Security Assessment Lead
Listed on 2026-07-25
-
IT/Tech
Cybersecurity
Description
OCH Technologies is seeking a Security Assessment Lead to act as the technical authority for all independent risk assessments, vulnerability assessments, and analyses of alternatives conducted under this contract. The candidate will lead assessment planning, assign and mentor assessment teams, ensure assessment execution follows NIST 800‑53A methodology, and is accountable for the quality and completeness of all System Security Assessment Reports (SARs) delivered.
LocationHybrid – FAA Hubs Air Traffic Control System Command Center (ATCSCC) Washington, DC or Mike Monroney Aeronautical Center (MMAC) Oklahoma City, OK. Position may require up to 50% travel to FAA facilities.
Core Responsibilities & Duties- Serve as primary technical POC for all security assessments, vulnerability assessments, and analyses of alternatives under the contract.
- Lead assessment planning and coordination at FAA facilities nationwide, including developing System Security Assessment Test Plans and managing pre‑ and post‑assessment activities.
- Personally lead complex or high‑visibility assessment events.
- Ensure all assessments use the three NIST 800‑53A methods (Examine, Interview, Test) and produce compliant SARs.
- Develop and maintain vulnerability scanning strategies including Tactics, Techniques, and Procedures (TTPs).
- Evaluate and recommend scanning tools and configurations for NAS and Mission Support environments.
- Conduct risk translation from assessment findings and develop draft Plans of Action and Milestones (POAMs) with actionable remediation guidance.
- Lead regression assessment activities to validate that patches, fixes, and configuration changes mitigate previously identified vulnerabilities.
- Attend all Program Management Reviews and report on assessment status, deliverable timelines, and technical issues.
- Mentor and develop junior assessment staff.
- Build a team culture where analysts take ownership of their assigned systems and drive assessments to completion independently.
- Coordinate with NAS system owners, FAA facility staff, AIT/AIS, and ACG to schedule assessments and resolve access and logistical issues.
- Ensure assessment work in NAS operational environments follows safety protocols. Test methods for NAS systems may need to be conducted in lab environments due to air traffic safety constraints.
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution. Master’s degree in a related field preferred.
Experience- At least fifteen (15)+ years of cybersecurity experience.
- Minimum of five (5) years of management and supervisory responsibility leading risk and vulnerability assessment teams.
- At least two (2) years of relevant experience performed within the last 3 years.
- Demonstrated track record of successful completion of multiple independent risk assessments and vulnerability assessments on complex, multi‑system environments.
- Deep working knowledge of NIST SP 800‑53 (Rev. 4/5), NIST SP 800‑53A, NIST SP 800‑37 (RMF), and FIPS‑199 security categorization.
- Hands‑on experience with vulnerability assessment tools including Nessus, Web Inspect, App Detective Pro, nMap, and Tcpdump.
- Experience developing System Security Assessment Reports (SARs), Plans of Action and Milestones (POAMs), and assessment test plans.
- Experience working in Operational Technology (OT), Industrial Control Systems (ICS), or other safety‑critical infrastructure environments.
Candidate must have the ability to obtain and maintain a Public Trust. Active Secret level clearance preferred.
CertificationsCurrent cybersecurity certification aligned with security assessment and risk management disciplines, including CISSP, GCED, CompTIA CASP+, CISA, or an equivalent. CAP (Certified Authorization Professional) or equivalent RMF certification preferred.
Preferred Qualifications- Prior experience assessing National Airspace System (NAS) systems or other FAA Air Traffic Organization (ATO) systems.
- Familiarity with FAA Order 1370.82, FAA Order , and the ATO ISCM Plan.
- Experience supporting FAA Assessment & Authorization (A&A)…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).