Senior Cybersecurity Lead

Chameleon Integrated Services

Linthicum (MD)

On-site

USD 140,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health insurance (dental)
Vision plan (100% paid)
401K with company match
Life insurance (100% paid)
Disability insurance (100% paid)
Training allowance
PTO

Job summary

Chameleon Integrated Services seeks an ISSM / Senior Cybersecurity & GRC Lead to serve as the primary cybersecurity advisor to the Government Program Manager. You will oversee the enterprise RMF package and coordinate GRC efforts across live cyber operations.

This role requires deep experience with RMF, eMASS, SSPs, POA&M, and automated ATO processes, plus leadership of ISSOs and technical assessors to meet DoD mandates. U.S.

Qualifications

  • Proven track record implementing the RMF lifecycle and submitting packages through eMASS.
  • Experience writing or consolidating SSPs, POA&M, and STIGs.
  • Experience advising an AO or senior government PM on risk boundaries.
  • Deep knowledge of operational cybersecurity workflows including penetration testing, threat hunting, and incident response.

Responsibilities

  • Manage the enterprise RMF package and ensure system compliance.
  • Lead continuous monitoring and Get-Well authoring for new systems.
  • Prepare SSPs, Security Assessment Plans, and eMASS submissions.
  • Track POA&M and provide risk acceptance recommendations to the AO.
  • Drive automation from ATO to continuous ATO (cATO).
  • Coordinate ISSOs and assessors.
  • Interface with live cyber operations for scans, patching, IaC, and incident response.

Skills

RMF lifecycle
eMASS
SSP writing
Risk advisory
Incident response

Tools

eMASS
POA&M
SSP docs

Job description

We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward-thinking candidates that have strong experience in operational support and can help take to the next level in a proactive stance.

Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity. We secure some of the most sensitive data for the Department of Defense and for other U.S. federal government agencies. We are known for the great care we take with clients and employees, and we believe in promoting from within.

We offer a Full Benefits package including:
  • Competitive Employee Health Insurance options including dental
  • 100% company paid vision plan
  • 401K plan with generous company match and no vesting period
  • 100% company paid life insurance
  • 100% company paid long and short-term disability insurance
  • Training allowance
  • PTO and more
ISSM / Senior Cybersecurity & GRC Lead

Location: Linthicum Heights, MD
Employment Type: Full-Time / Contingent Upon Contract Award
Clearance Required: TS/SCI clearance eligibility preferred;

U.S. Citizenship required

Required Certifications:

Must hold a certified Information Systems Security Manager (ISSM) or equivalent credential compliant with DoD 8140/8570 requirements (e.g., CISSP, CISM, or GSLC).

Position Note

Chameleon Integrated Services is actively bidding on a proposal to provide Cyberspace Operations and Development for the Enterprise (CODE) services under the DC3 Technical, Analytical, and Business Operations (TABO) requirement. This position is contingent upon contract award.

Position Overview

Chameleon Integrated Services is seeking an ISSM / Senior Cybersecurity & GRC Lead to serve as the primary cybersecurity risk advisor to the Government Program Manager and Authorizing Official (AO).

This role requires a unique, comprehensive skill set. While you will maintain the overarching enterprise Risk Management Framework (RMF) package and lead Governance, Risk, and Compliance (GRC) efforts, you must also be deeply familiar with the live, operational cyber environment. This position encompasses overseeing technical boundaries that include penetration testing, vulnerability assessments, threat hunting, incident response, and Security Operations Center (SOC) operations.

Responsibilities
  • Manage and maintain the overarching enterprise RMF package, validating the security compliance of all interconnected agency systems.
  • Execute dual RMF tracks: Steady-State Continuous Monitoring for systems with existing valid ATOs, and ATO Attainment ("Get-Well") authoring for newly onboarded systems.
  • Author and compile initial System Security Plans (SSPs), Security Assessment Plans, and coordinate AO-ready eMASS packages delivered within rigid 180-day windows.
  • Consolidate, manage, and track the enterprise-level Plan of Action and Milestones (POA&M) on behalf of the government, providing formal Risk Acceptance recommendations to the AO.
  • Guide the rapid evolution of agency networks away from a static ATO process and toward an automated Continuous ATO (cATO) framework.
  • Direct and coordinate teams of Information System Security Officers (ISSOs) and technical assessors.
  • Interface directly with live cyber operations to ensure vulnerability scans, automated patching windows, Infrastructure as Code (IaC) change repositories, and incident response procedures are fully compliant with DoD mandates.
Required Skills & Qualifications
  • Proven track record executing the end-to-end RMF lifecycle and submitting packages through eMASS.
  • Demonstrated experience writing, reviewing, or consolidating enterprise SSPs, POA&M, and STIG compliance documentation.
  • Direct experience advising an Authorizing Official (AO) or senior government program manager on risk acceptance boundaries.
  • Strong understanding of operational cybersecurity environments, including standard tools or workflows for penetration testing, threat hunting, and incident response.
Preferred Qualifications
  • Active TS/SCI security clearance.
  • Familiarity with continuous monitoring automation or cATO transition models inside a DoD enterprise.

“We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status”

Texting Privacy Policy

  • Message type: Informational; you will receive text messages regarding your application and potentially regarding interview scheduling.
  • No mobile information will be shared with third parties/affiliates for marketing/promotional purposes.
  • Message frequency will vary depending on the application process.Msg & data rates may apply.
  • OPT out at any time by texting "Stop".
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Federal IT Investment & Strategic Planning Lead
Federal IT Investment & Strategic Planning Lead

Chameleon Integrated Services • Linthicum (MD)

On-site
USD 140,000 - 190,000
Health insurance
Vision plan (company paid)
401K with company match
+4
Senior DevSecOps / cATO Engineer
Senior DevSecOps / cATO Engineer

Chameleon Integrated Services • Linthicum (MD)

On-site
USD 140,000 - 180,000
Health insurance
Vision plan
401K with company match
+4
Code Services Task Lead - DC3 Operations
Code Services Task Lead - DC3 Operations

Chameleon Integrated Services • Linthicum (MD)

On-site
USD 180,000 - 230,000
Competitive Employee Health Insurance
100% company paid vision plan
401K plan with generous company match
+4
Program Manager - DC3 Operations
Program Manager - DC3 Operations

Chameleon Integrated Services • Linthicum (MD)

On-site
USD 150,000 - 190,000
Health insurance
Vision plan
401K with match
+4
Senior Data Platform & Business Intelligence Lead
Senior Data Platform & Business Intelligence Lead

Chameleon Integrated Services • Linthicum (MD)

On-site
USD 150,000 - 190,000
Health insurance
Vision plan
401K with match
+4
Senior Enterprise / Hybrid Cloud Architect
Senior Enterprise / Hybrid Cloud Architect

Chameleon Integrated Services • Linthicum (MD)

On-site
USD 130,000 - 180,000
Health insurance (dental)
Vision plan (100% paid)
401K with generous company match
+4
AI/MLOps Lead
AI/MLOps Lead

Chameleon Integrated Services • Linthicum (MD)

On-site
USD 140,000 - 190,000
Health insurance
Vision plan
401K with match and no vesting period
+4
Information System Security Manager (req-294)
Information System Security Manager (req-294)

CATHEXIS • Tysons (VA)

On-site
USD 150,000 - 195,000
Performance Bonuses
Medical Insurance
Dental Insurance
+2
Cybersecurity Lead
Cybersecurity Lead

Client Solution Architects • Washington

On-site
USD 120,000 - 160,000
Cyber Security Principal
Cyber Security Principal

Abacus Technology Corporation • Bedford (MA)

On-site
USD 150,000 - 200,000