Cybersecurity Lead - ISSM
SAIC · Beale Air Force Base, CA · 1 wk ago
Engineering$160k–$200k/yrFull-time
Job Duties
- Embed JSIG, NIST SP 800‑53, STIG, and RMF controls into CMCC environments and capability onboarding workflows.
- Own RMF/ATO packages for CMCC Dev/Integration/Test environments; maintain SSP/POA&M/Continuous Monitoring artifacts.
- Lead CMCC cyber governance validate CP and External cyber artifacts, ensure technical completeness, and coordinate readiness for Infrastructure TO baseline updates.
- Provide hands‑on technical support to Cloud and DSOP cyber engineers during complex tasks, troubleshooting, or environment build‑outs.
- Represent Cyber on ARB/CCB and provide cyber recommendations for environment promotion gates.
- Review and adjudicate STIG, SAST/DAST, ACAS/Nessus, and cloud/pipeline vulnerabilities; coordinate remediation across DSOPS, Platform, Cloud, CE, and CP teams.
- Identify systemic cyber gaps early and lead corrective‑action plans aligned to mission objectives.
- Ensure MLS/MILS boundary compliance and alignment with CMCC multi‑tenant security patterns.
- Mentor and develop the Cyber team; reinforce communication expectations, WHY behind requirements, active participation, vector checks, and accountability.
Qualifications
- Bachelors and fourteen (14) years or more experience; Masters and twelve (12) years or more experience; PhD or JD and nine (9) years or more experience .
- Expert knowledge of RMF and cybersecurity governance across diverse enclaves.
- Experience with Xacta, STIGs, OWASP tooling, and ACAS/Nessus vulnerability adjudication.
- DoD 8140‑aligned certifications such as CISSP, CCSP, GIAC Security Engineer (GSE), CASP+, or equivalent.
Desired Qualifications And Experience
- Experience validating JSIG requirements and NIST SP 800‑53 controls across development, integration, and test environments.
- Background in cloud and container security.
- Prior leadership experience building, developing, and mentoring cyber teams.
Desired Skills And Certifications
- Experience with advanced cyber assessment, scanning, and STIG automation tools.
- Familiarity with Zero Trust, MLS/MILS concepts, cross domain security, and secure cloud/container architectures.
- Strong documentation, communication, and coordination habits aligned with RMF evidence and cyber governance workflows.