Security Assessment Lead

OCH Technologies, LLC

Leesburg (VA)

Hybrid

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Paid time off
Medical, Dental, Vision Insurance
Parental Leave
401(k)
Tuition Reimbursement

Job summary

OCH Technologies, LLC is seeking a Security Assessment Lead to act as the technical authority for independent risk and vulnerability assessments conducted under this contract. You will lead assessment planning, mentor teams, and ensure SAR quality following NIST 800-53A guidelines, with potential travel to FAA facilities in DC/OKC.

The role requires advanced cybersecurity leadership, hands-on assessment experience, and strong ability to translate findings into actionable POAMs for complex OT/ICS

Qualifications

  • Fifteen (15)+ years of cybersecurity experience.
  • Minimum of five (5) years of management and supervisory responsibility leading risk and vulnerability assessment teams.
  • At least two (2) years of relevant experience performed within the last 3 years.
  • Demonstrated track record of successful completion of multiple independent risk assessments and vulnerability assessments on complex, multi-system environments.
  • Hands-on experience with NIST SP 800-53 (Rev. 4/5), SP 800-53A, SP 800-37 (RMF), and FIPS-199 security categorization.

Responsibilities

  • Serve as primary technical POC for all security assessments, vulnerability assessments, and analyses of alternatives under the contract.
  • Lead assessment planning and coordination at FAA facilities nationwide, including developing System Security Assessment Test Plans and managing pre- and post-assessment activities.
  • Personally lead complex or high-visibility assessment events.
  • Ensure all assessments use the three NIST 800-53A methods (Examine, Interview, Test) and produce compliant SARs.
  • Develop and maintain vulnerability scanning strategies including TTPs.
  • Evaluate and recommend scanning tools and configurations for NAS and Mission Support environments.
  • Conduct risk translation from assessment findings and develop POAMs with actionable remediation guidance.
  • Lead regression assessment activities to validate mitigations.
  • Attend all Program Management Reviews and report on assessment status, deliverable timelines, and technical issues.
  • Mentor and develop junior assessment staff.
  • Build a team culture where analysts take ownership and drive assessments to completion.
  • Coordinate with NAS system owners, FAA facility staff, AIT/AIS, and ACG to schedule assessments and resolve access/logistical issues.
  • Ensure NAS environmental safety during assessments; some NAS tests may be lab-based.

Skills

Leadership
Team leadership
Communication
Analytical thinking
Problem solving

Education

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics
Master’s degree in a related field

Tools

Nessus
WebInspect
AppDetective Pro
Nmap
Tcpdump

Job description

Description

OCH Technologies is seeking a Security Assessment Lead to act as the technical authority for all independent risk assessments, vulnerability assessments, and analyses of alternatives conducted under this contract. The candidate will lead assessment planning, assign and mentor assessment teams, ensure assessment execution follows NIST 800‑53A methodology, and is accountable for the quality and completeness of all System Security Assessment Reports (SARs) delivered.

Location

Hybrid – FAA Hubs Air Traffic Control System Command Center (ATCSCC) Washington, DC or Mike Monroney Aeronautical Center (MMAC) Oklahoma City, OK. Position may require up to 50% travel to FAA facilities.

Core Responsibilities & Duties
  • Serve as primary technical POC for all security assessments, vulnerability assessments, and analyses of alternatives under the contract.
  • Lead assessment planning and coordination at FAA facilities nationwide, including developing System Security Assessment Test Plans and managing pre‑ and post‑assessment activities.
  • Personally lead complex or high‑visibility assessment events.
  • Ensure all assessments use the three NIST 800‑53A methods (Examine, Interview, Test) and produce compliant SARs.
  • Develop and maintain vulnerability scanning strategies including Tactics, Techniques, and Procedures (TTPs).
  • Evaluate and recommend scanning tools and configurations for NAS and Mission Support environments.
  • Conduct risk translation from assessment findings and develop draft Plans of Action and Milestones (POAMs) with actionable remediation guidance.
  • Lead regression assessment activities to validate that patches, fixes, and configuration changes mitigate previously identified vulnerabilities.
  • Attend all Program Management Reviews and report on assessment status, deliverable timelines, and technical issues.
  • Mentor and develop junior assessment staff.
  • Build a team culture where analysts take ownership of their assigned systems and drive assessments to completion independently.
  • Coordinate with NAS system owners, FAA facility staff, AIT/AIS, and ACG to schedule assessments and resolve access and logistical issues.
  • Ensure assessment work in NAS operational environments follows safety protocols. Test methods for NAS systems may need to be conducted in lab environments due to air traffic safety constraints.
Requirements
Education

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution. Master’s degree in a related field preferred.

Experience
  • At least fifteen (15)+ years of cybersecurity experience.
  • Minimum of five (5) years of management and supervisory responsibility leading risk and vulnerability assessment teams.
  • At least two (2) years of relevant experience performed within the last 3 years.
  • Demonstrated track record of successful completion of multiple independent risk assessments and vulnerability assessments on complex, multi‑system environments.
  • Deep working knowledge of NIST SP 800‑53 (Rev. 4/5), NIST SP 800‑53A, NIST SP 800‑37 (RMF), and FIPS‑199 security categorization.
  • Hands‑on experience with vulnerability assessment tools including Nessus, WebInspect, AppDetective Pro, nMap, and Tcpdump.
  • Experience developing System Security Assessment Reports (SARs), Plans of Action and Milestones (POAMs), and assessment test plans.
  • Experience working in Operational Technology (OT), Industrial Control Systems (ICS), or other safety‑critical infrastructure environments.
Security Clearance Requirement

Candidate must have the ability to obtain and maintain a Public Trust. Active Secret level clearance preferred.

Certifications

Current cybersecurity certification aligned with security assessment and risk management disciplines, including CISSP, GCED, CompTIA CASP+, CISA, or an equivalent. CAP (Certified Authorization Professional) or equivalent RMF certification preferred.

Preferred Qualifications
  • Prior experience assessing National Airspace System (NAS) systems or other FAA Air Traffic Organization (ATO) systems.
  • Familiarity with FAA Order 1370.82, FAA Order 1370.121, and the ATO ISCM Plan.
  • Experience supporting FAA Assessment & Authorization (A&A) processes.
  • Experience conducting assessments of cloud‑based services and web‑facing applications in federal environments.
  • Experience supporting international assessments or telecommunications infrastructure assessments.
Other Required Skills And Abilities
  • Strong written and verbal communication skills with the ability to produce clear, defensible, and actionable technical documentation.
  • Proven leadership and team development capabilities.
  • Ability to manage multiple assessment efforts simultaneously while maintaining quality standards.
  • Strong analytical and problem‑solving skills.
  • Ability to work effectively with government stakeholders, technical teams, and senior leadership.
Benefits
  • Paid time off and Holidays
  • Medical, Dental, and Vision Insurance
  • Paid Parental Leave
  • Short‑term disability, long‑term disability, and life insurance – Employer Paid!
  • 401(k)
  • Additional Voluntary Life Insurance
  • Tuition Reimbursement

E‑Verify Participation: OCH Technologies, LLC is a participant of E‑Verify to verify the identity and employment eligibility of newly hired employees.

Veteran’s Preference and Accessibility Statement: OCH Technologies, LLC is a federal contractor that encourages qualified veterans to apply and provides preference where permitted by law. We are committed to creating an accessible workplace for all individuals, in accordance with the Americans with Disabilities Act and Section 503 of the Rehabilitation Act. Please contact hiring@ochtec.com for accommodations.

OCH Technologies, LLC is a proud equal‑opportunity employer. We provide equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Assessment Lead
Security Assessment Lead

Ochtec • Oklahoma City (OK)

Hybrid
USD 180,000 - 240,000
Paid time off
Medical, Dental, Vision insurance
Short‑/Long-term disability and life保险
+2
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Ochtec • Washington (NJ)

On-site
USD 120,000 - 160,000
Paid time off and Holidays
Medical, Dental, and Vision Insurance
401(k)
+3
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

OCH Technologies, LLC • Leesburg (VA)

On-site
USD 120,000 - 150,000
Medical, Dental, and Vision Insurance
Paid Time Off
401(k)
+1
Cybersecurity Engineer
Cybersecurity Engineer

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 120,000 - 150,000
Medical, Dental, Vision Insurance
Paid time off & holidays
Parental Leave
+3
Cybersecurity Engineer
Cybersecurity Engineer

Ochtec • Washington (NJ)

Hybrid
USD 130,000 - 180,000
Medical, Dental, Vision Insurance
401(k)
Paid time off and holidays
+2
NCO (National Cybersecurity Operations) Technical Lead
NCO (National Cybersecurity Operations) Technical Lead

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 180,000 - 240,000
Paid time off
Health Insurance
Parental Leave
+4
Penetration Testing Lead
Penetration Testing Lead

Ochtec • Washington

Hybrid
USD 180,000 - 240,000
Paid time off and Holidays
Medical, Dental, Vision Insurance
401(k)
+1
Security Assessment Lead
Security Assessment Lead

Jobtailor • Oklahoma

On-site
USD 180,000 - 230,000
Program Manager
Program Manager

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 120,000 - 180,000
Paid time off and holidays
Medical, dental, and vision insurance
Paid parental leave
+2
Senior FAA Cybersecurity Analyst — Lead On-Site Assessments
Senior FAA Cybersecurity Analyst — Lead On-Site Assessments

Ochtec • Washington (NJ)

On-site
USD 120,000 - 160,000
Paid time off and Holidays
Medical, Dental, and Vision Insurance
401(k)
+3