Position: Cybersecurity Lead
Clearance: Secret
Location: Crystal City, VA (Hybrid Telework)
Type: Exempt, Full Time, Regular
Description
The Cybersecurity Lead plays a critical role in supporting cybersecurity modernization and compliance initiatives for the Project Management Office (PMO) within the Department of Defense (DoD). This role is critical in ensuring cybersecurity compliance, risk management, and secure system development across Army modernization initiatives. The ideal candidate will serve as a trusted advisor to senior leadership, guiding cybersecurity strategy and execution in alignment with Department of Defense (DoD) policies and frameworks. The Cyber Security Lead should be a proactive leader with deep technical expertise and a strong understanding of federal cybersecurity regulations and frameworks.
Duties and Responsibilities (including but not limited to)
· Apply current information security technologies and best practices to ensure the confidentiality, integrity, and availability of corporate information assets in compliance with established standards and procedures
· Continuously track regulatory changes, emerging threats, and evolving technologies to update security policies, standards, and compliance measures across the organization
· Develop security engineering documentation, including briefs, white papers, architecture designs, and implementation plans to support cybersecurity re-engineering efforts
· Provide expertise across the full spectrum of cybersecurity engineering activities, ensuring alignment with security frameworks and best practices
· Define and document “As-Is” and “To-Be” cybersecurity architecture and systems security engineering requirements to support modernization efforts
· Ensure acquired or developed systems comply with cybersecurity guidelines, conduct security reviews, identify architecture gaps, and develop risk management plans to assess security design adequacy in acquisition processes
· Review and validate remediation plans for vulnerability scans/testing across hosts, networks, applications, static code, and open-source solutions. Develop Plans of Action & Milestones (POA&Ms) to address security gaps
· Maintain expert knowledge of key cybersecurity regulations and frameworks, including:
- Executive Orders 13556 (CUI), 13960 & 14110 (AI)
- NIST Standards SP 800-171 (CMMC), SP 800-37 & 800-53 (FISMA RMF), SP 800-30 (Risk Assessment), SP -800-161 (C-SCRM), SP 800-218 (SSDF)
- Federal & DoD Compliance FedRAMP, DFARS 252.204-7012 / -7019 / -7020 / -7021, DoDI 8510.01 (DoD RMF), DISA STIGs, DoD Cloud Computing Security Requirements Guide (CC SRG)
- Encryption Standards FIPS 140-2 & 140-3 validated products and implementation guides
Required Qualifications
· Must possess and maintain a Secret Security Clearance
· Master’s degree in a relevant field (Cybersecurity, Information Technology), or Bachelor’s Degree in related field plus an additional two (2) years’ experience
· 12+ years of experience supporting cybersecurity
· Demonstrable experience in a Cybersecurity Lead, Subject Matter Expert (SME), or other advisory level position
· Experience supporting a Project Management Office (PMO) within the Department of the Army Headquarters
· Experience as an Information System Security Manager (ISSM) or Information System Security Officer (ISSO) on DoD programs
· Experience executing cybersecurity processes, procedures and RMF in an Agile environment
· Strong communication and leadership skills, with the ability to brief senior stakeholders.
· Demonstrated ability to manage multiple prioritie