Job Description
Description
The Cybersecurity Lead is responsible for all CMCC System Facilitator cyber governance, acting as the senior technical and accreditation authority. This role ensures Capability Providers and Externals deliver complete, technically validated cyber artifacts and coordinates with the Infrastructure Task Order to support inclusion into the Baseline. The Cybersecurity Lead maintains all RMF/ATO packages for development, integration, and test environments, leads continuous monitoring, participates in CCB promotion decisions, and provides hands on support to Cloud and DSOP engineers. The Lead reinforces mission alignment, technical excellence, active communication, WHY based guidance, and real time vector checks.
Job Duties include:
• Embed JSIG, NIST SP 800-53, STIG, and RMF controls into CMCC environments and capability onboarding workflows.
• Own RMF/ATO packages for CMCC Dev/Integration/Test environments; maintain SSP/POA&M/Continuous Monitoring artifacts.
• Lead CMCC cyber governance: validate CP and External cyber artifacts, ensure technical completeness, and coordinate readiness for Infrastructure TO baseline updates.
• Provide hands-on technical support to Cloud and DSOP cyber engineers during complex tasks, troubleshooting, or environment build-outs.
• Represent Cyber on ARB/CCB and provide cyber recommendations for environment promotion gates.
• Review and adjudicate STIG, SAST/DAST, ACAS/Nessus, and cloud/pipeline vulnerabilities; coordinate remediation across DSOPS, Platform, Cloud, CE, and CP teams.
• Identify systemic cyber gaps early and lead corrective-action plans aligned to mission objectives.
• Ensure MLS/MILS boundary compliance and alignment with CMCC multi-tenant security patterns.
• Mentor and develop the Cyber team; reinforce communication expectations, WHY behind requirements, active participation, vector checks, and accountability.
Qualifications
Required Qualifications & Experience:
• Bachelors and fourteen (14) years or more experience; Masters and twelve (12) years or more experience; PhD or JD and nine (9) years or more experience .
• Expert knowledge of RMF and cybersecurity governance across diverse enclaves.
• Experience with Xacta, STIGs, OWASP tooling, and ACAS/Nessus vulnerability adjudication.
• DoD 8140-aligned certifications such as CISSP, CCSP, GIAC Security Engineer (GSE), CASP+, or equivalent.
Desired qualifications and experience:
• Experience validating JSIG requirements and NIST SP 800-53 controls across development, integration, and test environments.
• Background in cloud and container security.
• Prior leadership experience building, developing, and mentoring cyber teams.
Desired Skills and Certifications:
• Experience with advanced cyber assessment, scanning, and STIG automation tools.
• Familiarity with Zero Trust, MLS/MILS concepts, cross domain security, and secure cloud/container architectures.
• Strong documentation, communication, and coordination habits aligned with RMF evidence and cyber governance workflows.
Target salary range: $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.
Overview
SAIC accepts applications on an ongoing basis and there is no deadline.