Cybersecurity Lead
Job Description
Ignite Fueling Innovation is seeking a Cybersecurity Lead to support the U.S. Army at Redstone Arsenal in Huntsville, AL (onsite). In this role, you will direct the contract cybersecurity program and serve as the primary point of contact for cybersecurity and information-systems security engineering, including RMF/A&A, security engineering, assessments, authorization support, and continuous monitoring across both classified and unclassified systems.
What you’ll be doing
- Establish, implement, operate, and continuously improve the contract cybersecurity program.
- Act as the primary cybersecurity/ISSE point of contact and provide or oversee qualified ISSM support.
- Lead RMF planning, categorization, control selection, implementation, assessment, authorization, monitoring, and package maintenance.
- Lead and perform compliance reviews of computer security plans, conduct risk assessments, and validate security test evaluations and audits.
- Coordinate ATO, ATC, and IATT activities with system owners, CA, AO, G-6, engineering, development, and operations personnel.
- Produce and maintain required RMF artifacts, including SSPs, PPSM registrations, POA&Ms, vulnerability documentation, and RMF package content.
- Direct vulnerability scanning and remediation workflows, including patch assessment, IAVM, STIG validation, prioritization, exception processing, and risk reporting.
- Integrate security into architecture, systems engineering, software design, testing, deployment, training, and lifecycle management.
- Enforce security assurance requirements such as software assurance, FOSS/SBOM review, mobile-code approval, hardware baseline, and CCB requirements.
- Ensure cybersecurity personnel maintain applicable DoDM 8140.03 qualifications and continuing professional development.
- Support cyber and engineering technical interchange meetings, incidents, audits, inspections, and executive briefings.
What you bring
- 10+ years of relevant cybersecurity/IA policy and compliance experience at the Senior/Lead level.
- Experience leading Certification and Accreditation, RMF/A&A, cyber defense compliance, audits and inspections, security-plan reviews, risk assessments, security testing, and enterprise security requirements analysis.
- Experience leading control implementation and evidence development for classified and unclassified systems and networks.
- Expert knowledge of applicable DoD and Army cybersecurity policy, including DoDI 8510.01, DoDI 8500.01, DoDM 8140.03, AR 25-2, NIST SP 800-37, NIST SP 800-53/53A, CNSSI 1253, and DISA STIGs.
- Experience with SSPs, PPSM, POA&Ms, control evidence, vulnerability scans, IAVM, risk acceptance, continuous monitoring, incident support, and authorization packages.
- Strong leadership, audit execution, technical writing, briefing, and cross-functional coordination skills.
- CompTIA Security+ is required.
- DoD 8140/DCWF-aligned qualification; CISSP, CISM, CISSP-ISSMP, GSLC, or equivalent.
- Maintain at least 20 hours of continuing professional development annually.
Security clearance
Must have an active DoD Top Secret Clearance (SCI and SAP eligible).
Education
MA/MS is required. BA/BS with 12+ years of relevant experience is permitted as a substitution.
Tools and technologies you may work with
- CompTIA Security+, CISSP, CISM, CISSP-ISSMP, GSLC
- DoDI 8510.01, DoDI 8500.01, DoDM 8140.03, AR 25-2, NIST SP 800-37, NIST SP 800-53/53A, CNSSI 1253, DISA STIGs
- Tenable Nessus/Security Manager, Evaluate STIG, STIG Viewer, Trellix, Fortify
- Elastic (Beats/Logstash/Kibana), VMware, Windows, Linux, OpenShift/container, cloud
- Identity, SBOM, FOSS, CMMC Level 2, CUI
- CMMC UID management
Similar Jobs
F