Enter a job title or keyword

Security Lead Release Lead (REMOTE)


Job Location:

Chantilly, VA - USA

Monthly Salary: Not provided by the employer
Posted: 21 August 2026 (13 days ago)
Application Deadline: 18 November 2026
Vacancies: 1 Vacancy

Job Summary

Koniag IT Systems LLC a Koniag Government Services company is seeking a Security Lead / Release Lead with a Secret security clearance to support KITS and our government customer. The position is remote. We offer competitive compensation and an extraordinary benefits package including health dental and vision insurance 401K with company matching flexible spending accounts paid holidays three weeks paid time off and IT Systems a Koniag Government Services company is seeking an experiencedSecurity & Release Leadto support a critical Government Identity Credential and Access Management (ICAM) initiative. This role supports a large-scale Application and Systems Enablement effort issued under an ICAM Enterprise Master IDIQ Contract. The Security & Release Lead will serve as the primary authority for security compliance oversight and release management across the ICAM enablement programensuring that all integration solutions platform configurations custom tools and application onboarding activities meet applicable DoD security requirements and that all releases into production environments are executed in a controlled documented and compliant mannerin direct support of the Department of Defense (DoD) Zero Trust Execution ideal candidate is an experienced security and release management professional with a strong background in federal IT security compliance DoD cybersecurity frameworks identity and access management and structured release processes. This individual must be equally comfortable operating as a security subject matter expert and a disciplined release manager capable of bridging the gap between security requirements and operational program execution in a high-volume fast-paced federal IT position requires an active Secret clearance and may require occasional travel to Government facilities. Primary work will be performed Security & Release Lead will serve as the integrated security and release management authority for the ICAM Application and Systems Enablement program responsible for ensuring that all program activitiesfrom initial application triage through platform configuration middleware development and production deploymentare executed in full compliance with applicable DoD and federal security standards and that all releases into test and production environments follow a structured auditable and risk-managed release process. This individual will work closely with the program manager deputy program manager migration team lead platform engineers middleware engineers and Government stakeholders to embed security throughout the enablement lifecycle and ensure that every production release is authorized tested documented and verified prior to responsibilities will include but are not limited to:Serve as the primary security subject matter expert (SME) for the ICAM enablement program providing authoritative guidance on applicable DoD and federal security requirements policies and frameworks across all program activities and implement and maintain the programs security compliance framework ensuring all enablement activities platform configurations custom tools connectors middleware solutions and integration artifacts adhere to applicable security standards including DoDI 8520.04 DoDM 8140.03 DFARS 252.204-7012 NIST SP 800-171 and all other referenced DoD and federal and enforce Controlled Unclassified Information (CUI) handling requirements across the program ensuring all personnel processes and systems comply with DoDI 5200.48 DoDM 5200.01 and applicable CUI marking safeguarding and dissemination Operations Security (OPSEC) requirements across the program ensuring OPSEC principles are incorporated into all relevant program activities documentation and communications in accordance with applicable DoD directives and ensuring all subcontractors handling Critical Information comply with flowed-down OPSEC supply chain risk management activities per DFARS 239.73 overseeing the vetting of all third-party connectors scripts code libraries and enhancements integrated into the ICAM environment to prevent the introduction of cybersecurity vulnerabilities malicious code or unauthorized data exfiltration all contractor personnel maintain required DoD cybersecurity certifications per DoDM 8140.03 tracking certification status across the program team and coordinating remediation for personnel with lapsed or insufficient implement and manage the program release management framework establishing standardized processes approval gates documentation requirements and rollback procedures for all releases into development test and production as the release authority for all production deployments coordinating release readiness reviews with the migration team lead platform engineers middleware engineers and Government stakeholders to ensure all release criteria are met prior to deployment and oversee the configuration management process across the program ensuring all platform configurations custom tools connectors integration artifacts and documentation are version-controlled baselined and maintained in accordance with the programs configuration management deficiency reporting analysis tracking and resolution activities across the program ensuring all deficiencies are identified documented tracked and resolved in accordance with applicable technical orders and reporting requirements including preparation of SF368 reports or with the Government COR and ICAM PMO on all security-related matters including incident reporting vulnerability disclosures cybersecurity certification status and security compliance all web-based applications user interfaces and digital materials enabled or developed under the contract comply with Section 508 of the Rehabilitation Act of 1973 coordinating accessibility reviews and remediation activities as the test program by integrating security testing requirements into the Master Test Plan and Software Test Plans ensuring security-relevant test cases are included in all integration testing and UAT activities and reviewing Software Test Reports for security compliance data rights compliance across the program ensuring all custom tools connectors workflows enhancements and documentation developed under the contract are properly identified marked and delivered in accordance with DFARS 252.227-.227-7014 and and report on security and release management program metrics contributing to the Enablement Tracking Database and Metrics Dashboard with relevant security compliance and release status and maintain security and release management documentation including security compliance checklists release readiness criteria configuration management records deficiency logs and OPSEC security awareness guidance and compliance coaching to program team members ensuring all personnel understand and adhere to applicable security requirements throughout the enablement current knowledge of evolving DoD security policies cybersecurity frameworks identity security standards and Zero Trust requirements proactively applying updated knowledge to strengthen program security posture and release and Experience:Required:Bachelors degree in Cybersecurity Information Technology Computer Science Information Systems or a related field from an accredited college or of 7 years of experience in information technology with at least 3 years of direct experience in IT security compliance cybersecurity program management or a related security discipline within a federal government of 2 years of experience in release management configuration management or IT change management within a structured federal IT program experience applying DoD cybersecurity frameworks policies and directives including DFARS 252.204-7012 DoDM 8140.03 NIST SP 800-171 and CUI requirements in a program execution Secret clearance. Must be able to satisfy requirements for CAC-card issuance and NIPRNet access including annual DoD CyberAwareness training and :Prior experience supporting DoD IT programs particularly within an ICAM cybersecurity or Zero Trust working in a federal government IT contracting environment supporting programs with complex security compliance managing security and release processes for programs involving large-scale application integration or enterprise identity platform Skills and Competencies:Deep knowledge of applicable DoD and federal security requirements policies and frameworks including DoDI 8520.04 DoDM 8140.03 DFARS 252.204-7012 DFARS 239.73 DoDI 5200.48 DoDM 5200.01 NIST SP 800-171 and related working knowledge of Controlled Unclassified Information (CUI) requirements including marking safeguarding dissemination controls aggregation monitoring and compliance with applicable DoD and federal CUI developing and implementing OPSEC programs and ensuring OPSEC principles are embedded into program activities documentation and communications in accordance with applicable DoD experience managing release management processes in a federal IT program environment including the development and enforcement of release readiness criteria approval gates change control procedures and rollback with configuration management processes and tools including version control systems baseline management and change tracking in a structured federal IT program with Identity Credential and Access Management (ICAM) security concepts including identity providers (IdP) identity governance and administration (IGA) Single Sign-On (SSO) Multi-Factor Authentication (MFA) and Zero Trust identity security conducting or overseeing supply chain risk management activities including the security vetting of third-party code libraries connectors and software components integrated into federal IT with deficiency reporting processes including preparation of SF368 reports or equivalent deficiency tracking and resolution coordination in a federal contracting ability to coordinate security compliance activities across cross-functional teams including engineers program managers and Government organizational skills with the ability to manage multiple concurrent security and release management workstreams while maintaining accuracy thoroughness and timeliness of all compliance communication skills in Englishboth written and oralwith the ability to clearly convey security requirements compliance findings and release management processes to both technical engineers and non-technical program with Microsoft Office Suite and collaboration tools such as Microsoft DoD cybersecurity certification at the IAT II level or above per DoDM 8140.03 (e.g. CompTIA Security or equivalent).Clearance Requirement:Secret clearance Desired Skills and Competencies:Certified Information Systems Security Professional (CISSP) Information Security Manager (CISM) Security certification or equivalent DoD 8140.03 baseline certification at the IAT II level or managing security compliance for programs involving Okta Identity Provider and SailPoint IdentityIQ platforms including platform-level security configuration access control enforcement and audit logging with Zero Trust Architecture (ZTA) principles and their application to security compliance and release management within a DoD managing or contributing to Authority to Operate (ATO) processes Risk Management Framework (RMF) activities or system security plan development within a DoD or federal government of DoD Freedom of Information Act (FOIA) requirements and their application to program documentation and data managing data rights compliance in a federal contracting environment including familiarity with DFARS 252.227-.227-7014 and with Section 508 compliance requirements for electronic and information technology including experience coordinating accessibility reviews and remediation with CI/CD pipeline security integration including the implementation of security gates automated security scanning and compliance checks within software delivery with enterprise identity protocols including SAML 2.0 OAuth 2.0 OIDC and SCIM from a security compliance and risk management developing and maintaining security compliance documentation including security plans compliance checklists risk registers and OPSEC plans in a federal contracting with CDRL deliverable development and management in a federal contracting with Agile and hybrid Agile-Waterfall program execution methodologies including experience integrating security and release management activities into sprint-based development managing personnel cybersecurity certification tracking and compliance remediation across a multi-disciplinary program Equal Employment Opportunity PolicyThe company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race color religion creed ethnicity sex sexual orientation gender or gender identity (except where gender is a bona fide occupational qualification) national origin or ancestry age disability citizenship military/veteran status marital status genetic information or any other characteristic protected by applicable federal state or local law. We are committed to equal employment opportunity in all decisions related to employment promotion wages benefits and all other privileges terms and conditions of company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website please get in touch with Heaven Wood via e-mail by calling to request Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical professional and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers employees and native communities. For more information please Opportunity Employer/Veterans/ Preference in accordance with Public Law 88-352

About Company

Company Logo

What We Do Koniag Government Services (KGS) is an Alaska Native Corporation comprised of multiple wholly owned subsidiary companies that deliver Enterprise Solutions, Professional Services, and Operations Management to Federal Government agencies. With an agile employee and corporate ... View more

View Profile View Profile