formatting and KSA mapping. When you are ready to start the federal application, you can get started here.
| Series | Federal job title | Typical grades | Match | Explore |
|---|---|---|---|---|
| GS-2210 | Information Technology Management | GS-9, GS-11, GS-12, GS-13 | 5 of 5 | View details |
| GS-0132 | Intelligence | GS-11, GS-12, GS-13 | 5 of 5 | View details |
| GS-1515 | Operations Research | GS-11, GS-12, GS-13, GS-14 | 4 of 5 | View details |
| GS-1550 | Computer Science | GS-9, GS-11, GS-12, GS-13 | 4 of 5 | View details |
| GS-0855 | Electronics Engineering | GS-9, GS-11, GS-12 | 3 of 5 | View details |
| GS-0301 | Miscellaneous Administration and Program | GS-11, GS-12, GS-13 | 3 of 5 | View details |
| GS-0080 | Security Administration | GS-9, GS-11, GS-12 | 3 of 5 | View details |
Federal raters match your record against the announcement's specialized experience statement. BMR writes the federal format for any GS series above, with the hours per week and supervisor detail a rater looks for.
Free to start. Federal and private sector formats included.
Not everyone stays in a related field. These paths run on the transferable half of the job: leadership, risk, logistics, planning.
SIGINT analysis develops the same statistical and pattern-recognition muscles commercial data analysts use daily. Less classification overhead, broader employer base.
Transfers: quantitative analysis, pattern recognition, SQL/scripting, reporting to stakeholders.
How to get there: Pick up SQL and a BI tool (Tableau or Power BI). Many 35Qs already use scripting and database query work in their daily collection workflow.
BLS OEWS May 2024 · 23% (Much faster than average)
35Qs who built collection scripts and analytics tooling in service have a head start on security-focused dev work.
Transfers: scripting (Python, Bash), systems thinking, protocol analysis, automation.
How to get there: Build a portfolio (GitHub) showing automation, parsing, or detection tooling. Combine with AWS or Azure cert. Bootcamps and CS degrees both work.
BLS OEWS May 2024 · 17% (Much faster than average)
Cloud-hosted IC environments mean many 35Qs already have working knowledge of AWS GovCloud, Azure Government, and similar architectures.
Transfers: network security, threat modeling, SIEM/EDR, cloud architecture.
How to get there: AWS Certified Security Specialty or Azure AZ-500. Combine with 1-2 years of hands-on commercial cloud experience to clear typical job requirements.
BLS OEWS May 2024 · 33% (Much faster than average)
Briefing senior commanders on adversary cyber threats translates to briefing CISOs and CIOs on enterprise risk.
Transfers: client communication, risk assessment, technical writing, executive briefings.
How to get there: Big-4 consulting and cleared consulting firms (Deloitte, Booz Allen, Accenture Federal) hire transitioning cyber intel veterans into consultant roles regularly.
BLS OEWS May 2024 · 14% (Faster than average)
Senior 35Qs (E-7+) routinely managed multi-team operations, mission planning, and personnel readiness — direct overlap with civilian security management.
Transfers: team leadership, risk management, compliance, program governance.
How to get there: Combine military leadership experience with CISSP or CISM. Mid-career path; usually requires 8+ years of cyber experience plus management background.
BLS OEWS May 2024 · 17% (Much faster than average)
Some separating 35Qs leverage their network and industry knowledge to recruit other cleared cyber professionals. Reasonable salary plus commission.
Transfers: network of cleared professionals, technical screening, industry knowledge.
How to get there: Cleared staffing firms (Insight Global, ClearedJobs, ClearanceJobs employers) hire former cleared veterans into technical recruiter roles for cyber talent.
BLS OEWS May 2024 · 6% (Faster than average)
Strong analytical methodology and familiarity with quantitative frameworks make 35Qs a clean fit for operations research roles, especially in defense analytics.
Transfers: quantitative modeling, statistical analysis, adversary behavior modeling.
How to get there: Federal GS-1515 series is an entry path. Master's preferred but not required when specialized experience is documented through military service.
BLS OEWS May 2024 · 23% (Much faster than average)
The skills behind the specialty carry further than the specialty. BMR rewrites your bullets for any of the paths above without making it sound like you have never done the work.
Free to start. Try as many angles as you want.
If you are staying in the cleared cyber and SIGINT world, your terminology translates directly. NSA hiring managers know what cryptologic SIGINT collection means. Booz Allen recruiters working DoD cyber contracts know what target development is. This section is for 35Qs targeting commercial cybersecurity, threat intelligence, or analytical roles outside the IC, where SIGINT and cyber-collection vocabulary does not register.
Before (military): "Performed cryptologic SIGINT collection and target development on priority adversary networks, producing 200+ intelligence reports supporting NSA and US Cyber Command operations."
After (commercial cyber threat intel): "Conducted advanced network traffic analysis and adversary profiling against priority threat actors, producing 200+ structured intelligence reports informing operational decisions for senior stakeholders. Methodology aligned with MITRE ATT&CK and Diamond Model frameworks."
Before (military): "Led 6-person SIGINT collection team conducting 24/7 cyberspace operations support across 3 mission sets, producing 40+ time-sensitive reports per month."
After (SOC / detection engineering): "Led 6-analyst team running 24/7 detection and response operations across 3 simultaneous mission lines. Produced 40+ time-sensitive incident reports per month, with average alert-to-report time under 90 minutes."
Before (military): "Fused SIGINT with all-source intelligence to develop adversary TTPs, briefing daily intelligence summary to O-6 commander and supporting joint operations planning."
After (commercial threat intel): "Synthesized multi-source intelligence to map adversary tactics, techniques, and procedures. Briefed daily threat assessment to senior leadership, informing strategic security decisions and incident response planning."
For broader military-to-civilian translation patterns, the 50 military terms civilian equivalents glossary covers terminology beyond the SIGINT/cyber lane. The military resume builder uses these translation patterns automatically when you select a target civilian role. Ready to start? Build your resume now.
Before, in service
Performed cryptologic SIGINT collection against priority adversary networks producing 200+ reports.
After, on the resume
Conducted advanced network traffic analysis and adversary signal intelligence, producing 200+ structured intelligence reports informing operational decisions.
Before, in service
Led target development on 5 priority adversary cyber actors over 18 months.
After, on the resume
Led adversary profiling and threat actor research on 5 priority cyber threat groups over 18 months, mapping infrastructure and TTPs.
Before, in service
Authored 60+ cyberspace intelligence reports for higher headquarters consumption.
After, on the resume
Authored 60+ structured threat intelligence reports including IoC documentation and mitigation recommendations for senior stakeholders.
Before, in service
Performed all-source fusion of SIGINT, GEOINT, and HUMINT for analytic products.
After, on the resume
Synthesized multi-source intelligence including signals, geospatial, and human-derived inputs to produce integrated analytic products.
Before, in service
Tracked adversary TTPs across 3 priority threat groups during 24-month deployment.
After, on the resume
Tracked threat actor tactics, techniques, and procedures across 3 priority threat groups, mapping behavior to MITRE ATT&CK framework.
Before, in service
Served as Mission Manager for 6-person SIGINT team across 24/7 operations.
After, on the resume
Served as senior analyst and team lead for 6-analyst detection and response team operating 24/7.
Before, in service
Resolved 80+ RFIs from senior leadership over 12 months.
After, on the resume
Resolved 80+ customer intelligence requirements from senior leadership stakeholders over 12 months.
Before, in service
Applied SIGINT tradecraft including target development and traffic analysis.
After, on the resume
Applied structured analytic techniques and intelligence methodology including network analysis, link analysis, and behavioral profiling.
Before, in service
Held TS/SCI w/ CI Poly for 6 years.
After, on the resume
Holds active TS/SCI security clearance with counterintelligence polygraph; eligible for full-scope poly.
Before, in service
Assigned to Cyber Mission Force Combat Mission Team supporting USCYBERCOM operations.
After, on the resume
Assigned to specialized cyber operations team supporting national cyber defense missions in coordination with senior commands.
BMR turns your 35Q duties and accomplishments into civilian bullets aimed at the job you are applying for. No manual translation.
Free to start. Tailored to each posting.
Which ones you need depends on where you are headed.
RecommendedCost $300 examTime 2-3 months prepGI Bill eligibleCloud security depth for 35Qs targeting commercial or hybrid-cloud roles.
RecommendedCost $165 examTime 2-3 months prepGI Bill eligibleMicrosoft cloud security cred. Fits 35Qs working in Microsoft-centric DoD environments.
RequiredCost $400 examTime 4-8 weeksGI Bill eligibleDoD 8140 baseline for most cyber-coded positions. Subsidized through Ed Centers and FedVTE.
Highly RecommendedCost $8,000+ (course + cert)Time 6-month prepGI Bill eligibleStandard cred for incident response and SOC analyst senior roles.
RecommendedCost $8,000+ (course + cert)Time 6-month prepGI Bill eligibleForensics and incident investigation. Strong fit for 35Qs pivoting to DFIR work.
RecommendedCost $400 examTime 4-8 weeksGI Bill eligibleCybersecurity Analyst cert focused on threat detection and behavioral analytics.
Senior CareerCost $750 exam + maintenanceTime 3-6 months prepGI Bill eligibleSenior security cred. Most 35Qs hit the 5-year experience requirement post-separation; can hold Associate of (ISC)2 status until then.
RecommendedCost $1,600 (course + exam)Time 3-6 monthsGI Bill eligibleStandard credential for penetration testing and red team roles.
RecommendedCost $130-$130/examTime 1-2 monthsGI Bill eligibleMajor SIEM platform across cleared SOCs. Hands-on experience translates directly.
RecommendedCost VariesTime 3-6 monthsIndustrial security and SCIF management cred for 35Qs targeting GS-0080 or facility security roles.
Highly RecommendedCost FreeTime VariesNSA-sponsored direct hire and skills-based pathways for transitioning service members.
Highly RecommendedCost $8,000+ (course + cert)Time 6-month prepGI Bill eligiblePremier cyber threat intel cert. SANS courses are GI Bill eligible at most chapters.
RecommendedCost $300 examTime 2-4 monthsGI Bill eligibleNetwork-side cyber operations cred. Useful for 35Qs targeting SOC analyst roles.
FoundationCost $370 examTime 4-6 weeksGI Bill eligibleNetworking foundation. Often a prerequisite for higher-level cyber certs.
RecommendedCost $405-$555 examTime 3-6 months prepGI Bill eligibleFor 35Qs pivoting into cyber program management or federal 0301/0343 roles.
Placement decides whether a screener ever sees it. BMR knows where each one ranks, what to call it, and how to frame it.
Free to start. Built around your real certs and clearance.
If your plan is NSA, US Cyber Command civilian, or cleared contractor cyber work, your runway is short and the demand is real. Focus on three things: (1) keep your clearance and polygraph current through the transition, (2) document specialized experience in language that maps to GS qualification standards or contract labor categories, (3) work the personal network you built during your service tours.
Some 35Qs leave the IC entirely after their commitment ends. Burnout from shift work, distance from family, or a desire to operate without classification handling drives the move. Commercial cybersecurity, data analytics, and software engineering are the realistic adjacent paths.
Most people do this backwards: wait for terminal leave, then panic. This is the sequence that works. Already out? Same plan, day one is today.
Days 0 to 30
Days 30 to 60
Days 60 to 90
BLS OEWS May 2024 reports a median of $124,910 for Information Security Analysts (15-1212.00), with the top 10% above $182,000. Cleared cyber threat intelligence roles requiring TS/SCI commonly pay $140K-$180K base plus clearance premium and bonuses. Compensation varies significantly by location — the Fort Meade and Northern Virginia corridors pay more than non-cleared geographies. Compensation also varies by polygraph status (CI poly, full-scope poly), which can add $10K-$30K to base.
The strongest direct matches are Cyber Threat Intelligence Analyst, Information Security Analyst, SOC Analyst, and Detection Engineer at cleared employers like Booz Allen Hamilton, Leidos, Peraton, SAIC, CACI, Mandiant, and CrowdStrike. Federal civilian roles in the GS-0132 (Intelligence) and GS-2210 (IT Management) series at NSA, US Cyber Command, DIA, and Army G-2 are also strong fits. Pivots into commercial cybersecurity, red team operations, or cloud security are all viable with appropriate certifications.
Highly valuable. Active TS/SCI with poly is one of the strongest negotiating levers in the cleared job market because clearances take 12-18 months to adjudicate from a cold start. Cleared employers cannot wait that long and pay premiums to candidates who already hold them. Your clearance stays active for 24 months after separation if you transfer to a sponsoring employer within that window — after that, it must be reinvestigated.
Yes. Commercial cybersecurity at companies like CrowdStrike, Mandiant (Google Cloud), Palo Alto Networks, and most MSSPs hires non-cleared analysts. The pay is competitive but typically lower than cleared roles for equivalent seniority. If you are leaving the IC entirely, certifications matter more in the commercial space — CompTIA Security+, GIAC GCIH/GCTI/GCFA, and offensive certs like OSCP carry significant weight.
Primary targets: GS-0132 Intelligence Specialist (NSA, DIA, Army G-2), GS-2210 Information Technology Management (cyber-coded positions), GS-1550 Computer Science (research roles), GS-0855 Electronics Engineering (signals systems), GS-1515 Operations Research (analytical methodology), GS-0301 Miscellaneous Administration (program management), and GS-0080 Security Administration (industrial security). With 35Q AIT and operational experience, GS-9 entry is realistic; GS-11 with strong production and senior collector roles.
For commercial cybersecurity and most cleared contractor roles, a degree is preferred but not required if you have strong certifications and operational experience. For federal civilian positions, degree requirements depend on the GS series. The 0132 and 2210 series do not require a specific degree; 1550 (Computer Science) and 0855 (Electronics Engineering) require relevant coursework. Use your post-9/11 GI Bill if you do not have a degree yet.
Stay above the classification line: describe the function, not the target. Talk about analytical methodology, frameworks (MITRE ATT&CK, Diamond Model, Cyber Kill Chain), tools by category (SIEM, traffic analysis platforms), report volume and audience, and impact in unclassified terms. Never name specific systems, targets, technical sources, or methods. Have your security manager review the resume before you send it externally — most commands offer this.
Prioritize CompTIA Security+ (DoD 8140 baseline for most cyber-coded positions), then GIAC GCIH or GCTI for threat intel and incident handling work. CISSP is the senior-level credential for IT security management — most 35Qs do not hit the 5-year experience requirement for full CISSP until after separation, but Associate of (ISC)2 status counts. Many bases offer free or subsidized cert prep through Education Centers or via FedVTE.
5-point preference applies to honorable discharge with qualifying service; 10-point preference applies to disabled veterans (any rating) and Purple Heart recipients. The 30% or More Disabled Veteran hiring authority allows agencies to hire you non-competitively up to GS-11. NSA, DIA, and other IC components apply Veterans Preference in line with their own merit hiring policies. Preference matters but does not override mission qualifications. USAJobs lets you filter for veteran-only postings.
Cleared cyber concentrates around: Fort Meade/Annapolis Junction MD (NSA), Northern Virginia (CIA, DIA, ODNI, contractor HQs), San Antonio TX (NSA Texas, JBSA), Augusta GA (Fort Eisenhower, Army Cyber Center of Excellence), Hawaii (NSA Hawaii), and Colorado Springs (US Space Command, Cheyenne Mountain). Remote-eligible cleared work exists but is limited by SCIF requirements. If you are tied to a non-cleared geography, expect to either commute to a SCIF or pivot to commercial cyber for that location.
Both paths are viable. Staying in cyber/SIGINT keeps you closest to the work you already do and the network you built. The salary ceiling is high and demand is structural. Pivoting to all-source intelligence (35F-style work) widens your applicable employer base and removes some of the operational shift-work pressure. The decision usually comes down to whether you want to keep the technical depth or move toward broader analytical and policy work.
Salary data from the U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics (OEWS), May 2024. Career data from O*NET OnLine.
Stop rewriting from scratch every time you apply. BMR turns your military experience into civilian and federal resumes, tailored to each job.
Tailored resumes
Rewritten for each job posting
Cover letters
Matched to the role
LinkedIn optimization
Profile rewrite for civilian recruiters
Elevator pitch generator
For interviews and networking
Company research reports
Know who you are applying to
Job tracker
Every application in one place