Security Lead / Release Lead (REMOTE)
Koniag Government Services · Chantilly, VA · Yesterday
ManagementFull-time
About the role
Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Security Lead / Release Lead with a Secret security clearance to support KITS and our government customer. The position is remote.
Responsibilities
- Serve as the primary security subject matter expert (SME) for the ICAM enablement program, providing authoritative guidance on applicable DoD and federal security requirements, policies, and frameworks across all program activities and deliverables.
- Develop, implement, and maintain the program's security compliance framework, ensuring all enablement activities, platform configurations, custom tools, connectors, middleware solutions, and integration artifacts adhere to applicable security standards including DoDI 8520.04, DoDM 8140.03, DFARS 252.204-7012, NIST SP 800-171, and all other referenced DoD and federal directives.
- Oversee and enforce Controlled Unclassified Information (CUI) handling requirements across the program, ensuring all personnel, processes, and systems comply with DoDI 5200.48, DoDM 5200.01, and applicable CUI marking, safeguarding, and dissemination requirements.
- Manage Operations Security (OPSEC) requirements across the program, ensuring OPSEC principles are incorporated into all relevant program activities, documentation, and communications in accordance with applicable DoD directives, and ensuring all subcontractors handling Critical Information comply with flowed-down OPSEC requirements.
- Lead supply chain risk management activities per DFARS 239.73, overseeing the vetting of all third-party connectors, scripts, code libraries, and enhancements integrated into the ICAM environment to prevent the introduction of cybersecurity vulnerabilities, malicious code, or unauthorized data exfiltration pathways.
- Ensure all contractor personnel maintain required DoD cybersecurity certifications per DoDM 8140.03, tracking certification status across the program team and coordinating remediation for personnel with lapsed or insufficient certifications.
- Develop, implement, and manage the program release management framework, establishing standardized processes, approval gates, documentation requirements, and rollback procedures for all releases into development, test, and production environments.
- Serve as the release authority for all production deployments, coordinating release readiness reviews with the migration team lead, platform engineers, middleware engineers, and Government stakeholders to ensure all release criteria are met prior to deployment authorization.
- Manage and oversee the configuration management process across the program, ensuring all platform configurations, custom tools, connectors, integration artifacts, and documentation are version-controlled, baselined, and maintained in accordance with the program's configuration management plan.
- Lead deficiency reporting, analysis, tracking, and resolution activities across the program, ensuring all deficiencies are identified, documented, tracked, and resolved in accordance with applicable technical orders and reporting requirements, including preparation of SF368 reports or equivalent.
- Cover security-related matters with the Government COR and ICAM PMO, including incident reporting, vulnerability disclosures, cybersecurity certification status, and security compliance findings.
- Ensure all web-based applications, user interfaces, and digital materials enabled or developed under the contract comply with Section 508 of the Rehabilitation Act of 1973, coordinating accessibility reviews and remediation activities as needed.
- Support the test program by integrating security testing requirements into the Master Test Plan and Software Test Plans, ensuring security-relevant test cases are included in all integration testing and UAT activities, and reviewing Software Test Reports for security compliance findings.
- Oversee data rights compliance across the program, ensuring all custom tools, connectors, workflows, enhancements, and documentation developed under the contract are properly identified, marked, and delivered in accordance with DFARS 252.227-7013, 252.227-7014, and 252.227-7017.
- Maintain current knowledge of evolving DoD security policies, cybersecurity frameworks, identity security standards, and Zero Trust requirements, proactively applying updated knowledge to strengthen program security posture and release controls.
- Develop and maintain security and release management documentation, including security compliance checklists, release readiness criteria, configuration management records, deficiency logs, and OPSEC plans.
- Provide security awareness guidance and compliance coaching to program team members, ensuring all personnel understand and adhere to applicable security requirements throughout the enablement lifecycle.
Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field from an accredited college or university.
- Minimum of 7 years of experience in information technology, with at least 3 years of direct experience in IT security compliance, cybersecurity program management, or a related security discipline within a federal government environment.
- Minimum of 2 years of experience in release management, configuration management, or IT change management within a structured federal IT program environment.
- Demonstrated experience applying DoD cybersecurity frameworks, policies, and directives including DFARS 252.204-7012, DoDM 8140.03, NIST SP 800-171, and CUI requirements in a program execution context.
- Active Secret clearance. Must be able to satisfy requirements for CAC-card issuance and NIPRNet access, including annual DoD CyberAwareness training and certification.
Skills and Competencies
- Deep knowledge of applicable DoD and federal security requirements, policies, and frameworks, including DoDI 8520.04, DoDM 8140.03, DFARS 252.204-7012, DFARS 239.73, DoDI 5200.48, DoDM 5200.01, NIST SP 800-171, and related directives.
- Strong working knowledge of Controlled Unclassified Information (CUI) requirements, including marking, safeguarding, dissemination controls, aggregation monitoring, and compliance with applicable DoD and federal CUI directives.
- Demonstrated experience managing release management processes in a federal IT program environment, including the development and enforcement of release readiness criteria, approval gates, change control procedures, and rollback plans.
- Familiarity with Identity, Credential, and Access Management (ICAM) security concepts, including identity providers (IdP), identity governance and administration (IGA), Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Zero Trust identity security principles.
- Experience conducting or overseeing supply chain risk management activities, including the security vetting of third-party code libraries, connectors, and software components integrated into federal IT environments.
- Experience with deficiency reporting processes, including preparation of SF368 reports or equivalent, deficiency tracking, and resolution coordination in a federal contracting environment.
- Demonstrated ability to coordinate security compliance activities across cross-functional teams, including engineers, program managers, and Government stakeholders.
- Strong organizational skills with the ability to manage multiple concurrent security and release management workstreams while maintaining accuracy, thoroughness, and timeliness of all compliance documentation.
- Strong communication skills in English—both written and oral—with the ability to clearly convey security requirements, compliance findings, and release management processes to both technical engineers and non-technical program stakeholders.
- Proficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams.
- Active DoD cybersecurity certification at the IAT II level or above per DoDM 8140.03 (e.g., CompTIA Security+ or equivalent).