Cyber Security Lead
Concept Plus LLC
About Concept Plus Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm. Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty. We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment. For more information, visit About the role Concept Plus LLC is seeking an experienced Cybersecurity Lead to plan, implement, upgrade, and monitor security measures for the protection of all common services and cloud environments in support of an Oracle eBusiness, OCI hosted common services program. In this role, you will ensure appropriate security controls are in place to safeguard digital files and vital electronic infrastructure hosted on the Cloud One Oracle Cloud Infrastructure (OCI) platform and will serve as the contractor's primary ISSO responsible for maintaining the program's Authorization to Operate (ATO), managing the DoD Risk Management Framework (RMF) lifecycle, and sustaining SOC 1 Type 2 audit readiness. You will respond to computer security breaches, vulnerabilities, and incidents affecting the environment and embed security practices throughout the DevSecOps pipeline. A CISSP certification or higher, and demonstrated RMF experience are required. An active Secret clearance is required to start. What you'll do
Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.
- Plan, implement, upgrade, and continuously monitor security measures for the protection of all networks, systems, data, and cloud infrastructure operating within the Cloud One OCI authorization boundary
- Serve as the contractor ISSO, owning the DoD RMF package lifecycle including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring for all information systems
- Ensure appropriate security controls are in place and operating effectively to safeguard digital files, financial management data, and vital electronic infrastructure across all environments, in compliance with NIST SP 800-53, DISA STIGs, and applicable Cloud One security requirements
- Lead and coordinate the ATO process with the Authorizing Official (AO), Security Control Assessor (SCA), and ISSM; maintain and update the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and all associated RMF artifacts on a continuous basis
- Detect, respond to, and document cybersecurity incidents, breaches, and vulnerabilities affecting environments; coordinate with DISA, Cloud One, and the Government ISSM as required for incident reporting and remediation
- Support SOC 1 Type 2 audit compliance for Federal Financial Management systems migrating to OCI, providing control evidence, audit artifacts, and liaison support to external auditors
- Collaborate with the DevSecOps Lead to embed security scanning (SAST, DAST, container image scanning) and RMF control validation into CI/CD pipelines for continuous ATO compliance
- Maintain the enterprise security posture across all environments, conducting regular vulnerability assessments, reviewing ACAS/SCAP scan results, and tracking remediation to closure within approved timelines
- Monitor security controls and system configurations for compliance with applicable STIGs, CCIs, and Cloud One security policies; generate and track POA&M items to resolution
- Advise the Program Manager and Technical Lead on cybersecurity risk, control gaps, and security architecture decisions, including OCI-native security services (Cloud Guard, Security Zones, OCI Vault, Bastion)
- Support the development and maintenance of security-related deliverables including Security/RMF Artifacts, DR/COOP security design documentation, and recurring posture reports
- Ensure near real-time Production-to-DR/COOP data replication and failover configurations meet security and data protection requirements
- Coordinate foreign ownership, control, and influence (FOCI) considerations and organizational conflict of interest (COI) disclosures with program leadership as required
- Support cybersecurity awareness and training to program team members and support security-related onboarding for all incoming personnel
- US Citizen
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related technical field
- 5+ years of progressive information security experience in a DoD or Federal environment, including direct experience as an ISSO or equivalent role
- Active CISSP (Certified Information Systems Security Professional) or higher relevant certification required at time of hire
- Demonstrated, hands-on experience managing the DoD Risk Management Framework (RMF) lifecycle, including SSP development, control assessment, POA&M management, and ATO maintenance
- Experience implementing, upgrading, and monitoring security measures for the protection of computer networks and information systems, including ensuring appropriate controls are in place to safeguard digital files and electronic infrastructure
- Experience responding to computer security breaches, vulnerabilities, and incidents in a DoD or Federal environment
- Familiarity with NIST SP 800-53, DISA STIGs, SCAP/ACAS scanning tools, and cloud security controls applicable to FedRAMP/DoD cloud environments
- Active DoD Secret clearance required to start; must be maintainable for the duration of the program
- Active Top Secret (TS) security clearance; candidates holding an active TS clearance will be given strong preference as the program's operational scope and data sensitivity may require TS access
- Experience as an ISSO for systems operating within a DISA-managed or Cloud One environment, including familiarity with IL4/IL5 authorization requirements and Cloud One tenancy security controls
- Hands-on experience with OCI security services including Cloud Guard, Security Zones, OCI Vault, Network Security Groups (NSGs), and OCI Bastion
- Experience supporting SOC 1 Type 2 audits for Federal Financial Management systems, including evidence collection, auditor liaison, and FISCAM/FFMIA compliance familiarity
- Familiarity with Oracle eBusiness Suite (eBS), Oracle Fusion Middleware, or Oracle database security hardening and patching
- Experience with STIG implementation and automated compliance scanning for Oracle database and middleware products
- Additional DoD 8140/8570 IAM-level certifications (e.g., CISM, GSLC, CCISO) or IAT-level certifications (e.g., CASP+ CE, CISA) are a strong plus
- Familiarity with the DoD Enterprise Services Management Framework (DESMF) and service management security considerations
- Prior experience supporting AFLCMC, BES Directorate, or a DoD ERP program of record
Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Cyber Security Lead in United States vacancy
$141.92k - $212.89k
...is the largest independent regulator of securities firms doing business in the United States... ...? As a Senior Principal Risk Specialist, Cyber Engagements, you'll play a pivotal role in... ...evolving cyber threats. You'll design and lead immersive tabletop exercises and...SuggestedFull timeTemporary workFor contractorsFor subcontractorLocal areaImmediate start$76 - $76.9 per hour
...Cyber Security Analyst - Lead Immediate need for a talented Cyber Security Analyst - Lead. This is a 04 months contract opportunity with long-term potential and is located in NC, GA, FL, VA, SC (Remote). Pay Range: $76 - $76.90/hour. Employee benefits include, but...SuggestedContract workLocal areaImmediate startRemote work$113.84k - $170.76k
...ProfessionalCompany: CitiAs the Business Command Center (BCC) Major Incident/Cyber Lead, you will play a critical role in ensuring the stability and... ...events and incidents in close coordination with Information Security, Business, and Technology partners.Represent the BCC and the...SuggestedFull time- ...We’re actively seeking a talented Senior Security Engineer to join the Engineering department... ..., assessing, and communicating cyber and IT risks to support effective enterprise... ...Working closely with the Engineering Service Lead and Service Manager, you'll help shape service...SuggestedFull timeWork at officeRemote workFlexible hours
$160.2k - $241.85k
Cyber Threat Intelligence Leads (Western Union, LLC, Denver, CO)Determine threat intelligence focus areas and analytical approaches based on business... ...and domestic offices for in-person work with various security and technology teams to further evangelize the Cyber Threat...SuggestedFull timeTemporary workWork at officeRemote workWork from homeFlexible hours2 days per week3 days per week$175k - $200k
...difference? At Danaher, you can build an incredible career at a leading science and technology company, where we’re committed to... ...Business System which makes everything possible.The Principal Cyber Security Architecture Lead will provide strategic leadership for a team...Full timeRemote workWork from homeFlexible hoursNight shift- ...Cyber Security Analyst Lead – Cyber Threat Hunting FIS Management Services, LLC seeks Cyber Security Analyst Leads – Cyber Threat Hunting in Jacksonville, FL to serve as a technical lead within FIS Cyber Threat Hunting (CTH) program, driving proactive, hypothesis-based...Remote workWork from home
$134.5k - $265.1k
Position Summary Deloitte’s Cyber Services help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber... ...Resilience offerings. Responsibilities Experience in leading the full lifecycle of Cyber incident response, manage...Local areaVisa sponsorship$112k - $179k
ResponsibilitiesPeraton is seeking a Cyber Threat Team Lead in our Linthicum, MD office in support of our Department of Defense (DoD) customer... ...candidate will contribute to protecting national security interests by leveraging technical expertise, analytical skills...Contract workWork at officeShift work$120k - $202.5k
The Cyber Policy Enforcement Lead, VP is responsible for leading the enterprise capability that ensures Cyber Policies and Standards are consistently... ...preferred, such as:CISSP (Certified Information Systems Security Professional)CISM (Certified Information Security Manager...Full timeTemporary workFlexible hours- ...Booz Allen is seeking a Cyber Incident Response Business Development Senior Manager to drive growth in their incident response business. You will engage with stakeholders and manage strategic partner relationships while contributing to innovative solutions in a dynamic...
$76 - $76.9 per hour
A leading consulting firm is seeking an experienced Cyber Security Analyst - Lead for a 4-month contract with potential for extension. This remote position involves managing API security requests, coordinating with development teams, and utilizing DAST/SAST tools for vulnerability...Contract workRemote work- ...Title: Cyber Security Location: Long Island (Remote) Job Description: We are seeking a seasoned Cyber Security professional to lead the development and implementation of the organization's enterprise information security strategy and Compliance....Remote work
- ...Cyber Security Specialist - EU This is a remote position with some travel (10 - 15%) with a Global highly respected service provider who... ...skills, behaviours, and approaches to be an effective Security Lead, e.g., security-minded, curious, investigative, persevering,...Remote work
- Trinnex is seeking a Senior Cyber Security Analyst to join its Security Team and safeguard software used in water utilities and infrastructure. You will embed security into the SDLC, lead threat detection, vulnerability management, and secure development practices across...
$154.05k - $278.48k
...Description Leidos has an exciting opportunity for Cyber Security Engineer—Technical Lead in our Intel Security Sector's Analysis Solutions Business Area . Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO), Mission...Local areaImmediate startFlexible hours- ...Cyber Security Tower Lead Location: Atlanta, GA (onsite) Duration: 6+ Month Experience/Role: Responsible for the day-to-day operations of the Cyber Security team and the Enterprise Infrastructure security tools like Firewalls, email security etc., security event monitoring...Full timePart timeFor contractors
- ...Rackspace Technology is seeking a Senior Cyber Security Manager to lead a technical cybersecurity team and own the security tool portfolio, including EDR, NDR, IDPS, vulnerability scanners, and cloud security tooling. You will oversee exposure management, telemetry quality...
$155k - $180k
...strengthen and protect our nation’s vital interests. Title : Cyber Threat Intelligence Lead Clearance : Active Top Secret with SCI eligibility,... ...in cyber threat analysis to develop and operate cyber security capabilities for a Cybersecurity Operation Center (CSOC)...Relocation package- A prominent cyber security firm is seeking a Senior Cyber Security Consultant. This role involves leading security teams, implementing government standards, and managing risk across various projects. The ideal candidate should have strong foundations in security assurance...Flexible hours
- Accenture Federal Services is seeking a Cyber Threat Hunt Lead in Arlington, Virginia. This role involves leading a specialized team to identify... .... Candidates should have over 5 years of experience in security monitoring and relevant certifications. The company offers...
- Grant Thornton is seeking a Cyber Strategy & Management Manager to apply cybersecurity capabilities across governance, risk, strategy,... ...and incident response for our Cyber & Privacy Practice. You will lead client engagements, assess architectures, and deliver strategic...
- General Dynamics Information Technology seeks a Deputy Program Manager to drive cyber exercise planning, execution, and analysis for a DHS program. You will design realistic scenarios, coordinate with federal partners, and produce insights to strengthen national cybersecurity...
- The Estée Lauder Companies Inc. in New York City is seeking a CTR Lead to coordinate incident response, investigate threats, and guide containment, remediation, and recovery during active security events. You will collaborate with Security Operations, IT, Legal, Privacy...
- Prestige Staffing is seeking a highly skilled Senior Detection and Response Analyst to join a cybersecurity team supporting regional security operations. The role involves maintaining 24x7 monitoring, threat analysis, incident triage, and contributing to the overall...Remote job
- Capital One is seeking a Senior Associate in Cyber Risk & Analysis for Retail Bank. This role focuses on end‑to‑end management of the... .... You will partner across lines of business to maintain security and risk posture. The position requires a Bachelor’s degree and...
- Mizuho is seeking a Cyber Security Advisory Lead to act as the trusted security advisor across business and technology leadership. You will embed security into decision-making from strategy through delivery, guiding risk decisions, secure‑by‑design guidance, and regulatory...
- Phase2 Technology is seeking a Cyber Incident Response Business Development Senior Manager to lead business growth efforts. This role requires experience in business development and incident response, focusing on building strategic relationships and identifying new opportunities...
- Revolutional seeks a Lead Cyber Threat Intelligence Analyst to oversee the CTI function for a federal enterprise cybersecurity program. You will identify threats across classified and unclassified streams, craft risk mitigation guidance, and deliver classified briefings...
- The Ohio Adjutant General’s Department seeks an Agency Information Security Professional 2 in Columbus to help secure agency networks and systems. You will plan, implement, upgrade, and monitor security measures while communicating complex concepts to diverse audiences...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security Lead. Be the first to apply!
Related searches
- cyber security account manager United States
- cybersecurity project manager United States
- cybersecurity manager United States
- cyber security project manager United States
- cyber security program manager United States
- senior manager cyber security United States
- cyber security lead United States
- director - cyber security United States
- cyber sales United States
- cyber forensics United States


