Cybersecurity Lead
Listed on 2026-08-17
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Location:
Huntsville, AL Required Clearance: TS/SCI Required
Education:
Bachelor's degree in cybersecurity, computer science, information technology, information assurance, engineering, or a related field; equivalent relevant experience may be considered where permitted by applicable workforce qualification requirements.
Required Experience:
Senior cybersecurity experience leading RMF, assessment and authorization, security engineering, vulnerability management, security documentation, and remediation activities for DoD/Army information systems.
Position Description
Ping Wind is seeking a Cybersecurity Lead to direct the cybersecurity program supporting PAE Fires OCIO IMAS. The Cybersecurity Lead will provide senior security leadership across systems engineering, software design/integration, testing, training, RMF assessment and authorization, vulnerability management, security documentation, and continuous risk reduction for classified and unclassified systems.
Primary ResponsibilitiesTypical Responsibilities/Tasks:
Lead implementation and operation of the contract cybersecurity program and maintain the security expertise needed to support systems engineering, software design/integration, testing, training, and lifecycle support. Serve as the contractor primary cybersecurity/IS systems-engineering point of contact and coordinate security activities with Government cybersecurity leadership, assessors, authorizing officials, engineers, developers, administrators, and program management. Lead RMF Assess and Authorize activities and support achievement and maintenance of ATO/ATC or IATT decisions as appropriate for supported missions.
Ensure system cybersecurity implementation is aligned with applicable DoD and Army requirements, NIST 800-series controls, CNSS guidance, DISA STIGs, and other governing cybersecurity policies identified by the PWS. Provide cybersecurity engineering across the system security architecture, including security configuration/implementation, product selection, threat assessment, vulnerability assessment, and risk assessment documentation. Manage security exceptions, alternative implementations, and discrepancies through appropriate Government review and Change Control Board approval before implementation.
Oversee software-assurance activities for Government software, including risk management for third-party/public-domain/FOSS components, Software Bill of Materials where feasible, mobile-code approvals, static code analysis, DISA APP DEV STIG implementation, OWASP Top 10 mitigation, and applicable software-assurance practices. Oversee hardware-assurance baseline inventory requirements and maintain security-relevant hardware information in the Army authoritative cybersecurity repository as required. Lead Information Assurance Vulnerability Management activities, including Vulnerability Management Plan content, patch review, security scans, IAVA/IAVM tracking, test reporting, and use of DISA-approved scanning tools.
Produce, maintain, and deliver RMF cybersecurity artifacts including the System Security Plan, Ports/Protocols/Services Matrix, POA&M, and other required documentation. Prioritize and drive remediation of identified vulnerabilities and weaknesses, with High and Moderate risks addressed first and Low-risk findings managed as part of comprehensive risk reduction. Ensure cybersecurity personnel maintain required qualifications and continuous professional development in accordance with DoDM 8140.03 and applicable DCWF work roles/proficiency levels.
Demonstrated senior-level experience leading DoD/Army cybersecurity programs, RMF assessment/authorization, security engineering, and continuous risk management for enterprise information systems. Expert knowledge of NIST SP 800-37, NIST SP 800-53, DoDI 8510.01, DoDI/DoDD 8500-series cybersecurity requirements, DISA STIGs, and related Army cybersecurity policy. Experience developing and maintaining RMF artifacts such as SSPs, PPSM information, POA&M, risk/vulnerability assessments, security-control evidence, and authorization packages. Experience leading vulnerability management, security scanning,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).