> Markdown version of [/jobs/ext/3050348-lead-security-consultant](https://www.wearedevelopers.com/jobs/ext/3050348-lead-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Consultant - **Company:** Kratos Defense & Security Solutions, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Cyber Security, Information Systems, Identity and Access Management, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Red Team (Cyber Security), SC Clearance, 3-tier Architectures - **Published:** September 24, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9188862/lead-security-consultant ## About the Role The ideal candidate will have a deep understanding of how to apply the principles of information security in a variety of circumstances and expertise translating security requirements into common technical implementations. Experience working across multiple compliance frameworks (CMMC, FedRAMP, DoD SRG, NIST, PCI, ISO, HIPAA, SOC, CJIS, etc.) is highly desirable. As a Lead, you are expected to guide teammates, drive solutioning discussions, and ensure deliverable excellence across engagements., * Cybersecurity Experience: 6 or more years of hands-on work in a cybersecurity role (e.g., CISO, Red Team member, SOC analyst). * Management Experience: 6 or more years of experience in a management or leadership role. * Assessment/Audit Experience: 3 or more years participating on teams conducting internal or external compliance audits. * CMMC Lead Certified Assessor (LCCA) * Tier 3 suitability (or Secret clearance or higher) * Ability and willingness to learn and support other security compliance frameworks. * Ability to successfully pass security framework certification requirements. * Broad based IT background with a technical understanding of networks, protocols, security configuration, cryptography and identity and access management. * Excellent communication skills, both written and verbal, including an ability to translate technical concepts and issues into non-technical or layman's terms. * Ability to successfully deliver on multiple, simultaneous tasks. * An active, Secret clearance is required Preferred Skills and Experience * Local to the Washington DC metro area * Certified Information Security Manager (CISM) * Certified Information Systems Security Officer (CISSO) * Certified Penetration Testing Engineer (CPTE) * Cybersecurity Analyst+ (CySA+) * Federal IT Security Professional-Auditor (FITSP-A) * GIAC Cloud Security Automation (GCSA) * Certified Information Systems Auditor (CISA) * Certified Information Systems Security Professional (CISSP) * CISSP - Information Systems Security Engineering Professional (CISSP-ISSEP) * GIAC Security Leadership Certification (GSLC) * GIAC Systems and Network Auditor (GSNA) ## Description General * Maintain expert-level knowledge of the CMMC framework, including practice requirements, assessment methodology, and authoritative interpretation of technical and non?technical controls. * Regularly obtain continuing education necessary to maintain certifications and meet qualification requirements. * Proactively maintain up?to?date knowledge of industry trends, threat activity, and evolving security technologies to enhance skills and abilities. * Independently and proactively communicate progress on tasks, deliverables, and schedule impacts to clients and internal leadership. * Apply rigorous quality control practices to all work products in advance of quality assurance review, ensuring deliverables meet Kratos quality and QMS standards. * Take ownership of opportunities to improve current service offerings and contribute to continuous improvement of assessment processes, documentation, and methodologies. * Mentor peers and junior team members by sharing assessment techniques, evidence evaluation strategies, and control interpretation guidance. Assessor * Lead assessments and project tasks as a Lead CCA or RP, ensuring teams stay aligned with project scope, schedule, and quality expectations. * Provide critical input and leadership in the development of assessment artifacts, including Assessment Plans, Daily Checkpoint Logs, Risk Traceability Matrices, and Security Assessment Reports and briefings. * Conduct client interviews across all security requirements with no preparation needed, while supporting other team members during their interviews. Resolve control interpretation issues in real time for clients and teammates. * Collaborate effectively within dynamic teams and across multiple customer organizations with diverse personalities and expertise to drive agreement on complex issues. * Document successful and unsuccessful security practice implementations accurately, clearly articulating test methods, evidence sources, and interpretations aligned with CMMC methodology. * Cross?walk multiple sources of evidence (artifacts, demonstrations, interviews, tests) to assess maturity and sufficiency of practice implementation throughout an organization. * Own documentation quality, producing client?ready materials and providing constructive peer reviews to strengthen overall team output. Advisor * Conduct diagnostic and discovery sessions to gain an enterprise-level understanding of security architecture, inheritance, boundaries, and practice implementations. * Leverage deep understanding of security controls and technical architectures to identify gaps, develop supporting documentation, and propose both technical and operational remediation solutions. * Work with internal and external stakeholders to assess security compliance gaps and guide organizations toward solutions that align with CMMC, NIST SP 800?171, and relevant regulatory requirements. * Provide consultative reviews of security documentation, offering authoritative remediation or enhancement recommendations. * Lead collaborative discussions within dynamic teams and across multiple customer organizations to drive agreement on complex issues. * Research customer questions and deliver clear, accurate, authoritative guidance, ensuring alignment with CMMC interpretive expectations and Kratos QMS requirements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)