Cybersecurity Lead
Huntsville, AL - USA
Job Summary
Location: Huntsville AL
Required Clearance: TS/SCI
Required Education: Bachelors degree in cybersecurity computer science information technology information assurance engineering or a related field; equivalent relevant experience may be considered where permitted by applicable workforce qualification requirements.
Required Experience: Senior cybersecurity experience leading RMF assessment and authorization security engineering vulnerability management security documentation and remediation activities for DoD/Army information systems.
Position Description
PingWind is seeking a Cybersecurity Lead to direct the cybersecurity program supporting PAE Fires OCIO IMAS. The Cybersecurity Lead will provide senior security leadership across systems engineering software design/integration testing training RMF assessment and authorization vulnerability management security documentation and continuous risk reduction for classified and unclassified systems.
Primary Responsibilities
Typical Responsibilities/Tasks:
- Lead implementation and operation of the contract cybersecurity program and maintain the security expertise needed to support systems engineering software design/integration testing training and lifecycle support.
- Serve as the contractor primary cybersecurity/IS systems-engineering point of contact and coordinate security activities with Government cybersecurity leadership assessors authorizing officials engineers developers administrators and program management.
- Lead RMF Assess and Authorize activities and support achievement and maintenance of ATO/ATC or IATT decisions as appropriate for supported missions.
- Ensure system cybersecurity implementation is aligned with applicable DoD and Army requirements NIST 800-series controls CNSS guidance DISA STIGs and other governing cybersecurity policies identified by the PWS.
- Provide cybersecurity engineering across the system security architecture including security configuration/implementation product selection threat assessment vulnerability assessment and risk assessment documentation.
- Manage security exceptions alternative implementations and discrepancies through appropriate Government review and Change Control Board approval before implementation.
- Oversee software-assurance activities for Government software including risk management for third-party/public-domain/FOSS components Software Bill of Materials where feasible mobile-code approvals static code analysis DISA APP DEV STIG implementation OWASP Top 10 mitigation and applicable software-assurance practices.
- Oversee hardware-assurance baseline inventory requirements and maintain security-relevant hardware information in the Army authoritative cybersecurity repository as required.
- Lead Information Assurance Vulnerability Management activities including Vulnerability Management Plan content patch review security scans IAVA/IAVM tracking test reporting and use of DISA-approved scanning tools.
- Produce maintain and deliver RMF cybersecurity artifacts including the System Security Plan Ports/Protocols/Services Matrix POA&M and other required documentation.
- Prioritize and drive remediation of identified vulnerabilities and weaknesses with High and Moderate risks addressed first and Low-risk findings managed as part of comprehensive risk reduction.
- Ensure cybersecurity personnel maintain required qualifications and continuous professional development in accordance with DoDM 8140.03 and applicable DCWF work roles/proficiency levels.
Required Qualifications
- Demonstrated senior-level experience leading DoD/Army cybersecurity programs RMF assessment/authorization security engineering and continuous risk management for enterprise information systems.
- Expert knowledge of NIST SP 800-37 NIST SP 800-53 DoDI 8510.01 DoDI/DoDD 8500-series cybersecurity requirements DISA STIGs and related Army cybersecurity policy.
- Experience developing and maintaining RMF artifacts such as SSPs PPSM information POA&Ms risk/vulnerability assessments security-control evidence and authorization packages.
- Experience leading vulnerability management security scanning patch assessment IAVM/IAVA processes remediation prioritization and technical risk reporting.
- Working knowledge of secure systems engineering and software assurance including static analysis secure configuration FOSS/third-party risk SBOM concepts and OWASP/DISA application-security practices.
- Ability to lead cybersecurity staff work across engineering/development/operations teams brief Government leaders and assessors and drive issues through formal approval/governance processes.
- Must meet the applicable DoDM 8140.03/DCWF qualification requirements for the assigned cybersecurity work role and proficiency level including required continuing professional development.
- TS/SCI security clearance.
Desired Qualifications
- CISSP CGRC/CAP Security or other certifications aligned to the assigned DCWF role and proficiency level.
- Experience serving as an ISSM ISSE cybersecurity manager or senior RMF lead for Army/DoD systems.
- Experience with Tenable Nessus/Tenable Security Manager STIG Viewer/Evaluate STIG Trellix security tools or comparable vulnerability/compliance platforms.
- Experience supporting classified systems SAP environments software assurance and Government Change Control Board processes.
About PingWind
PingWind is focused on delivering outstanding services to the federal government. We have extensive experience in the fields of cybersecurity development IT infrastructure supply chain management and other professional services such as system design and continuous improvement. PingWind is an SBA certified Service-Disabled Veteran-Owned Small Business (SDVOSB) with offices in Northern Virginia and Huntsville AL.
Our benefits include:
Eleven Federal Holidays
Paid Time Off accrued each pay period
Parental Leave
Three medical plan choices with generous employer contribution
Dental and Vision Insurance
Company paid Short-Term and Long-Term Disability
Company paid Life and AD&D Insurance
401k with competitive matching and vesting schedule
Continuing education assistance
Short Term / Long Term Disability & Life Insurance
Medical Dependent Care and Commuter Flexible Spending Accounts
Employee Assistance Program
Wellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass)
529 College Savings Plan
Legal Insurance
Pet Insurance
Salary Range
$106k-$148K
The pay range for this job is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) job responsibilities education certifications experience as well as internal equity mapping and alignment with market data or other applicable laws.
Veterans are encouraged to apply
PingWind Inc. does not discriminate in employment opportunities terms and conditions of employment or practices on the basis of race age gender religious or political beliefs national origin or heritage disability sexual orientation or any characteristic protected by law