Security Assessment Lead

Jobtailor

Oklahoma

On-site

USD 180,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a highly experienced cybersecurity leader to serve as the primary technical POC for security assessments, risk management, and compliance activities across FAA facilities nationwide.

The role requires extensive experience in NIST RMF, vulnerability assessment, and SAR/POAM development, with a track record of guiding multi-system environments and safety-critical operations.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution.
  • Fifteen (15)+ years of cybersecurity experience.
  • Five (5) years of management and supervisory responsibility leading risk and vulnerability assessment teams.

Responsibilities

  • Serve as primary technical POC for security assessments, vulnerability assessments, and analyses of alternatives under the contract.
  • Lead assessment planning and coordination at FAA facilities nationwide, including developing System Security Assessment Test Plans and managing pre- and post-assessment activities.
  • Personally lead complex or high-visibility assessment events.
  • Ensure all assessments use the three NIST 800-53A methods (Examine, Interview, Test) and produce compliant SARs.
  • Develop and maintain vulnerability scanning strategies including TTPs.
  • Evaluate and recommend scanning tools and configurations for NAS and Mission Support environments.
  • Conduct risk translation from assessment findings and develop draft POAMs with actionable remediation guidance.
  • Lead regression assessment activities to validate patches and configuration changes.
  • Attend all Program Management Reviews and report on assessment status, deliverable timelines, and technical issues.
  • Mentor and develop junior assessment staff.
  • Build a team culture where analysts take ownership of their assigned systems and drive assessments to completion independently.
  • Coordinate with NAS system owners, FAA facility staff, AIT/AIS, and ACG to schedule assessments and resolve access and logistical issues.
  • Ensure assessment work in NAS operational environments follows safety protocols.

Skills

Cybersecurity leadership
Risk assessment
Vulnerability assessment
NIST RMF / NIST 800-53
Technical writing
Stakeholder management

Education

Bachelor's degree in Cybersecurity/CS/IT/Engineering/Math/Physics

Tools

Nessus
WebInspect
AppDetective Pro
nMap
Tcpdump

Job description

Responsibilities
  • Serve as primary technical POC for all security assessments, vulnerability assessments, and analyses of alternatives under the contract
  • Lead assessment planning and coordination at FAA facilities nationwide, including developing System Security Assessment Test Plans and managing pre- and post-assessment activities
  • Personally lead complex or high‑visibility assessment events
  • Ensure all assessments use the three NIST 800‑53A methods (Examine, Interview, Test) and produce compliant SARs
  • Develop and maintain vulnerability scanning strategies including Tactics, Techniques, and Procedures (TTPs)
  • Evaluate and recommend scanning tools and configurations for NAS and Mission Support environments
  • Conduct risk translation from assessment findings and develop draft Plans of Action and Milestones (POAMs) with actionable remediation guidance
  • Lead regression assessment activities to validate that patches, fixes, and configuration changes mitigate previously identified vulnerabilities
  • Attend all Program Management Reviews and report on assessment status, deliverable timelines, and technical issues
  • Mentor and develop junior assessment staff
  • Build a team culture where analysts take ownership of their assigned systems and drive assessments to completion independently
  • Coordinate with NAS system owners, FAA facility staff, AIT/AIS, and ACG to schedule assessments and resolve access and logistical issues
  • Ensure assessment work in NAS operational environments follows safety protocols
Requirements
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution
  • At least fifteen (15)+ years of cybersecurity experience
  • Minimum of five (5) years of management and supervisory responsibility leading risk and vulnerability assessment teams
  • At least two (2) years of relevant experience performed within the last three (3) years
  • Demonstrated track record of successful completion of multiple independent risk assessments and vulnerability assessments on complex, multi‑system environments
  • Deep working knowledge of NIST SP 800‑53 (Rev. 4/5), NIST SP 800‑53A, NIST SP 800‑37 (RMF), and FIPS‑199 security categorization
  • Hands‑on experience with vulnerability assessment tools including Nessus, WebInspect, AppDetective Pro, nMap, and Tcpdump
  • Experience developing System Security Assessment Reports (SARs), Plans of Action and Milestones (POAMs), and assessment test plans
  • Experience working in Operational Technology (OT), Industrial Control Systems (ICS), or other safety‑critical infrastructure environments
  • Candidate must have the ability to obtain and maintain a Public Trust Active Secret level clearance preferred
  • Current cybersecurity certification aligned with security assessment and risk management disciplines, including CISSP, GCED, CompTIA CASP+, CISA, or an equivalent
  • CAP (Certified Authorization Professional) or equivalent RMF certification preferred.
  • Strong written and verbal communication skills with the ability to produce clear, defensible, and actionable technical documentation
  • Proven leadership and team development capabilities
  • Ability to manage multiple assessment efforts simultaneously while maintaining quality standards
  • Strong analytical and problem‑solving skills
  • Ability to work effectively with government stakeholders, technical teams, and senior leadership.
Core Competencies

Demonstrates extensive expertise in cybersecurity assessments, including risk and vulnerability management, while leading teams to ensure compliance with NIST standards and producing actionable remediation strategies. Proven ability to mentor staff and manage complex assessment projects in safety‑critical environments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Assessment Lead
Security Assessment Lead

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 140,000 - 190,000
Paid time off
Medical, Dental, Vision Insurance
Parental Leave
+2
Traveling Security Control Assessor
Traveling Security Control Assessor

Jobtailor • Maryland

On-site
USD 120,000 - 160,000
Security Control Assessor
Security Control Assessor

Jobtailor • Town of Florida (NY)

On-site
USD 90,000 - 130,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital Global Connectors • McLean (VA)

Hybrid
USD 110,000 - 160,000
Security Assessment Lead
Security Assessment Lead

Ochtec • Oklahoma City (OK)

Hybrid
USD 180,000 - 240,000
Paid time off
Medical, Dental, Vision insurance
Short‑/Long-term disability and life保险
+2
Cybersecurity Engineer
Cybersecurity Engineer

Jobtailor • San Diego (CA)

On-site
USD 120,000 - 190,000
Risk and Cybersecurity Strategy Consultant
Risk and Cybersecurity Strategy Consultant

Jobtailor • Washington

On-site
USD 140,000 - 180,000
Security Assessment Lead — Senior Cyber Risk & Compliance
Security Assessment Lead — Senior Cyber Risk & Compliance

Jobtailor • Oklahoma

On-site
USD 180,000 - 230,000
Traveling DoD Cybersecurity Assessments Specialist
Traveling DoD Cybersecurity Assessments Specialist

Jobtailor • Maryland

On-site
USD 120,000 - 160,000
Risk Management Support Lead
Risk Management Support Lead

Jobtailor • Illinois

On-site
USD 120,000 - 180,000