Job DescriptionWarCollar Industries is seeking an experienced Technical Lead to support the National Telecommunications and Information Administration (NTIA) in conducting High Value Asset (HVA) cybersecurity assessments. The Technical Lead will serve as the primary technical authority for Non-Tier 1 HVA assessments, leading technical assessment activities, coordinating technical discussions with stakeholders, evaluating security controls, identifying vulnerabilities and gaps, and developing comprehensive technical assessment reports.
The Technical Lead will work across Risk and Vulnerability Assessments (RVA), Security Architecture Reviews (SAR), and System Security Engineering (SSE) activities. This position requires strong experience in cloud architecture, cybersecurity, security assessment methodologies, technical analysis, and the ability to translate complex technical findings into clear, actionable recommendations.
Required SkillsKey Responsibilities- Serve as the primary technical lead for Non-Tier 1 HVA cybersecurity assessments.
- Develop and execute technical approaches for HVA assessment activities.
- Lead Technical Exchange Meetings (TEMs), technical interviews, demonstrations, and other technical discussions with government stakeholders.
- Review system documentation and identify security controls and technical requirements applicable to in-scope HVA environments.
- Design, coordinate, and/or direct technical security scans, testing, and assessment activities.
- Conduct technical evaluations of cybersecurity controls and perform detailed gap analyses.
- Assess threats, vulnerabilities, security configurations, and potential risks across HVA environments.
- Support Risk and Vulnerability Assessment activities, including penetration testing, network mapping, vulnerability scanning, phishing assessments, wireless assessments, web application assessments, operating system security assessments, and database assessments.
- Support Security Architecture Reviews through architecture design reviews, system configuration reviews, log analysis, and network traffic analysis.
- Provide Systems Security Engineering support throughout the system development lifecycle.
- Evaluate proposed operational modifications and identify alternative technical solutions.
- Conduct end-to-end architecture tradeoff assessments and provide recommendations for reducing cybersecurity risk.
- Support the development of strategic and tactical plans, implementation strategies, and security standards.
- Investigate and evaluate emerging technologies for potential implementation within HVA environments.
- Develop technical assessment reports documenting findings, risks, vulnerabilities, control gaps, impacts, and recommended remediation actions.
- Communicate technical findings and assessment results to the Assessment Lead (AL), government stakeholders, and other members of the assessment team.
- Lead technical team members and mentor Operators performing hands-on assessment activities.
- Review and validate technical evidence, including system configurations, logs, screenshots, scan results, and other assessment artifacts.
- Support assessment meetings, status meetings, Technical Exchange Meetings, and assessment out-briefs.
- Provide technical responses and clarification to stakeholder questions throughout assessment and report-review cycles.
- Ensure assessment activities and deliverables align with applicable federal cybersecurity requirements, HVA assessment methodologies, and NTIA requirements.
- Contribute to timely, accurate, and complete assessment deliverables throughout the performance period.
Required Qualifications- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field.
- Minimum of 8 years of experience in Cloud Architecture and Cybersecurity.
- Demonstrated experience conducting cybersecurity assessments, security architecture reviews, vulnerability assessments, or related security engineering activities.
- Experience evaluating cybersecurity controls and performing technical gap analyses.
- Experience reviewing system architectures, configurations, logs, and network traffic.
- Experience developing technical cybersecurity assessment reports and presenting technical findings to stakeholders.
- Strong understanding of cybersecurity threats, vulnerabilities, attack methodologies, and security controls.
- Strong technical communication, analytical, and problem-solving skills.
- Cybersecurity, Cloud Architecture, Security Engineering, or similar professional certification.
- Ability to obtain and maintain a Department of Commerce Secret clearance.
Desired SkillsDesired Qualifications- Experience supporting Federal High Value Asset (HVA) cybersecurity assessments.
- Experience with Risk and Vulnerability Assessments (RVA), Security Architecture Reviews (SAR), and/or Systems Security Engineering (SSE).
- Experience with penetration testing, vulnerability scanning, network mapping, web application security, wireless security, operating system security, and database security assessments.
- Experience with federal cybersecurity standards and frameworks, including NIST SP 800-series guidance, FISMA, FIPS 199/200, and OMB A-130.
- Knowledge of Zero Trust cybersecurity principles and federal cybersecurity requirements.
- Experience supporting cloud security architecture and engineering.
- CISSP, cloud security, security engineering, or comparable certifications.
- Experience working directly with federal government cybersecurity and IT stakeholders.
Additional DetailsSecurity RequirementThis position requires a minimum of a Secret security clearance. An interim Secret clearance is acceptable to begin work, subject to applicable government requirements.