> Markdown version of [/jobs/ext/2115769-cybersecurity-program-lead-mass](https://www.wearedevelopers.com/jobs/ext/2115769-cybersecurity-program-lead-mass). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Program Lead - MASS - **Company:** Applied Research Solutions - **Location:** Dayton, OH, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Identity and Access Management, Information Systems Security Engineering Professional, Systems Development Life Cycle, Secure Coding, Information Technology, Patch Management, Scap Compliance Checker, Devsecops, Vulnerability Analysis - **Published:** August 19, 2026 - **Apply:** https://recruiting.ultipro.com/APP1013ARSS/JobBoard/d7bd66ed-d867-48a4-879e-5b0f95b51ad5/OpportunityDetail?opportunityId=c80a1ad7-1e75-41b2-a03a-46774a2abe16 ## About the Role * US Citizenship Required * Security Clearance: Must possess an active Top-Secret clearance with SCI eligibility. * Experience: A minimum of 8-10 years of progressive experience in cybersecurity, with at least 3 years in a leadership or management role for a DoD or IC program. * Education: A Bachelor of Science (B.S.) degree from an accredited institution in Cybersecurity, Computer Science, Information Technology, or a related engineering field. * RMF Expertise: Demonstrated, hands-on experience leading a system through the DoD RMF process to a successful ATO decision. * DoD 8570/8140 Certification: Must meet IAT Level III or IAM Level II requirements with an active certification, such as CISSP (preferred), CISM, or CASP+. * Classified Environment Experience: Proven experience working in TS/SCI environments and a strong understanding of the unique security challenges and procedures on networks like JWICS., * Advanced Degree: A Master of Science (M.S.) degree in Cybersecurity, Information Assurance, or a related technical field. * Advanced Certifications: Higher-level certifications such as CISSP-ISSEP (Information Systems Security Engineering Professional) or a Project Management Professional (PMP). * Technical Tooling: Hands-on experience with security tools such as ACAS, HBSS, SCAP Compliance Checker, and the eMASS platform. * Secure Development: Experience integrating cybersecurity into the full system development lifecycle (DevSecOps) and familiarity with secure coding practices. * Cross-Domain Solutions (CDS): Experience with the design, accreditation, and operation of Cross-Domain Solutions. * Program Management: Experience managing budget and schedule for a technical team. All positions at Applied Research Solutions are subject to background investigations. Employment is contingent upon successful completion of a background investigation including criminal history and identity check. ## Description Applied Research Solutions seeks an experienced and strategic leader to serve as our Cybersecurity Integrated Product Team (IPT) Lead. This is a senior-level position responsible for safeguarding our critical national security systems. You will lead a dedicated team of cybersecurity professionals and be given the authority and resources to build and execute a comprehensive cybersecurity strategy. Your primary mission will be to ensure the system achieves and maintains its Authority to Operate (ATO) within a highly classified environment, while proactively managing risk and ensuring mission readiness. This role requires a unique blend of deep technical expertise, proven leadership, and mastery of DoD accreditation processes. This is a challenging but rewarding position that places you at the center of our program's success. If you are a cybersecurity leader ready to take on a critical national security mission, I look forward to reviewing your application., * Leadership and Management: Lead, mentor, and manage the Cyber IPT, overseeing all cybersecurity-related tasks, schedules, and resources to ensure program objectives are met. * Cybersecurity Strategy: Develop, implement, and maintain the Program's Cybersecurity Strategy, ensuring alignment with overarching DoD, Intelligence Community, and program-specific requirements. * Risk Management Framework (RMF): Shepherd the COMPASE system through the entire RMF lifecycle, from system categorization and control selection to assessment, authorization, and continuous monitoring. * Accreditation and Authorization (A&A): Act as the primary liaison with the Authorizing Official (AO), Security Control Assessor (SCA), and other security stakeholders. Prepare and manage all necessary documentation to achieve and maintain the system's ATO. * Security Documentation Creation and Review: Support required documentation, such as SCGs and SSPs * Technical Oversight: Direct and oversee all technical security activities, including vulnerability scanning (e.g., ACAS), Security Technical Implementation Guide (STIG) implementation, patch management, and the mitigation of security findings. * High-Side Operations: Ensure all cybersecurity operations, testing, and monitoring are conducted in accordance with policies governing the Joint Worldwide Intelligence Communications System (JWICS) and other high-side environments. * Stakeholder Engagement: Regularly brief program leadership and government customers on the system's cybersecurity posture, risks, and mitigation strategies. * Other duties as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)