Cybersecurity Manager - Part-time

UKG

Washington, Northern (District of Columbia, KY)

Hybrid

USD 83,000 - 88,000

Part time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Copperhead Technologies, performing work for the Veterans Affairs Data Collection Tool program, seeks a Cybersecurity Manager to own the ATO process, manage RMF lifecycle, and coordinate comprehensive security assessments.

The role requires developing threat models, privacy reviews, and authorization evidence for ongoing monitoring, with close collaboration with VA ISSOs and security teams. This is a part-time contract position contingent on award.

Qualifications

  • Own and manage end-to-end ATO for the DCT using RMF principles.
  • Coordinate security assessments and prioritize remediation actions.
  • Develop and maintain security controls documentation with ISSO.
  • Create a threat model and privacy assessment for DCT data.
  • As primary contact, organize authorization evidence for VA stakeholders.

Responsibilities

  • Own and manage the end-to-end ATO process for the DCT.
  • Coordinate web app, infrastructure, and database security assessments.
  • Review and track findings through closure.
  • Maintain RMF artifacts and authorization evidence packages.
  • Engage with VA stakeholders and security teams for milestones.

Skills

ATO process
RMF lifecycle
security assessments
threat modeling
privacy reviews
eMASS
security controls
stakeholder coordination

Tools

eMASS

Job description

Cybersecurity Manager - Part-time - Veterans Affairs

Copperhead Technologies, an operating firm of Command Holdings, is seeking a Cybersecurity Manager to support the operation of the Veterans Affairs (VA) Data Collection Tool (DCT) program. The Cybersecurity Manager owns the Authority to Operate (ATO) process for the VA Data Collection Tool (DCT) program. This role is responsible for achieving and maintaining an ATO for a federally implemented COTS product that collects sensitive health information, managing the full Risk Management Framework (RMF) lifecycle, coordinating required security scans, maintaining security controls documentation, developing threat models, and producing privacy risk assessments. This position supports an active VA program requiring ongoing coordination with government ISSOs, system stewards, and security assessment teams, with sustained ownership of authorization documentation and continuous monitoring activities to keep the DCT's ATO current throughout the period of performance.

Responsibilities may include, but are not limited to:

  • Own and manage the end-to-end ATO process for the DCT, applying RMF principles to achieve and sustain authorization for a COTS product requiring additional systems configuration to protect sensitive health information.
  • Coordinate and oversee execution of required security assessments, including web application scans that examine the application for common vulnerabilities and vulnerable design patterns, penetration scans that examine infrastructure for common vulnerabilities and weak communication security, and database scans that examine database configurations and data management practices for vulnerabilities and weak protections, and reviews scan results, prioritizes remediation activities, and tracks findings through closure.
  • Develop and maintain comprehensive security controls documentation, including access and policy documentation managed in coordination with the Information System Security Officer (ISSO) and system steward within eMASS, ensuring authorization evidence remains current, accurate, and audit ready.
  • Develop and maintain a diagram-based threat model that maps system elements, devices, and connections to identify potential threats to the DCT environment, updating the model as the architecture evolves, and conducts comprehensive privacy reviews of DCT data elements, policies, and procedures to produce a privacy statement that identifies privacy risks and documents mitigation strategies, ensuring sensitive health information handling aligns with federal privacy requirements.
  • Compile and organize authorization evidence packages to support ATO submission, renewal, and continuous monitoring activities, serving as the primary point of contact for security control assessments, audits, and RMF milestone reviews with VA stakeholders.

This position is contingent on contract award.

Expected hourly rate: $60.00 - $64.00

  • Moderate noise (i.e. business office with computers, phone and printers) and /or occasional Loud noise (airfield, large equipment).
  • Ability to sit at a computer terminal for an extended period of time.
  • Ability to work in confined areas.

Physical Demands:

  • While performing the responsibilities of the job, the employee is required to sit, stand, talk, and hear.
  • Employee is often required to sit and use their hands and fingers to operate a computer.
  • Must be able to occasionally lift and/or move up to 50 pounds.

Travel:

  • 0-10% / Minimal travel expected: off-sites, meetings, training, a conference, etc.

Copperhead Technologies, an operating firm of Command Holdings, is a tribally-owned firm providing management consulting services to U.S. government agencies.

Pursuant to PL 93-638, as amended, preference will be given to qualified Native Americans and spouses in all phases of employment.

At Copperhead Technologies, our employees are the embodiment of our success as a firm. Our team is comprised of a tenacious group of professionals located across the globe. It includes military veterans and spouses of active duty troops, former federal employees, policy experts, academics, attorneys, and technical and business experts, all of whom share a strong work ethic and the skills to succeed in both collaborative and independent environments. Copperhead Technologies is invested in the long-term success of both our clients and colleagues for the right reasons. Our dedication to putting good government into practice is underpinned by a merit-based culture that measures success by productivity and credibility.

Copperhead Technologies will provide reasonable accommodations to applicants who are unable to utilize our online application system due to a disability. Please send your request to the Human Resources Team .

Copperhead Technologies is committed to equal employment opportunitybased on merit.We recruit, employ, train, compensate, and promote without regard to race, religion, color, national origin, age, sex, disability, protected veteran status, or any other basis protected by applicable federal, state, or local law, and in accordancewith EO 14173 and Federal Employment Laws: Equal Employment Opportunity and Employee Polygraph Protection Act.

Copperhead Technologies’ Affi... program is available to any employee or applicant for employment for inspection upon request, to the extent required by federal regulations. The Affi... program can be accessed during normal business hours by making an appointment with the Human Resources Team .

*Eligibility requirements apply

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

COTS Integration Engineer - Veterans Affairs
COTS Integration Engineer - Veterans Affairs

UKG • Washington, Northern (KY)

Hybrid
USD 103,000 - 111,000
Health, Dental, and Vision Insurance
Flexible Spending Accounts
Life and Disability Insurance
+5
COTS Integration Engineer - Veterans Affairs
COTS Integration Engineer - Veterans Affairs

Command Holdings, a Pequot Company • Washington

On-site
USD 103,000 - 111,000
Health Insurance
Retirement Plan
PTO
+6
Senior Business Systems Analyst - Veterans Affairs
Senior Business Systems Analyst - Veterans Affairs

Command Holdings, a Pequot Company • Washington

On-site
USD 103,000 - 110,000
Health Insurance
Dental Insurance
Vision Insurance
+1
Cybersecurity Analyst – Tier 2 (On-Site)
Cybersecurity Analyst – Tier 2 (On-Site)

Oxley Enterprises, Inc. • West Virginia

On-site
USD 92,490 - 102,790
Medical, dental, and vision coverage
Life and disability insurance
401k plan options
Cybersecurity Analyst Tier 2 (On-Site)
Cybersecurity Analyst Tier 2 (On-Site)

Koitecc Solutions • Martinsburg (WV)

On-site
USD 92,000 - 103,000
Medical, dental, vision coverage
401k plan options
Life insurance
Cybersecurity Engineer - CONTINGENT - 26-025 - Hybrid
Cybersecurity Engineer - CONTINGENT - 26-025 - Hybrid

AUSGAR Technologies Inc • San Diego (CA)

Hybrid
USD 120,000 - 155,000
Hybrid work model (60% onsite / 40%远?)
E-Verify employment eligibility
Cybersecurity Engineer - CONTINGENT - 26-025 - Hybrid
Cybersecurity Engineer - CONTINGENT - 26-025 - Hybrid

AUSGAR Technologies, Inc. • San Diego (CA)

Hybrid
USD 120,000 - 155,000
Hybrid work model
Competitive salary and benefits
Cybersecurity Engineer
Cybersecurity Engineer

Electrosoft • Fort Belvoir (VA)

On-site
USD 110,000 - 160,000
Cybersecurity Analyst – Tier 2 (On-Site)
Cybersecurity Analyst – Tier 2 (On-Site)

Oxley Enterprises, Inc. • Illinois

On-site
USD 93,538 - 103,319
Medical, dental, vision insurance
401k plan
Life insurance
Cybersecurity Analyst Tier 2 (On-Site)
Cybersecurity Analyst Tier 2 (On-Site)

https:/www.scheurer.org/careers/ • Proviso Township (IL)

On-site
USD 93,000 - 104,000
Medical, dental, vision insurance
Life Insurance
401k plan