Cybersecurity Lead
20 days ago
Washington
Job DescriptionDescription: About the Position: The Cybersecurity Lead is responsible for overseeing the design, implementation, and management of an organization’s cybersecurity strategy and infrastructure. This role involves leading a team of cybersecurity professionals to protect the organization's information systems, network, and data from potential threats, ensuring compliance with relevant security regulations and standards. The Cybersecurity Lead will coordinate risk management efforts, respond to security incidents, and work proactively to secure all aspects of the organization’s digital presence. Key Responsibilities: Cybersecurity Strategy & Leadership: • Develop and implement a comprehensive cybersecurity strategy aligned with the organization’s business objectives and risk management framework., • Lead a team of cybersecurity professionals, providing direction, guidance, and support on security-related issues., • Ensure cyber-related tasks are performed efficiently, accurately, on time, and in compliance with all federal, state, and local regulations and guidelines., • Stay informed on the latest cybersecurity trends, threats, and technologies to ensure the organization’s security posture remains robust and up to date., • Enforce National Institute of Standards and Technology (NIST) RMF standards as well as Clinger Cohen Act (CCA) and Federal Information Security Management Act (FISMA) regulations., • Ensure non-compliant controls are being addressed in a timely manner (IAW DAF standards and best practices)., • Conduct regular risk assessments to identify potential vulnerabilities, threats, and areas of concern in the organization's infrastructure., • Develop and execute risk mitigation strategies, ensuring timely resolution of security gaps and vulnerabilities., • Implement and manage security monitoring tools to detect and respond to cyber threats in real-time., • Collect initial vulnerability scanning deliverables, specifically Assured Compliance Assessment Solution (ACAS) scans and Security Technical Implementation Guide (STIG) checklists., • Lead the response to cybersecurity incidents, including data breaches, malware attacks, and network intrusions., • Investigate security incidents, analyze root causes, and implement corrective actions to prevent future occurrences., • Oversee the design, implementation, and maintenance of secure network architectures, firewalls, intrusion detection/prevention systems, and endpoint security solutions., • Collaborate with IT teams to ensure security controls are effectively integrated into the infrastructure, cloud environments, and application development processes., • Ensure the organization complies with relevant cybersecurity regulations, standards, and best practices (e.g., GDPR, HIPAA, NIST, ISO 27001)., • Develop and maintain cybersecurity policies and procedures to ensure compliance with internal and external requirements., • Lead cybersecurity training programs for employees, raising awareness about potential threats such as phishing, social engineering, and other forms of cyberattacks., • Work closely with senior management and other departments (e.g., IT, legal, operations) to integrate cybersecurity into business processes and ensure alignment with organizational goals., • Communicate security risks and mitigation strategies to non-technical stakeholders, making complex issues understandable., • Prepare and present regular reports on logistics performance, inventory status, cost analysis, and potential issues to senior management., • Maintain accurate records of logistics activities, transactions, and communications with external partners., • Ensure compliance with internal reporting requirements and industry regulations., • Oversee vulnerability management processes, ensuring regular scanning and timely patching of systems, software, and applications., • Lead the continuous improvement of security processes, tools, and strategies to enhance the organization’s cybersecurity resilience., • Evaluate and recommend new cybersecurity technologies, solutions, and best practices to keep the organization’s security posture ahead of evolving threats Requirements: Cybersecurity Expertise: • In-depth knowledge of cybersecurity principles, frameworks, and technologies (e.g., firewalls, encryption, VPNs, IDS/IPS, SIEM)., • Strong understanding of risk management, incident response, vulnerability management, and security operations., • Experience with cloud security, network security, endpoint protection, and securing distributed systems., • Experienced working within the DoD Risk Management Framework (RMF) process., • Proven ability to lead, mentor, and manage a team of cybersecurity professionals., • Expertise in leading incident response, digital forensics, and root cause analysis., • Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or similar certifications., • Strong communication skills, both verbal and written, to articulate complex security concepts to stakeholders., • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field., • 7+ years of experience in cybersecurity, with at least 3 years in a leadership or senior technical role., • Proven experience managing security operations, incident response, and security risk management., • Occasional after-hours work may be required in the event of a security breach or ongoing incident., • The role may involve on-call availability to respond to security incidents outside of standard working hours., • Some travel may be required for audits, training, or industry conferences.