Security Lead / Release Lead (REMOTE)
$31,200–$31,200 year
RemoteUnited States
Job Summary
Lead security and release management for the ICAM Application and Systems Enablement program, serving as the primary authority for DoD compliance oversight across application triage, platform configuration, middleware development, and production deployment. Develop and maintain the security compliance framework ensuring adherence to DoDI 8520.04, DoDM 8140.03, NIST SP 800-171, and CUI requirements, while overseeing supply chain risk management and contractor cybersecurity certifications. Execute controlled release processes including readiness reviews, approval gates, and rollback procedures for development, test, and production environments. Manage configuration baselining, deficiency reporting, and security awareness coaching for the program team. Coordinate with Government stakeholders and the COR on incident reporting and vulnerability disclosures. Requires an active Secret clearance and experience with federal IT security directives.
Required Qualifications
- Active Secret clearance
- Must be able to satisfy requirements for CAC-card issuance and NIPRNet access
- Must be able to complete annual DoD CyberAwareness training and certification
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field from an accredited college or university
- Minimum of 7 years of experience in information technology
- At least 3 years of direct experience in IT security compliance, cybersecurity program management, or a related security discipline within a federal government environment
- Minimum of 2 years of experience in release management, configuration management, or IT change management within a structured federal IT program environment
- Demonstrated experience applying DoD cybersecurity frameworks, policies, and directives including DFARS 252.204-7012, DoDM 8140.03, NIST SP 800-171, and CUI requirements in a program execution context
- Active DoD cybersecurity certification at the IAT II level or above per DoDM 8140.03 (e.g., CompTIA Security+ or equivalent)
- Deep knowledge of applicable DoD and federal security requirements, policies, and frameworks, including DoDI 8520.04, DoDM 8140.03, DFARS 252.204-7012, DFARS 239.73, DoDI 5200.48, DoDM 5200.01, NIST SP 800-171, and related directives
- Strong working knowledge of Controlled Unclassified Information (CUI) requirements, including marking, safeguarding, dissemination controls, aggregation monitoring, and compliance with applicable DoD and federal CUI directives
- Experience developing and implementing OPSEC programs and ensuring OPSEC principles are embedded into program activities, documentation, and communications in accordance with applicable DoD directives
- Demonstrated experience managing release management processes in a federal IT program environment, including the development and enforcement of release readiness criteria, approval gates, change control procedures, and rollback plans
- Experience with configuration management processes and tools, including version control systems, baseline management, and change tracking in a structured federal IT program context
- Familiarity with Identity, Credential, and Access Management (ICAM) security concepts, including identity providers (IdP), identity governance and administration (IGA), Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Zero Trust identity security principles
- Demonstrated experience managing supply chain risk management activities, including the security vetting of third-party code libraries, connectors, and software components integrated into federal IT environments
- Experience with deficiency reporting processes, including preparation of SF368 reports or equivalent, deficiency tracking, and resolution coordination in a federal contracting environment
- Demonstrated ability to coordinate security compliance activities across cross-functional teams, including engineers, program managers, and Government stakeholders
- Strong organizational skills with the ability to manage multiple concurrent security and release management workstreams while maintaining accuracy, thoroughness, and timeliness of all compliance documentation
- Strong communication skills in English—both written and oral—with the ability to clearly convey security requirements, compliance findings, and release management processes to both technical engineers and non-technical program stakeholders
- Proficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams
Desired Qualifications
- Prior experience supporting DoD IT programs, particularly within an ICAM, cybersecurity, or Zero Trust context
- Experience working in a federal government IT contracting environment supporting programs with complex security compliance requirements
- Experience managing security and release processes for programs involving large-scale application integration or enterprise identity platform deployments
- Certified Information Systems Security Professional (CISSP) certification
- Certified Information Security Manager (CISM) certification
- CompTIA Security+ certification or equivalent DoD 8140.03 baseline
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.