Cybersecurity Lead
Lucayan Technology Solutions LLC United States
IT Services and IT Consulting · 51-200 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The Cybersecurity Lead will direct the Risk Management Framework and Authority to Operate efforts for a new Department of Defense emergency mass notification system. Responsibilities include managing the full RMF lifecycle, authoring security documentation, and ensuring system compliance through rigorous testing and remediation.
What they look for
Requirements
Candidates must have at least 5 years of DoD RMF experience and hold an active DoD 8570/8140 IAM Level II-compliant certification. Applicants must also be eligible for a DoD Common Access Card and military base access.
Full description
Location: This is a US-based remote position, with approved on-site work at a U.S. military installation in Germany as needed.
- On-site travel is scheduled in advance and approved travel costs are covered.
Employment Type: Part-Time Contract Security Clearance: Must be eligible for a DoD Common Access Card (CAC) and military base access
Status: Actively Hiring
Job Summary
We are looking for an experienced Cybersecurity Lead to direct the Risk Management Framework (RMF) and Authority to Operate (ATO) effort for a new Department of Defense emergency mass notification system. You will own the authorization package from boundary definition through AO decision support, working alongside the engineering and installation team on an accelerated schedule.
Key Responsibilities
● Lead the full RMF lifecycle: boundary definition, categorization, control selection, implementation, assessment, and authorization
● Author the SSP, control narratives, network and data-flow diagrams, and interconnection security agreements (ISAs)
● Apply STIGs/SRGs, run SCAP, Evaluate-STIG, and ACAS/Nessus scans, and maintain hardened baselines
● Manage findings, POA&Ms, patching, and IAVM records, and direct field staff on remediation
● Secure system APIs and provide cybersecurity test procedures and evidence for acceptance testing
● Prepare an eMASS-ready ATO package and support assessor reviews, AO briefings, and IATT when needed
● Deliver continuous-monitoring and patch-management plans, weekly status reports, and closeout knowledge transfer
Required Qualifications
● Legally authorized to work in the United States
● Ability to obtain a DoD CAC and military base access
● Active DoD 8570/8140 IAM Level II-compliant certification
● Minimum 5 years of DoD RMF experience, including leading systems through ATO
● Hands-on experience with eMASS, STIG/SRG compliance, ACAS, and POA&M management
● Experience writing SSPs, ISAs, and security architecture documentation
● Valid U.S. passport or ability to obtain one before travel
Preferred Qualifications
● Greenfield (new system) ATO experience
● Air Force or overseas (OCONUS) installation experience
● Familiarity with mass notification, unified communications, or VoIP systems
● Interim Authority to Test (IATT) experience
Certifications
● DoD 8570/8140 IAM Level II-compliant certification required (e.g., CISSP, CISM, CASP+/SecurityX, CGRC/CAP, GSLC, CCISO)
● DoD Cyber Awareness and Antiterrorism/Force Protection training completed upon hire
Similar roles
-
IT Manager, Data Governance & Cybersecurity (AI Compliance)
Maker Lab Singapore, Singapore
-
Cybersecurity Engineer (PKI, Cryptography Experience)
NCS Singapore, Singapore
-
Lead Application Security Engineer
Agoda Bangkok, Thailand
-
Cybersecurity Internship Winter 2027 - Federal
Tevora Irvine, California, United States · $56K/yr
-
Cybersecurity Internship Winter 2027 - Enterprise Risk Management
Tevora Irvine, California, United States · $56K/yr
-
Cybersecurity Internship Winter 2027 - Healthcare
Tevora Irvine, California, United States · $56K/yr