Koniag Government Services

Security Lead / Release Lead (REMOTE)

Koniag Government Services  •  Remote  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Security Lead / Release Lead with a Secret security clearance to support KITS and our government customer. The position is remote.

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

Koniag IT Systems, a Koniag Government Services company, is seeking an experienced Security & Release Lead to support a critical Government Identity, Credential, and Access Management (ICAM) initiative. This role supports a large-scale Application and Systems Enablement effort issued under an ICAM Enterprise Master IDIQ Contract. The Security & Release Lead will serve as the primary authority for security compliance oversight and release management across the ICAM enablement program—ensuring that all integration solutions, platform configurations, custom tools, and application onboarding activities meet applicable DoD security requirements and that all releases into production environments are executed in a controlled, documented, and compliant manner—in direct support of the Department of Defense (DoD) Zero Trust Execution Roadmap.
The ideal candidate is an experienced security and release management professional with a strong background in federal IT security compliance, DoD cybersecurity frameworks, identity and access management, and structured release processes. This individual must be equally comfortable operating as a security subject matter expert and a disciplined release manager, capable of bridging the gap between security requirements and operational program execution in a high-volume, fast-paced federal IT environment.

This position requires an active Secret clearance and may require occasional travel to Government facilities. Primary work will be performed remotely.

The Security & Release Lead will serve as the integrated security and release management authority for the ICAM Application and Systems Enablement program, responsible for ensuring that all program activities—from initial application triage through platform configuration, middleware development, and production deployment—are executed in full compliance with applicable DoD and federal security standards, and that all releases into test and production environments follow a structured, auditable, and risk-managed release process. This individual will work closely with the program manager, deputy program manager, migration team lead, platform engineers, middleware engineers, and Government stakeholders to embed security throughout the enablement lifecycle and ensure that every production release is authorized, tested, documented, and verified prior to deployment.

Principal responsibilities will include but are not limited to:
• Serve as the primary security subject matter expert (SME) for the ICAM enablement program, providing authoritative guidance on applicable DoD and federal security requirements, policies, and frameworks across all program activities and deliverables.
• Develop, implement, and maintain the program's security compliance framework, ensuring all enablement activities, platform configurations, custom tools, connectors, middleware solutions, and integration artifacts adhere to applicable security standards including DoDI 8520.04, DoDM 8140.03, DFARS 252.204-7012, NIST SP 800-171, and all other referenced DoD and federal directives.
• Oversee and enforce Controlled Unclassified Information (CUI) handling requirements across the program, ensuring all personnel, processes, and systems comply with DoDI 5200.48, DoDM 5200.01, and applicable CUI marking, safeguarding, and dissemination requirements.
• Manage Operations Security (OPSEC) requirements across the program, ensuring OPSEC principles are incorporated into all relevant program activities, documentation, and communications in accordance with applicable DoD directives, and ensuring all subcontractors handling Critical Information comply with flowed-down OPSEC requirements.
• Lead supply chain risk management activities per DFARS 239.73, overseeing the vetting of all third-party connectors, scripts, code libraries, and enhancements integrated into the ICAM environment to prevent the introduction of cybersecurity vulnerabilities, malicious code, or unauthorized data exfiltration pathways.
• Ensure all contractor personnel maintain required DoD cybersecurity certifications per DoDM 8140.03, tracking certification status across the program team and coordinating remediation for personnel with lapsed or insufficient certifications.
• Develop, implement, and manage the program release management framework, establishing standardized processes, approval gates, documentation requirements, and rollback procedures for all releases into development, test, and production environments.
• Serve as the release authority for all production deployments, coordinating release readiness reviews with the migration team lead, platform engineers, middleware engineers, and Government stakeholders to ensure all release criteria are met prior to deployment authorization.
• Manage and oversee the configuration management process across the program, ensuring all platform configurations, custom tools, connectors, integration artifacts, and documentation are version-controlled, baselined, and maintained in accordance with the program's configuration management plan.
• Lead deficiency reporting, analysis, tracking, and resolution activities across the program, ensuring all deficiencies are identified, documented, tracked, and resolved in accordance with applicable technical orders and reporting requirements, including preparation of SF368 reports or equivalent.
• Coordinate with the Government COR and ICAM PMO on all security-related matters, including incident reporting, vulnerability disclosures, cybersecurity certification status, and security compliance findings.
• Ensure all web-based applications, user interfaces, and digital materials enabled or developed under the contract comply with Section 508 of the Rehabilitation Act of 1973, coordinating accessibility reviews and remediation activities as needed.
• Support the test program by integrating security testing requirements into the Master Test Plan and Software Test Plans, ensuring security-relevant test cases are included in all integration testing and UAT activities, and reviewing Software Test Reports for security compliance findings.
• Oversee data rights compliance across the program, ensuring all custom tools, connectors, workflows, enhancements, and documentation developed under the contract are properly identified, marked, and delivered in accordance with DFARS 252.227-7013, 252.227-7014, and 252.227-7017.
• Monitor and report on security and release management program metrics, contributing to the Enablement Tracking Database and Metrics Dashboard with relevant security compliance and release status data.
• Develop and maintain security and release management documentation, including security compliance checklists, release readiness criteria, configuration management records, deficiency logs, and OPSEC plans.
• Provide security awareness guidance and compliance coaching to program team members, ensuring all personnel understand and adhere to applicable security requirements throughout the enablement lifecycle.
• Maintain current knowledge of evolving DoD security policies, cybersecurity frameworks, identity security standards, and Zero Trust requirements, proactively applying updated knowledge to strengthen program security posture and release controls.

Education and Experience:
Required:
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field from an accredited college or university.
• Minimum of 7 years of experience in information technology, with at least 3 years of direct experience in IT security compliance, cybersecurity program management, or a related security discipline within a federal government environment.
• Minimum of 2 years of experience in release management, configuration management, or IT change management within a structured federal IT program environment.
• Demonstrated experience applying DoD cybersecurity frameworks, policies, and directives including DFARS 252.204-7012, DoDM 8140.03, NIST SP 800-171, and CUI requirements in a program execution context.
• Active Secret clearance. Must be able to satisfy requirements for CAC-card issuance and NIPRNet access, including annual DoD CyberAwareness training and certification.

Preferred:
• Prior experience supporting DoD IT programs, particularly within an ICAM, cybersecurity, or Zero Trust context.
• Experience working in a federal government IT contracting environment supporting programs with complex security compliance requirements.
• Experience managing security and release processes for programs involving large-scale application integration or enterprise identity platform deployments.

Required Skills and Competencies:
• Deep knowledge of applicable DoD and federal security requirements, policies, and frameworks, including DoDI 8520.04, DoDM 8140.03, DFARS 252.204-7012, DFARS 239.73, DoDI 5200.48, DoDM 5200.01, NIST SP 800-171, and related directives.
• Strong working knowledge of Controlled Unclassified Information (CUI) requirements, including marking, safeguarding, dissemination controls, aggregation monitoring, and compliance with applicable DoD and federal CUI directives.
• Experience developing and implementing OPSEC programs and ensuring OPSEC principles are embedded into program activities, documentation, and communications in accordance with applicable DoD directives.
• Demonstrated experience managing release management processes in a federal IT program environment, including the development and enforcement of release readiness criteria, approval gates, change control procedures, and rollback plans.
• Experience with configuration management processes and tools, including version control systems, baseline management, and change tracking in a structured federal IT program context.
• Familiarity with Identity, Credential, and Access Management (ICAM) security concepts, including identity providers (IdP), identity governance and administration (IGA), Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Zero Trust identity security principles.
• Experience conducting or overseeing supply chain risk management activities, including the security vetting of third-party code libraries, connectors, and software components integrated into federal IT environments.
• Experience with deficiency reporting processes, including preparation of SF368 reports or equivalent, deficiency tracking, and resolution coordination in a federal contracting environment.
• Demonstrated ability to coordinate security compliance activities across cross-functional teams, including engineers, program managers, and Government stakeholders.
• Strong organizational skills with the ability to manage multiple concurrent security and release management workstreams while maintaining accuracy, thoroughness, and timeliness of all compliance documentation.
• Strong communication skills in English—both written and oral—with the ability to clearly convey security requirements, compliance findings, and release management processes to both technical engineers and non-technical program stakeholders.
• Proficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams.
• Active DoD cybersecurity certification at the IAT II level or above per DoDM 8140.03 (e.g., CompTIA Security+ or equivalent).

Clearance Requirement:
• Secret clearance

Desired Skills and Competencies:
• Certified Information Systems Security Professional (CISSP) certification.
• Certified Information Security Manager (CISM) certification.
• CompTIA Security+ certification or equivalent DoD 8140.03 baseline certification at the IAT II level or above.
• Experience managing security compliance for programs involving Okta Identity Provider and SailPoint IdentityIQ platforms, including platform-level security configuration, access control enforcement, and audit logging requirements.
• Familiarity with Zero Trust Architecture (ZTA) principles and their application to security compliance and release management within a DoD context.
• Experience managing or contributing to Authority to Operate (ATO) processes, Risk Management Framework (RMF) activities, or system security plan development within a DoD or federal government context.
• Knowledge of DoD Freedom of Information Act (FOIA) requirements and their application to program documentation and data management.
• Experience managing data rights compliance in a federal contracting environment, including familiarity with DFARS 252.227-7013, 252.227-7014, and 252.227-7017.
• Familiarity with Section 508 compliance requirements for electronic and information technology, including experience coordinating accessibility reviews and remediation activities.
• Experience with CI/CD pipeline security integration, including the implementation of security gates, automated security scanning, and compliance checks within software delivery pipelines.
• Familiarity with enterprise identity protocols including SAML 2.0, OAuth 2.0, OIDC, and SCIM from a security compliance and risk management perspective.
• Experience developing and maintaining security compliance documentation including security plans, compliance checklists, risk registers, and OPSEC plans in a federal contracting environment.
• Experience with CDRL deliverable development and management in a federal contracting environment.
• Familiarity with Agile and hybrid Agile-Waterfall program execution methodologies, including experience integrating security and release management activities into sprint-based development cycles.
• Experience managing personnel cybersecurity certification tracking and compliance remediation across a multi-disciplinary program team.

Our Equal Employment Opportunity Policy
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
Koniag Government Services

About Koniag Government Services

Koniag Government Services (KGS) is an Alaska Native Corporation comprised of multiple wholly owned subsidiary companies that deliver Enterprise Solutions, Professional Services, and Operations Management to Federal Government agencies. With an agile employee and corporate culture, KGS applies its proven technical, professional, and operational expertise to enable successful mission outcomes for Defense and Civilian agencies through forward-leaning, solution-oriented business partnerships and a commitment to exceptional service delivery.

Our commitment to quality delivery is demonstrated by our independently accredited CMMI/Dev Level3, CMMI/Svc Level3, ISO 9001:2015 Quality Management System, and ISO 20001:2011 Service Management System. KGS is headquartered in Chantilly, VA with offices all over the country.

KGS is seeking qualified candidates for our open positions, but we will only extend an offer of employment after a candidate applies through the link in our job posting. If you receive a job offer via email only and have not been interviewed by the KGS hiring manager, feel free to contact KGSrecruiting@koniag-gs.com to verify its validity.

Industry
IT & Software
Company Size
1,001-5,000 employees
Headquarters
Chantilly, Virginia
Year Founded
1975
Social Media