Full-Time

Cybersecurity Lead

Updated on 9/12/2026

Concept Plus

Concept Plus

201-500 employees

IT services for federal government contracts

No salary listed

No H1B Sponsorship

Remote in USA

Remote

US Citizenship, US Top Secret Clearance Required

Bachelor's

Category
Cybersecurity (1)
Required Skills
Cybersecurity
Vulnerability Analysis
DevOps

Get referred to Concept Plus

See people who can refer or advise you

Requirements
  • U.S. citizenship is required.
  • A bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related technical field is required.
  • At least 5 years of progressive information security experience in a Department of Defense or federal environment, including direct experience as an Information System Security Officer or equivalent role, is required.
  • An active Certified Information Systems Security Professional certification or higher relevant certification is required at the time of hire.
  • Hands-on experience managing the Department of Defense Risk Management Framework lifecycle, including System Security Plan development, control assessment, Plan of Action and Milestones management, and Authorization to Operate maintenance, is required.
  • Experience implementing, upgrading, and monitoring security measures protecting computer networks and information systems is required.
  • Experience responding to computer security breaches, vulnerabilities, and incidents in a Department of Defense or federal environment is required.
  • Familiarity with National Institute of Standards and Technology Special Publication 800-53, Defense Information Systems Agency Security Technical Implementation Guides, Security Content Automation Protocol and Assured Compliance Assessment Solution scanning tools, and cloud security controls applicable to Federal Risk and Authorization Management Program and Department of Defense cloud environments is required.
  • An active Department of Defense Secret clearance is required to start and must be maintainable for the duration of the program.
Responsibilities
  • Plan, implement, upgrade, and continuously monitor security measures protecting networks, systems, data, and cloud infrastructure within the Cloud One Oracle Cloud Infrastructure authorization boundary.
  • Serve as the contractor Information System Security Officer and own the Department of Defense Risk Management Framework package lifecycle, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Ensure security controls protect digital files, financial management data, and electronic infrastructure across environments in compliance with National Institute of Standards and Technology Special Publication 800-53, Defense Information Systems Agency Security Technical Implementation Guides, and Cloud One security requirements.
  • Lead and coordinate the Authorization to Operate process with the Authorizing Official, Security Control Assessor, and Information System Security Manager; continuously maintain the System Security Plan, Plan of Action and Milestones, and associated Risk Management Framework artifacts.
  • Detect, respond to, and document cybersecurity incidents, breaches, and vulnerabilities; coordinate incident reporting and remediation with Defense Information Systems Agency, Cloud One, and the Government Information System Security Manager.
  • Support SOC 1 Type 2 audit compliance for Federal Financial Management systems migrating to Oracle Cloud Infrastructure by providing control evidence, audit artifacts, and liaison support to external auditors.
  • Collaborate with the DevSecOps Lead to embed static application security testing, dynamic application security testing, container image scanning, and Risk Management Framework control validation into continuous integration and continuous delivery pipelines.
  • Maintain enterprise security posture by conducting vulnerability assessments, reviewing Assured Compliance Assessment Solution and Security Content Automation Protocol scan results, and tracking remediation to closure.
  • Monitor security controls and system configurations for compliance with Security Technical Implementation Guides, Control Correlation Identifiers, and Cloud One security policies; generate and track Plan of Action and Milestones items to resolution.
  • Advise the Program Manager and Technical Lead on cybersecurity risk, control gaps, and security architecture decisions, including Oracle Cloud Infrastructure security services.
  • Support security-related deliverables, including Security and Risk Management Framework artifacts, disaster recovery and continuity of operations security design documentation, and recurring posture reports.
  • Ensure near-real-time production-to-disaster-recovery and continuity-of-operations data replication and failover configurations meet security and data protection requirements.
  • Coordinate foreign ownership, control, and influence considerations and organizational conflict of interest disclosures with program leadership as required.
  • Support cybersecurity awareness and training for program team members and security-related onboarding for incoming personnel.
Desired Qualifications
  • An active Top Secret security clearance is preferred.
  • Experience as an Information System Security Officer for systems operating within a Defense Information Systems Agency-managed or Cloud One environment, including familiarity with Impact Level 4 and Impact Level 5 authorization requirements and Cloud One tenancy security controls, is preferred.
  • Hands-on experience with Oracle Cloud Infrastructure security services, including Cloud Guard, Security Zones, Oracle Cloud Infrastructure Vault, Network Security Groups, and Oracle Cloud Infrastructure Bastion, is preferred.
  • Experience supporting SOC 1 Type 2 audits for Federal Financial Management systems, including evidence collection, auditor liaison, and familiarity with Federal Information System Controls Audit Manual and Federal Financial Management Improvement Act compliance, is preferred.
  • Familiarity with Oracle eBusiness Suite, Oracle Fusion Middleware, or Oracle database security hardening and patching is preferred.
  • Experience with Security Technical Implementation Guide implementation and automated compliance scanning for Oracle database and middleware products is preferred.
  • Additional Department of Defense 8140/8570 Information Assurance Manager-level certifications, such as Certified Information Security Manager, Global Information Assurance Certification Security Leadership, or Certified Chief Information Security Officer, or Information Assurance Technical-level certifications, such as CompTIA Advanced Security Practitioner Continuing Education or Certified Information Systems Auditor, are preferred.
  • Familiarity with the Department of Defense Enterprise Services Management Framework and service management security considerations is preferred.
  • Prior experience supporting Air Force Life Cycle Management Center, BES Directorate, or a Department of Defense enterprise resource planning program of record is preferred.

Concept Plus provides information technology services to the U.S. federal government and commercial clients. Its work centers on Oracle solutions, cloud computing, data analytics, and artificial intelligence, delivered through consulting and technology services to help clients modernize their IT and boost productivity. The company primarily sells core services in cloud computing, systems integration, and mobile development, using these capabilities to support digital transformation initiatives across agencies and private-sector organizations. Concept Plus distinguishes itself as a certified 8(a) disadvantaged small business backed by Blue Delta Capital Partners, which helps it win government contracts and scale through strategic investment. Its approach combines government-focused contracting with strong technical delivery to align IT services with customers’ specific needs, aiming to accelerate modernization, improve efficiency, and deliver measurable business outcomes.

Company Size

201-500

Company Stage

N/A

Total Funding

N/A

Headquarters

Fair Oaks, Virginia

Founded

2008

Get referred to Concept Plus

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • January 2026 CEMS milestone validates execution on a $33 million contract.
  • May 2026 ILER and Tradewinds wins expand health and data platforms.
  • Milad Bahrami’s January 2026 presidency signals tighter operating discipline.

What critics are saying

  • One-bid DHA awards expose weak competitive depth and pricing leverage.
  • TRICARE and ILER follow-ons in 2026 can shift to larger integrators.
  • Loss of federal set-asides or CEMS rebids would crush the business model.

What makes Concept Plus unique

  • Oracle-heavy federal modernization expertise anchors Concept Plus’s niche.
  • March 2025 CEMS win shows trusted Air Force sustainment capability.
  • 8(a) small-business status opens set-aside federal contracting lanes.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Paid Vacation

Paid Holidays

Performance Bonus

Tuition Reimbursement

Professional Development Budget

Flexible Work Hours

Growth & Insights and Company News

Headcount

6 month growth

20%

1 year growth

20%

2 year growth

16%
WashingtonExec
Nov 8th, 2023
Blue Delta Capital Partners Invests in Concept Plus | WashingtonExec

Ahmad Abuzaakouk, Concept Plus Federal IT solutions and services provider Concept Plus, LLC has received a growth investment from venture capital firm Blue ...