Concept Plus
Cyber Security Lead
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 11h ago · Found 11h ago
First listed today.
Salary
Not stated
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Lead
Category
Software
This employer didn't state pay. Jobs like this usually pay around $200k–$275k a year, a typical range taken from 597 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Remote (United States)"
What Nomaders makes of it
- Residency required in United States
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Concept Plus Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm.
Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty.
We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment.
For more information, visit www.conceptplus.com .
About the role
Concept Plus LLC is seeking an experienced Cybersecurity Lead to plan, implement, upgrade, and monitor security measures for the protection of all common services and cloud environments in support of an Oracle eBusiness, OCI hosted common services program. In this role, you will ensure appropriate security controls are in place to safeguard digital files and vital electronic infrastructure hosted on the Cloud One Oracle Cloud Infrastructure (OCI) platform and will serve as the contractor's primary ISSO responsible for maintaining the program's Authorization to Operate (ATO), managing the DoD Risk Management Framework (RMF) lifecycle, and sustaining SOC 1 Type 2 audit readiness. You will respond to computer security breaches, vulnerabilities, and incidents affecting the environment and embed security practices throughout the DevSecOps pipeline. A CISSP certification or higher, and demonstrated RMF experience are required. An active Secret clearance is required to start.
What you'll do
Plan, implement, upgrade, and continuously monitor security measures for the protection of all networks, systems, data, and cloud infrastructure operating within the Cloud One OCI authorization boundary
Serve as the contractor ISSO, owning the DoD RMF package lifecycle including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring for all information systems
Ensure appropriate security controls are in place and operating effectively to safeguard digital files, financial management data, and vital electronic infrastructure across all environments, in compliance with NIST SP 800-53, DISA STIGs, and applicable Cloud One security requirements
Lead and coordinate the ATO process with the Authorizing Official (AO), Security Control Assessor (SCA), and ISSM; maintain and update the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and all associated RMF artifacts on a continuous basis
Detect, respond to, and document cybersecurity incidents, breaches, and vulnerabilities affecting environments; coordinate with DISA, Cloud One, and the Government ISSM as required for incident reporting and remediation
Support SOC 1 Type 2 audit compliance for Federal Financial Management systems migrating to OCI, providing control evidence, audit artifacts, and liaison support to external auditors
Collaborate with the DevSecOps Lead to embed security scanning (SAST, DAST, container image scanning) and RMF control validation into CI/CD pipelines for continuous ATO compliance
Maintain the enterprise security posture across all environments, conducting regular vulnerability assessments, reviewing ACAS/SCAP scan results, and tracking remediation to closure within approved timelines
Monitor security controls and system configurations for compliance with applicable STIGs, CCIs, and Cloud One security policies; generate and track POA&M items to resolution
Advise the Program Manager and Technical Lead on cybersecurity risk, control gaps, and security architecture decisions, including OCI-native security services (Cloud Guard, Security Zones, OCI Vault, Bastion)
Support the development and maintenance of security-related deliverables including Security/RMF Artifacts, DR/COOP security design documentation, and recurring posture reports
Ensure near real-time Production-to-DR/COOP data replication and failover configurations meet security and data protection requirements
Coordinate foreign ownership, control, and influence (FOCI) considerations and organizational conflict of interest (COI) disclosures with program leadership as required
Support cybersecurity awareness and training to program team members and support security-related onboarding for all incoming personnel
Required Qualifications
US Citizen
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related technical field
Requirements
- ·Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related technical field
- ·5+ years of progressive information security experience in a DoD or Federal environment, including direct experience as an ISSO or equivalent role
- ·Active CISSP (Certified Information Systems Security Professional) or higher relevant certification required at time of hire
- ·Demonstrated, hands-on experience managing the DoD Risk Management Framework (RMF) lifecycle, including SSP development, control assessment, POA&M management, and ATO maintenance
- ·Experience responding to computer security breaches, vulnerabilities, and incidents in a DoD or Federal environment
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Concept Plus, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 11h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $200k to $275k per year · You'll be taken to the employer's careers page.