Cybersecurity Lead
Listed on 2026-08-16
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Location: Huntsville, AL
Required Clearance: TS/SCI
Required
Education:
Bachelor's degree in cybersecurity, computer science, information technology, information assurance, engineering, or a related field; equivalent relevant experience may be considered where permitted by applicable workforce qualification requirements.
Required Experience: Senior cybersecurity experience leading RMF, assessment and authorization, security engineering, vulnerability management, security documentation, and remediation activities for DoD/Army information systems.
Position DescriptionPing Wind is seeking a Cybersecurity Lead to direct the cybersecurity program supporting PAE Fires OCIO IMAS. The Cybersecurity Lead will provide senior security leadership across systems engineering, software design/integration, testing, training, RMF assessment and authorization, vulnerability management, security documentation, and continuous risk reduction for classified and unclassified systems.
Primary ResponsibilitiesTypical Responsibilities/Tasks:
- Lead implementation and operation of the contract cybersecurity program and maintain the security expertise needed to support systems engineering, software design/integration, testing, training, and lifecycle support.
- Serve as the contractor primary cybersecurity/IS systems-engineering point of contact and coordinate security activities with Government cybersecurity leadership, assessors, authorizing officials, engineers, developers, administrators, and program management.
- Lead RMF Assess and Authorize activities and support achievement and maintenance of ATO/ATC or IATT decisions as appropriate for supported missions.
- Ensure system cybersecurity implementation is aligned with applicable DoD and Army requirements, NIST 800-series controls, CNSS guidance, DISA STIGs, and other governing cybersecurity policies identified by the PWS.
- Provide cybersecurity engineering across the system security architecture, including security configuration/implementation, product selection, threat assessment, vulnerability assessment, and risk assessment documentation.
- Manage security exceptions, alternative implementations, and discrepancies through appropriate Government review and Change Control Board approval before implementation.
- Oversee software-assurance activities for Government software, including risk management for third‑party/public‑domain/FOSS components, Software Bill of Materials where feasible, mobile‑code approvals, static code analysis, DISA APP DEV STIG implementation, OWASP Top 10 mitigation, and applicable software‑assurance practices.
- Oversee hardware‑assurance baseline inventory requirements and maintain security‑relevant hardware information in the Army authoritative cybersecurity repository as required.
- Lead Information Assurance Vulnerability Management activities, including Vulnerability Management Plan content, patch review, security scans, IAVA/IAVM tracking, test reporting, and use of DISA‑approved scanning tools.
- Produce, maintain, and deliver RMF cybersecurity artifacts including the System Security Plan, Ports/Protocols/Services Matrix, POA&M, and other required documentation.
- Prioritize and drive remediation of identified vulnerabilities and weaknesses, with High and Moderate risks addressed first and Low‑risk findings managed as part of comprehensive risk reduction.
- Ensure cybersecurity personnel maintain required qualifications and continuous professional development in accordance with DoDM 8140.03 and applicable DCWF work roles/proficiency levels.
- Demonstrated senior‑level experience leading DoD/Army cybersecurity programs, RMF assessment/authorization, security engineering, and continuous risk management for enterprise information systems.
- Expert knowledge of NIST SP 800-37, NIST SP 800-53, DoDI 8510.01, DoDI/DoDD 8500‑series cybersecurity requirements, DISA STIGs, and related Army cybersecurity policy.
- Experience developing and maintaining RMF artifacts such as SSPs, PPSM information, POA&Ms, risk/vulnerability assessments, security‑control evidence, and authorization packages.
- Experience leading vulnerability management, security scanning, patch…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).