CISO

ECS Limited
Sierra Vista, AZ, United States
9 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Databases Monitoring of Systems Identity and Access Management Issue Tracking Systems Networking Hardware Intrusion Detection and Prevention Network Security Zero Trust Network Access Security Content Automation Protocol Security Information and Event Management
+11 more
Software Vulnerability Management Data Logging Cyber Threat Analysis Backend Information Technology Cybercrime Nessus Front End Software Development CIS Benchmarks Network Server Plan of Action and Milestones

Job description

ECS is seeking a CISO to work in our Sierra Vista, AZ office.

The Chief Information Security Officer will serve as the senior cybersecurity leader and principal security advisor to the Program Manager for The Army Endpoint Security Solution (AESS). This role is responsible for protecting the service delivery environment, including back-end and front-end security infrastructure, endpoints, servers, networks, customer-facing services, and supporting operational platforms.

The CISO will lead cybersecurity governance, risk management, information assurance, security operations, compliance, documentation, and policy activities across the program. The role provides oversight of Information Assurance and Security Operations Center personnel and ensures program alignment with DoD requirements, RMF, NIST SP 800-53, DoD security baselines, DISA STIGs, ACAS scanning, continuous monitoring, vulnerability management, and Zero Trust principles.

  • Senior security advisor to the Program Manager on cybersecurity risk, compliance, security operations, incident response, and mission assurance matters.
  • Lead the cybersecurity strategy for the AESS.
  • Oversee Information Assurance and SOC personnel, including day-to-day security operations, compliance activities, documentation, reporting, and process improvement.
  • Ensure the security of service delivery infrastructure, including endpoint security platforms, backend systems, frontend services, servers, networks, administrative access paths, and customer-facing capabilities.
  • Provide oversight of SOC, including monitoring, alert triage, incident response, threat hunting, detection engineering, escalation management, SIEM/EDR operations, and security reporting.
  • Lead Information Assurance activities, (RMF support, control documentation, evidence collection, assessment readiness, POA&M management, continuous monitoring, and security authorization support).
  • Ensure compliance with NIST SP 800-53, DoD cybersecurity requirements, DoD security baselines, DISA STIGs, ACAS scanning requirements, and applicable customer security policies.
  • Oversee vulnerability management activities, (ACAS scan coordination, findings analysis, remediation tracking, risk reporting, and compliance validation).
  • Ensure STIG compliance is implemented, documented, reviewed, and maintained across applicable endpoints, servers, applications, databases, infrastructure, and network devices.
  • Develop, maintain, and enforce cybersecurity policies, standards, plans, procedures, playbooks, runbooks, and security documentation.
  • Establish/maintain program-level cybersecurity risk management process, (risk identification, tracking, mitigation recommendations, and risk reporting).
  • Advise on security impacts of architecture changes, service enhancements, onboarding/offboarding activities, integrations, and operational changes.
  • Provide regular security posture updates to the Program Manager, customer stakeholders, and internal leadership.
  • Track/report key security metrics, (incident trends, vulnerability status, POA&M progress, compliance posture, SOC performance, and remediation activities).
  • Coordinate with endpoint engineering, infrastructure, network, systems administration, identity, cloud, service desk, compliance, and operations teams.
  • Support audits, assessments, inspections, cybersecurity reviews, and contract deliverables.
  • Mentor and guide security personnel while promoting a culture of accountability, mission support, and continuous improvement.

Requirements

  • Active Top Secret clearance.
  • Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related discipline.
  • Minimum of 12 years of cybersecurity experience.
  • Demonstrated experience supporting Department of Defense environments.
  • Experience in a senior cybersecurity leadership, information assurance, security operations, security architecture, or cyber risk management role.
  • Strong knowledge of RMF, NIST SP 800-53, DoD cybersecurity requirements, DISA STIGs, DoD security baselines, POA&M management, continuous monitoring, and vulnerability management.
  • Experience overseeing SOC activities, including security monitoring, alert triage, incident response, threat hunting, detection engineering, escalation, and reporting.
  • Familiarity with endpoint security, infrastructure security, network security, server security, identity and access management, logging, monitoring, and vulnerability management technologies.
  • Strong understanding of Zero Trust concepts and their application in enterprise or government environments.
  • Excellent written and verbal communication skills, including the ability to brief technical risk to program leadership, government customers, and non-technical stakeholders.
  • Must be local to the Sierra Vista, AZ
  • CISSP or CISM
  • ITIL Certification

Desired Skills

  • Master’s degree in cybersecurity, information assurance, computer science, information systems, business, or a related field.
  • Experience with ACAS, Nessus, SCAP, STIG Viewer, SIEM platforms, SOAR platforms, EDR tools, ticketing systems, and enterprise monitoring platforms.
  • Experience supporting DoD authorization activities, audits, inspections, cybersecurity readiness reviews, or assessment events.
  • Familiarity with DoD 8140 or DoD 8570 cybersecurity workforce requirements.
  • Experience operating within an MSP, MSSP, or multi-customer government service delivery model.
  • Experience developing executive briefings, security metrics, dashboards, compliance reports, and operational performance reporting.

The ideal candidate is a senior cybersecurity leader with deep DoD experience, strong knowledge of security operations and information assurance, and the ability to serve as the program’s principal security authority. This individual can lead teams, advise program leadership, manage cybersecurity risk, protect MSP service delivery operations, and ensure compliance across a complex endpoint security environment.

About the company

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

is the federal segment of , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We value:

  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

1:12 min

Choosing TypeScript for complex backend applications

Maximilian Otto Maximilian Otto · World Congress 2024

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all