AYN

Cybersecurity Lead

Lucayan Technology Solutions · Remote (United States) · remote

Location: This is a US-based remote position, with approved on-site work at a U.S. military installation in Germany as needed.

- On-site travel is scheduled in advance and approved travel costs are covered.

Employment Type: Part-Time Contract

Security Clearance: Must be eligible for a DoD Common Access Card (CAC) and military base access

Status: Actively Hiring

Job Summary

We are looking for an experienced Cybersecurity Lead to direct the Risk Management Framework (RMF) and Authority to Operate (ATO) effort for a new Department of Defense emergency mass notification system. You will own the authorization package from boundary definition through AO decision support, working alongside the engineering and installation team on an accelerated schedule.

Key Responsibilities

● Lead the full RMF lifecycle: boundary definition, categorization, control selection, implementation, assessment, and authorization

● Author the SSP, control narratives, network and data-flow diagrams, and interconnection security agreements (ISAs)

● Apply STIGs/SRGs, run SCAP, Evaluate-STIG, and ACAS/Nessus scans, and maintain hardened baselines

● Manage findings, POA&Ms, patching, and IAVM records, and direct field staff on remediation

● Secure system APIs and provide cybersecurity test procedures and evidence for acceptance testing

● Prepare an eMASS-ready ATO package and support assessor reviews, AO briefings, and IATT when needed

● Deliver continuous-monitoring and patch-management plans, weekly status reports, and closeout knowledge transfer

Required Qualifications

● Legally authorized to work in the United States

● Ability to obtain a DoD CAC and military base access

● Active DoD 8570/8140 IAM Level II-compliant certification

● Minimum 5 years of DoD RMF experience, including leading systems through ATO

● Hands-on experience with eMASS, STIG/SRG compliance, ACAS, and POA&M management

● Experience writing SSPs, ISAs, and security architecture documentation

● Valid U.S. passport or ability to obtain one before travel

Preferred Qualifications

● Greenfield (new system) ATO experience

● Air Force or overseas (OCONUS) installation experience

● Familiarity with mass notification, unified communications, or VoIP systems

● Interim Authority to Test (IATT) experience

Certifications

● DoD 8570/8140 IAM Level II-compliant certification required (e.g., CISSP, CISM, CASP+/SecurityX, CGRC/CAP, GSLC, CCISO)

● DoD Cyber Awareness and Antiterrorism/Force Protection training completed upon hire

Apply on the employer’s site