Lucayan Technology Solutions LLC

Cybersecurity Lead

Lucayan Technology Solutions LLC United States

IT Services and IT Consulting · 51-200 employees

6 h ago
Remote security Senior (5-10 yrs) Contractor United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Cybersecurity Lead will direct the Risk Management Framework and Authority to Operate efforts for a new Department of Defense emergency mass notification system. Responsibilities include managing the full RMF lifecycle, authoring security documentation, and ensuring system compliance through rigorous testing and remediation.

What they look for

Risk Management Framework RMF ATO DoD 8570 eMASS STIG SRG ACAS Nessus SCAP POA&M SSP ISA Cybersecurity Network Security Compliance

Requirements

Candidates must have at least 5 years of DoD RMF experience and hold an active DoD 8570/8140 IAM Level II-compliant certification. Applicants must also be eligible for a DoD Common Access Card and military base access.

Full description

Location: This is a US-based remote position, with approved on-site work at a U.S. military installation in Germany as needed.

  • On-site travel is scheduled in advance and approved travel costs are covered.

Employment Type: Part-Time Contract Security Clearance: Must be eligible for a DoD Common Access Card (CAC) and military base access

Status: Actively Hiring

Job Summary

We are looking for an experienced Cybersecurity Lead to direct the Risk Management Framework (RMF) and Authority to Operate (ATO) effort for a new Department of Defense emergency mass notification system. You will own the authorization package from boundary definition through AO decision support, working alongside the engineering and installation team on an accelerated schedule.

Key Responsibilities

●      Lead the full RMF lifecycle: boundary definition, categorization, control selection, implementation, assessment, and authorization

●      Author the SSP, control narratives, network and data-flow diagrams, and interconnection security agreements (ISAs)

●      Apply STIGs/SRGs, run SCAP, Evaluate-STIG, and ACAS/Nessus scans, and maintain hardened baselines

●      Manage findings, POA&Ms, patching, and IAVM records, and direct field staff on remediation

●      Secure system APIs and provide cybersecurity test procedures and evidence for acceptance testing

●      Prepare an eMASS-ready ATO package and support assessor reviews, AO briefings, and IATT when needed

●      Deliver continuous-monitoring and patch-management plans, weekly status reports, and closeout knowledge transfer

Required Qualifications

●      Legally authorized to work in the United States

●      Ability to obtain a DoD CAC and military base access

●      Active DoD 8570/8140 IAM Level II-compliant certification

●      Minimum 5 years of DoD RMF experience, including leading systems through ATO

●      Hands-on experience with eMASS, STIG/SRG compliance, ACAS, and POA&M management

●      Experience writing SSPs, ISAs, and security architecture documentation

●      Valid U.S. passport or ability to obtain one before travel

Preferred Qualifications

●      Greenfield (new system) ATO experience

●      Air Force or overseas (OCONUS) installation experience

●      Familiarity with mass notification, unified communications, or VoIP systems

●      Interim Authority to Test (IATT) experience

Certifications

●      DoD 8570/8140 IAM Level II-compliant certification required (e.g., CISSP, CISM, CASP+/SecurityX, CGRC/CAP, GSLC, CCISO)

●      DoD Cyber Awareness and Antiterrorism/Force Protection training completed upon hire

Similar roles