Senior Cybersecurity Lead
Job Description
Chameleon Integrated Services seeks an ISSM / Senior Cybersecurity & GRC Lead to act as the primary cybersecurity risk advisor to the Government Program Manager and Authorizing Official (AO). This onsite role in Linthicum Heights, MD will lead enterprise RMF and GRC execution while also overseeing core technical cybersecurity activities, including testing, vulnerability management, threat hunting, incident response, and SOC operations.
Key Responsibilities
- Manage and maintain the enterprise RMF package, validating security compliance across all interconnected agency systems.
- Execute both RMF tracks: Steady-State Continuous Monitoring for systems with existing valid ATOs and ATO Attainment (“Get-Well”) for newly onboarded systems.
- Author and compile initial System Security Plans (SSPs) and Security Assessment Plans, and coordinate AO-ready eMASS packages delivered within strict 180-day windows.
- Consolidate, manage, and track the enterprise Plan of Action and Milestones (POA&M) on behalf of the government, including formal Risk Acceptance recommendations to the AO.
- Guide the agency transition away from a static ATO process toward an automated Continuous ATO (cATO) framework.
- Direct and coordinate teams of Information System Security Officers (ISSOs) and technical assessors.
- Interface with live cyber operations to ensure compliance of vulnerability scanning, automated patching windows, Infrastructure as Code (IaC) change repositories, and incident response procedures with DoD mandates.
Required Qualifications
- Certified Information Systems Security Manager (ISSM) or equivalent credential compliant with DoD 8140/8570 requirements (for example CISSP, CISM, or GSLC).
- Proven ability to execute the end-to-end RMF lifecycle and submit packages through eMASS.
- Demonstrated experience writing, reviewing, or consolidating enterprise SSPs, POA&Ms, and STIG compliance documentation.
- Direct experience advising an Authorizing Official (AO) or senior government program manager on risk acceptance boundaries.
- Strong understanding of operational cybersecurity environments, including standard tools or workflows for penetration testing, threat hunting, and incident response.
- Clearance Required: TS/SCI clearance eligibility preferred; U.S. Citizenship required.
Relevant Technologies
- DoD 8140, DoD 8570
- eMASS
- RMF, SSPs, POA&M, STIG
- Continuous ATO (cATO)
- Infrastructure as Code (IaC)
Benefits
- Competitive Employee Health Insurance options including dental
- 100% company paid vision plan
- 401K plan with generous company match and no vesting period
- 100% company paid life insurance
- 100% company paid long and short-term disability insurance
- Training allowance
- PTO and more
Position Notes
Chameleon Integrated Services is actively bidding on a proposal to provide Cyberspace Operations and Development for the Enterprise (CODE) services under the DC3 Technical, Analytical, and Business Operations (TABO) requirement. This position is contingent upon contract award.
Preferred Qualifications
- Active TS/SCI security clearance
- Familiarity with continuous monitoring automation or cATO transition models inside a DoD enterprise
Location and Employment Type
- Location: Linthicum Heights, MD (onsite)
- Employment Type: Full-Time / Contingent Upon Contract Award
- Clearance Required: TS/SCI clearance eligibility preferred; U.S. Citizenship required