Cyber Security Lead
Concept-Plus
About Concept Plus
Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm.
Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty.
We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment.
Concept Plus LLC is seeking an experienced Cybersecurity Lead to plan, implement, upgrade, and monitor security measures for the protection of all common services and cloud environments in support of an Oracle eBusiness, OCI hosted common services program. In this role, you will ensure appropriate security controls are in place to safeguard digital files and vital electronic infrastructure hosted on the Cloud One Oracle Cloud Infrastructure (OCI) platform and will serve as the contractor's primary ISSO responsible for maintaining the program's Authorization to Operate (ATO), managing the DoD Risk Management Framework (RMF) lifecycle, and sustaining SOC 1 Type 2 audit readiness. You will respond to computer security breaches, vulnerabilities, and incidents affecting the environment and embed security practices throughout the DevSecOps pipeline. A CISSP certification or higher, and demonstrated RMF experience are required. An active Secret clearance is required to start.
What you'll do
- Plan, implement, upgrade, and continuously monitor security measures for the protection of all networks, systems, data, and cloud infrastructure operating within the Cloud One OCI authorization boundary
- Serve as the contractor ISSO, owning the DoD RMF package lifecycle including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring for all information systems
- Ensure appropriate security controls are in place and operating effectively to safeguard digital files, financial management data, and vital electronic infrastructure across all environments, in compliance with NIST SP 800-53, DISA STIGs, and applicable Cloud One security requirements
- Lead and coordinate the ATO process with the Authorizing Official (AO), Security Control Assessor (SCA), and ISSM; maintain and update the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and all associated RMF artifacts on a continuous basis
- Detect, respond to, and document cybersecurity incidents, breaches, and vulnerabilities affecting environments; coordinate with DISA, Cloud One, and the Government ISSM as required for incident reporting and remediation
- Support SOC 1 Type 2 audit compliance for Federal Financial Management systems migrating to OCI, providing control evidence, audit artifacts, and liaison support to external auditors
- Collaborate with the DevSecOps Lead to embed security scanning (SAST, DAST, container image scanning) and RMF control validation into CI/CD pipelines for continuous ATO compliance
- Maintain the enterprise security posture across all environments, conducting regular vulnerability assessments, reviewing ACAS/SCAP scan results, and tracking remediation to closure within approved timelines
- Monitor security controls and system configurations for compliance with applicable STIGs, CCIs, and Cloud One security policies; generate and track POA&M items to resolution
- Advise the Program Manager and Technical Lead on cybersecurity risk, control gaps, and security architecture decisions, including OCI-native security services (Cloud Guard, Security Zones, OCI Vault, Bastion)
- Support the development and maintenance of security-related deliverables including Security/RMF Artifacts, DR/COOP security design documentation, and recurring posture reports
- Ensure near real-time Production-to-DR/COOP data replication and failover configurations meet security and data protection requirements
- Coordinate foreign ownership, control, and influence (FOCI) considerations and organizational conflict of interest (COI) disclosures with program leadership as required
- Support cybersecurity awareness and training to program team members and support security-related onboarding for all incoming personnel
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related technical field
- 5+ years of progressive information security experience in a DoD or Federal environment, including direct experience as an ISSO or equivalent role
- Active CISSP (Certified Information Systems Security Professional) or higher relevant certification required at time of hire
- Demonstrated, hands-on experience managing the DoD Risk Management Framework (RMF) lifecycle, including SSP development, control assessment, POA&M management, and ATO maintenance
- Experience implementing, upgrading, and monitoring security measures for the protection of computer networks and information systems, including ensuring appropriate controls are in place to safeguard digital files and electronic infrastructure
- Experience responding to computer security breaches, vulnerabilities, and incidents in a DoD or Federal environment
- Familiarity with NIST SP 800-53, DISA STIGs, SCAP/ACAS scanning tools, and cloud security controls applicable to FedRAMP/DoD cloud environments
- Active DoD Secret clearance required to start; must be maintainable for the duration of the program
Preferred Qualifications
- Active Top Secret (TS) security clearance; candidates holding an active TS clearance will be given strong preference as the program's operational scope and data sensitivity may require TS access
- Experience as an ISSO for systems operating within a DISA-managed or Cloud One environment, including familiarity with IL4/IL5 authorization requirements and Cloud One tenancy security controls
- Hands-on experience with OCI security services including Cloud Guard, Security Zones, OCI Vault, Network Security Groups (NSGs), and OCI Bastion
- Experience supporting SOC 1 Type 2 audits for Federal Financial Management systems, including evidence collection, auditor liaison, and FISCAM/FFMIA compliance familiarity
- Familiarity with Oracle eBusiness Suite (eBS), Oracle Fusion Middleware, or Oracle database security hardening and patching
- Experience with STIG implementation and automated compliance scanning for Oracle database and middleware products
- Additional DoD 8140/8570 IAM-level certifications (e.g., CISM, GSLC, CCISO) or IAT-level certifications (e.g., CASP+ CE, CISA) are a strong plus
- Familiarity with the DoD Enterprise Services Management Framework (DESMF) and service management security considerations
- Prior experience supporting AFLCMC, BES Directorate, or a DoD ERP program of record
Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.
#J-18808-Ljbffr$141.92k - $212.89k
...is the largest independent regulator of securities firms doing business in the United States... ...? As a Senior Principal Risk Specialist, Cyber Engagements, you'll play a pivotal role in... ...evolving cyber threats. You'll design and lead immersive tabletop exercises and...SuggestedFull timeTemporary workFor contractorsFor subcontractorLocal areaImmediate start- ...We’re actively seeking a talented Senior Security Engineer to join the Engineering department... ..., assessing, and communicating cyber and IT risks to support effective enterprise... ...Working closely with the Engineering Service Lead and Service Manager, you'll help shape service...SuggestedFull timeWork at officeRemote workFlexible hours
$185k - $225k
...direct responsibility for pricing and portfolio management of all Cyber Reinsurance business written across the globe through offices in... ....Role Factors:In this role, you will typically be required to:• Lead pricing across Cyber Reinsurance, with responsibility for new...SuggestedFull timeWorldwide$143k - $224k
About this role: Wells Fargo is seeking a Cyber Behavioral Defense Lead (Lead Information Security Analyst), as part of the Technology Management and Strategy team.Learn more about the career areas and lines of business at wellsfargojobs.com.You will serve as the lead...SuggestedFull timeWork experience placement- Staples Digital Solutions is strengthening its cyber defense capabilities, and we’re looking... ...environment. This role sits within Cyber Security and partners closely with Security... ...enterprise.As a Cyber Security Incidence Response Lead, you’ll serve as a senior technical...SuggestedWork experience placementLocal areaRelocationRelocation package
$50 per hour
...ProfessionalFT/PT/Casual: FullTimeDepartment: RMS CoreBusiness Unit: RMS CoreStandard Job Description"This Classified Cyber Security Asc Manager/Lead Information System Security Officer (ISSO) position will support the Information System Security Manager (ISSM) as an additional...Full timeTemporary workWork experience placementCasual workFlexible hoursShift workDay shift$125k - $190k
...impactful results that strengthen missions and drive lasting value. ResponsibilitiesLMI is seeking a skilled ISSM / RMF Lead to manage information systems security and Risk Management Framework (RMF) activities across a network of technical communications facilities. This...Full time$50 per hour
...Doing:Lockheed Martin’s, Rotary & Mission Systems (LM RMS), F-35 Cyber Security invites you to step up to one of today’s most daunting challenges: the protection of exquisite government capabilities leading to warfighter supremacy against our peer and near peer...Full timeTemporary workWork experience placementCasual workFlexible hoursShift workDay shift$170.4k - $255.6k
...TennesseeThe Senior Principal Cybersecurity Specialist will lead Medtronic’s Security Culture function, driving enterprise-wide cybersecurity... ...engagement programs. This role focuses on reducing human-related cyber risk through education, behavior change, and strategic...Full timeH1bWork at officeLocal areaImmediate startFlexible hours$120k - $202.5k
The Cyber Policy Enforcement Lead, VP is responsible for leading the enterprise capability that ensures Cyber Policies and Standards are consistently... ...preferred, such as:CISSP (Certified Information Systems Security Professional)CISM (Certified Information Security Manager...Full timeTemporary workFlexible hours$113k - $190k
...oversight, with primary responsibility for leading and managing the company’s Systems and... ...as a SOC 2 leader, contributes to broader cyber risk oversight, recommending and monitoring... ...of SOC 2 Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality...Full timeRemote work- ...Phase2 Technology is seeking a Cyber Incident Response Business Development Senior Manager to lead business growth efforts. This role requires experience in business development and incident response, focusing on building strategic relationships and identifying new opportunities...
$76 - $76.9 per hour
A leading consulting firm is seeking an experienced Cyber Security Analyst - Lead for a 4-month contract with potential for extension. This remote position involves managing API security requests, coordinating with development teams, and utilizing DAST/SAST tools for vulnerability...Contract workRemote work- ...Booz Allen is seeking a Cyber Incident Response Business Development Senior Manager to drive growth in their incident response business. You will engage with stakeholders and manage strategic partner relationships while contributing to innovative solutions in a dynamic...
$112k - $179k
ResponsibilitiesPeraton is seeking a Cyber Threat Team Lead in our Linthicum, MD office in support of our Department of Defense (DoD) customer... ...candidate will contribute to protecting national security interests by leveraging technical expertise, analytical skills...Contract workWork at officeShift work- ...Phase2 Technology is looking for a Cyber Incident Response Business Development Senior Manager to lead and grow its Incident Response business. This role involves driving business development initiatives, engaging key stakeholders, and managing strategic partner relationships...Work at officeRemote work
- ...Phase2 Technology is seeking a Cyber Incident Response Business Development Senior Manager to lead the growth of our Incident Response business. This role will engage key stakeholders, maintain relationships, and drive the business development process through strategic...
$195k - $262.7k
...A financial technology company is seeking a Sr. Manager, Cyber Threat Researcher to leverage cyber threat intelligence. The position involves creating detection mechanisms and maintaining expertise in current threat landscapes. Ideal candidates should have extensive experience...Remote work- MITRE is seeking an Operational Technology (OT) Cyber Threat Intelligence Lead to bridge OT threat intel and automated adversary emulation. You will analyze adversary TTPs affecting ICS, SCADA, and Space OT, translating findings into operational behaviors for deployment...
$105.05k - $161.8k
Cyber Engagement Program Lead We are seeking a highly motivated Cybersecurity Engineer with 5-7 years of experience in enterprise security architecture, process transformation and AI-driven security solutions. This role requires an individual who can understand cybersecurity...Full timeTemporary workLocal areaRelocationFlexible hoursShift work- Steampunk in McLean, VA seeks a Cyber Risk Management Specialist to lead RMF/A&A activities and ensure FedRAMP compliance across cloud environments. The role focuses on implementing security controls, conducting continuous monitoring, and coordinating with 3PAO and auditors...
$100k - $140k
...bring 5+ years of experience in Information Security and Privacy, including establishing... ...conflicts and maintain efficiency. We lead crisis response during major breaches, supporting... ...motivated, career- and customer-oriented Cyber Security Task Lead to join our team in...Full timeContract workFor contractorsFor subcontractorWork at office- NVIDIA is seeking a Cybersecurity Analyst to lead incident response across corporate, cloud, and product environments. You will perform... ..., and digital forensics to accelerate detections and strengthen security posture. Collaborate with engineering and security teams to...
- ...Regulatory Authority, Inc. is seeking a Senior Principal Risk Specialist - Cyber Engagements in Rockville, MD. This role is central to reinforcing cybersecurity resilience across the financial sector by leading tabletop exercises that simulate real-world incidents. Qualified...
- ...is the largest independent regulator of securities firms in the U.S. It protects investors... ...As a Senior Principal Risk Specialist - Cyber Engagements, you will strengthen the industry... ...evolving cyber threats by designing and leading immersive tabletop exercises and...Local area
- Everforth ECS seeks a Cyber Solution Area Lead to shape and drive the cyber strategy across the federal market, translating technical capabilities into repeatable solutions and sustained growth. Based in Fairfax, VA, you will mobilize leaders across the company to win...
$275k - $350k
...ECS is seeking a Job Description Everforth ECS is seeking a Cyber Solution Area Lead to work in our Fairfax, VA office. The Cyber Solution Area... ...such as Zero Trust, identity and access management, cloud security, network security, cyber operations, vulnerability management...Work at officeLocal area$155k - $180k
...strengthen and protect our nation’s vital interests. Title : Cyber Threat Intelligence Lead Clearance : Active Top Secret with SCI eligibility,... ...in cyber threat analysis to develop and operate cyber security capabilities for a Cybersecurity Operation Center (CSOC)...Relocation package- ...Cyber Security Cluster Lead Food Manufacturing Richmond, Virginia(On-Site) (Full Time) Job Description: Position Overview We are seeking a Cyber Security Cluster Lead with strong experience in manufacturing automation, controls systems, infrastructure...Full timeLocal area
- ...Job Description Job Description Description: Client Solution Architects (CSA) is currently seeking a NST/Cyber Security Lead to support our program at Fort Leavenworth, KS. For nearly 50 years, CSA has delivered integrated technology and operational support services...Contract workTemporary workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security Lead. Be the first to apply!
- cyber security lead United States
- senior manager cyber security United States
- cyber security project manager United States
- cybersecurity project manager United States
- cybersecurity manager United States
- cyber security program manager United States
- cyber security account manager United States
- director - cyber security United States
- cyber threat intelligence analyst United States
- cyber sales United States


