Security Assessment Lead
OCH Technologies LLC
Security Assessment Lead
OCH Technologies is seeking a Security Assessment Lead to act as the technical authority for all independent risk assessments, vulnerability assessments, and analyses of alternatives conducted under this contract. The candidate will lead assessment planning, assign and mentor assessment teams, ensures assessment execution follows NIST 800-53A methodology, and is accountable for the quality and completeness of all System Security Assessment Reports (SARs) delivered.
This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.
Location: Hybrid – FAA Hubs Air Traffic Control System Command Center (ATCSCC) Washington, DC OR Mike Monroney Aeronautical Center (MMAC) Oklahoma City, OK.
This position may require up to 50% travel to FAA facilities.
Core Responsibilities & Duties:
- Serve as primary technical POC for all security assessments, vulnerability assessments, and analyses of alternatives under the contract.
- Lead assessment planning and coordination at FAA facilities nationwide, including developing System Security Assessment Test Plans and managing pre- and post-assessment activities.
- Personally lead complex or high-visibility assessment events.
- Ensure all assessments use the three NIST 800-53A methods (Examine, Interview, Test) and produce compliant SARs.
- Develop and maintain vulnerability scanning strategies including Tactics, Techniques, and Procedures (TTPs).
- Evaluate and recommend scanning tools and configurations for NAS and Mission Support environments.
- Conduct risk translation from assessment findings and develop draft Plans of Action and Milestones (POAMs) with actionable remediation guidance.
- Lead regression assessment activities to validate that patches, fixes, and configuration changes mitigate previously identified vulnerabilities.
- Attend all Program Management Reviews and report on assessment status, deliverable timelines, and technical issues.
- Mentor and develop junior assessment staff.
- Build a team culture where analysts take ownership of their assigned systems and drive assessments to completion independently.
- Coordinate with NAS system owners, FAA facility staff, AIT/AIS, and ACG to schedule assessments and resolve access and logistical issues.
- Ensure assessment work in NAS operational environments follows safety protocols. Test methods for NAS systems may need to be conducted in lab environments due to air traffic safety constraints.
Requirements:
Minimum Qualifications:
Education: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution. Master's degree in a related field preferred.
Experience:
- At least fifteen (15)+ years of cybersecurity experience.
- Minimum of five (5) years of management and supervisory responsibility leading risk and vulnerability assessment teams.
- At least two (2) years of relevant experience performed within the last 3 years.
- Demonstrated track record of successful completion of multiple independent risk assessments and vulnerability assessments on complex, multi-system environments.
- Deep working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-53A, NIST SP 800-37 (RMF), and FIPS-199 security categorization.
- Hands-on experience with vulnerability assessment tools including Nessus, WebInspect, AppDetective Pro, nMap, and Tcpdump.
- Experience developing System Security Assessment Reports (SARs), Plans of Action and Milestones (POAMs), and assessment test plans.
- Experience working in Operational Technology (OT), Industrial Control Systems (ICS), or other safety-critical infrastructure environments.
Security Clearance Requirement:
Candidate must have the ability to obtain and maintain a Public Trust. Active Secret level clearance preferred.
Certifications:
Current cybersecurity certification aligned with security assessment and risk management disciplines, including CISSP, GCED, CompTIA CASP+, CISA, or an equivalent. CAP (Certified Authorization Professional) or equivalent RMF certification preferred.
Preferred Qualifications:
- Prior experience assessing National Airspace System (NAS) systems or other FAA Air Traffic Organization (ATO) systems.
- Familiarity with FAA Order 1370.82, FAA Order 1370.121, and the ATO ISCM Plan.
- Experience supporting FAA Assessment & Authorization (A&A) processes.
- Experience conducting assessments of cloud-based services and web-facing applications in federal environments.
- Experience supporting international assessments or telecommunications infrastructure assessments.
Other Required Skills and Abilities:
- Strong written and verbal communication skills with the ability to produce clear, defensible, and actionable technical documentation.
- Proven leadership and team development capabilities.
- Ability to manage multiple assessment efforts simultaneously while maintaining quality standards.
- Strong analytical and problem-solving skills.
- Ability to work effectively with government stakeholders, technical teams, and senior leadership.
About Us:
At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting-edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward-thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability.
What Defines Us:
- Integrity - We act with unwavering honesty, ensuring every decision is rooted ethically.
- Adaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead.
- People-Focused - We prioritize relationships, championing growth and mutual success.
- Accountable - We own our outcomes, striving for excellence through continuous improvement.
- Collaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions.
Why Join Us?
Step into a role at OCH where your contributions make a tangible impact. Join a team that values creativity and initiative, offering a platform to transform the landscape of government IT services. Here, your work is not just a career—it's a mission. Embrace the opportunity to grow, innovate, and excel alongside industry leaders who are as passionate about technology as they are about making a difference. Plus, we offer a comprehensive benefits package designed to support your wellbeing and work-life balance, including:
- Paid time off and Holidays
- Medical, Dental, and Vision Insurance
- Paid Parental Leave
- Short-term disability, long-term disability, and life insurance - Employer Paid!
- 401(k)
- Additional Voluntary Life Insurance
- Tuition Reimbursement
& More!
E-Verify Participation: OCH Technologies, LLC is a participant of E-Verify to verify the identity and employment eligibility of newly hired employees.
Veteran's Preference and Accessibility Statement: At OCH Technologies, we deeply respect and appreciate the unique skills and experiences that veterans bring to our team. As a federal contractor, we encourage qualified veterans to apply and provide preference where permitted by law. Your service and dedication are valued here.
We are committed to creating a workplace that is open, welcoming, and accessible to everyone. In accordance with the Americans with Disabilities Act (ADA) and Section 503 of the Rehabilitation Act, we provide reasonable accommodations throughout the hiring process to ensure individuals with disabilities can apply without barriers. If you need assistance or an accommodation, please contact us at View email address on click.appcast.io.
OCH Technologies, LLC is proud to be an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.
- ...technology solutions company based in Washington, D.C. is seeking a Security Assessor responsible for evaluating security measures and... ...in cybersecurity. Responsibilities include conducting assessments, identifying vulnerabilities, ensuring compliance, and collaborating...Suggested
- ...Koniag IT Systems, LLC, a Koniag Government Services company , is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The customer may need support as needed at...SuggestedLocal areaFlexible hours
- ...contractor that provides services and solutions in: ~National Security Programs ~Professional, Administrative, and Management... ...Time Position Status: Contingent Position Title: Security Assessment Lead Location:Washington, DC Clearance: Secret Duties and Responsibilities...SuggestedFull timeFor contractors
$127.5k - $276.2k
Security Control Assessor III Position Description The Security Control Assessor III... ...senior authority for complex security assessments across Treasury systems, providing independent... ...future duties and responsibilities Lead comprehensive control testing, including...SuggestedWork at officeLocal area- ...growing government contractor providing leading-edge support to federal customers, with... ...particular focus on Defense and National Security mission sets. We leverage more than 17 years... ...Barbaricum is seeking an experienced Assessment Lead Subject Matter Expert to lead...SuggestedContract workFor contractorsWork at office
- ...Security Analyst Job Requirements: Washington, DC Secret Polygraph Unspecified Career Level... ...Job Description: Requires skills to assess, plan, and enact security measures to help... ...Trust implementation). Risk Management: Leading the identification, assessment, and...
- ...impact. We serve the Infrastructure; Nuclear, Security & Environmental; Energy; Mining & Metals,... .... Job Summary The AI Enablement Lead is responsible for driving the adoption... ...Work with Data Architecture and AI team to assess use-cases, determine build requirements,...Work experience placement
- ...Purpose and Scope The Head of Physical Security is a senior security executive responsible... ...violence prevention, behavioral threat assessment, investigations, training, and crisis response... ...& Behavioral Threat Assessment Lead enterprise-wide Workplace Violence Prevention...Local area
- ...company supporting cutting-edge AI innovation and national security initiatives. AI Governance Lead The AI Governance Lead will design and implement... ...responsible AI implementation. Develop AI risk assessment frameworks for federal mission environments....
- Job Title: Evaluation Team Lead Location: USA, Remote Duration: Contract-based; project... ...vital to U.S. national defense and security. SCALE employs a public-private-academic... ...that will provide a third‑party, unbiased assessment of program outcomes and impacts,...Contract workPart timeWork at officeRemote work
- ...RMS is seeking a Senior Cybersecurity Engineer / Offensive Security Lead to support high‑visibility federal and IC programs. This role... ...operations across federal and IC environments. Conduct full‑scope assessments, exploit development, and hands‑on attack simulations....
- ...Summary Division of Police ensures the safety and security of employees, visitors, patients, and contractors, as well as the protection... ...and paste the duties, specialized experience, or occupational assessment questionnaire from this announcement into your resume as that...For contractorsWork at officeLocal areaTrial period
- Lead Solutions Architect At B&A, we foster and embrace a distinct set of values that we... ...goals. The Lead Solutions Architect designs secure multi-cloud solutions leveraging... ...supervise others. Responsibilities Review and assess current cloud architecture and engineering...Full timeWork at officeLocal area
$201.6k - $325k
...with and supports our mission. About the Role This is a senior individual contributor policy role leading OpenAI's engagement with state and major metropolitan homeland security, emergency management, cybersecurity, election security, law enforcement and public safety...Local area- ...global health organization based in Washington, DC, is seeking a Monitoring and Evaluation Manager to lead efforts for a CDC-funded project focused on global health security. The ideal candidate will have a Master's degree in a relevant field, along with 7-10 years of...Remote work
- ...Receiving Lead Receiving Leads are key players in our store's success by making sure our products get in the door quickly and accurately... ...backroom/receiving area operations to minimize costs, enforce security procedures, promote a safe work environment and provide superior...Immediate startAfternoon shift
- ...Thomson Reuters is seeking a Lead Governance & Compliance Analyst in Washington, DC to ensure our federal-facing products maintain compliance... ...involves collaboration with various stakeholders to support security and authorization activities while ensuring continuous audit...Flexible hours
- ...opportunities and training. Duties and Responsibilities: Lead all Food Lion To-Go operations, including training, coaching,... ...guidelines, policies and standard practices Maintains security standards Successfully complete Computer Based Training (CBT...Work experience placementLocal areaImmediate start
$25.5 - $27.5 per hour
...patterns,pricingand promotions strategies Leading a team by planning department(s) daily/... ..., and product availability. Help assess reporting toidentifygaps in GM processes... ...accurately. Model the execution of physical security processesin order toenhance the instore...Hourly payTemporary workWork experience placementFlexible hoursShift workNight shift$99.3k - $159.33k
...Windows designs, implements, and supports cloud-hosted Windows server environments that underpin mission-critical applications in secure federal cloud or hybrid infrastructures. This role builds and maintains virtual machines, images, and automation to provision Windows...Contract workWork at office- ...Team Lead A Team Lead will oversee all Escort Staff on site coordinating schedules and job coverage and ensuring all personnel remain... ...required duties are performed and escort them outside the security perimeter after completion of business. Keep and maintain an...
$150k - $170k
...Zachary Piper Solutions is seeking a SOC Lead to support a company focused on cybersecurity operations, engineering, and compliance for the Department of Energy (DOE) and National Nuclear Security Administration (NNSA). This position is on‑site in Manassas, VA and Washington...$150k - $175k
...Site Lead Arlington, VA Nooks is pioneering Classified-Infrastructure-as-a-Service (CIaaS) — designing, building, and operating... ...Sensitive Compartmented Information Facilities (SCIFs) and other secured, classified environments for the defense and national security...For contractorsWork at officeLocal areaImmediate startShift work- ...Overview Amyx is seeking to hire a Communications Lead to support our Department of Homeland Security, ICE contract in the Washington DC area. Responsibilities A Communications Lead is required with a minimum of eight (8) years of progressive experience in developing...Contract workTemporary workFor contractorsFlexible hours
- ...Deployed Global Solutions, LLC, a veteran-owned national security operator, seeks a Proposal Manager to lead federal proposal development across IT, construction, and manufacturing domains. You will write, coordinate, and refine compelling responses and supporting documentation...
- ...Security And Intelligence Career Field Position Lead a patrol team of three or more officers, including Department of Army Civilian Police (DACP), Military Police (MP) and Department of Army Security Guards (DASG). Provide direct oversight of all stages of investigations...Shift workRotating shiftWeekend workAfternoon shift
$147k - $200k
...for advanced sensor systems and platforms in support of national security. At STR, Defense Systems Researchers study complex defense... ...programs. The Role The SAAM Group is seeking a Lead Program Manager with an engineering background to manage a portfolio...Full timeContract workFor subcontractorWork at officeLocal areaNight shift- ...provides services and solutions in: ~National Security Programs ~Professional, Administrative,... ...Position Title: Cybersecurity Policy Lead Location:Washington, DC Clearance:... ...management in providing inputs for risk assessment memos ~Meet with Subject Matter Experts...Full timeFor contractorsWork at office
- ...provides services and solutions in: ~National Security Programs ~Professional, Administrative,... ...Position Title: System Compliance Lead Location:Washington, DC Clearance:... ...update existing templates for Memos, Risk Assessments, Disposal Packages, etc. to standardize...Full timeFor contractors
- ...Job Description Job Description Security Management Lead (SML) – SME Work Location: Washington, DC Employment Type: Full-Time,... ...process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or...Full timeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Assessment Lead. Be the first to apply!

