Lead Cybersecurity Assessor/Technical Lead

1 day ago


Washington, Washington, D.C., United States Aretum Full time

Public Trust Eligibility Required

This is a contingent position, meaning employment is dependent upon the successful award of the associated contract to Aretum and completion of any required background investigation or security clearance verification.

About Aretum

Aretum is a mission-driven organization committed to delivering innovative, technology-enabled solutions to our customers across defense, civilian, and homeland security sectors. Our teams work at the intersection of strategy, technology, and transformation, helping agencies solve their most critical challenges. We believe in investing in our people and creating a culture where collaboration, inclusion, and professional growth are at the forefront. 

Job Summary

The Lead Cybersecurity Assessor / Technical Lead is responsible for leading independent cybersecurity assessments and audits of government information systems, with a focus on validating the effectiveness of management, operational, and technical security controls and identifying vulnerabilities that impact mission and compliance. This role plans and executes assessments in alignment with federal risk management and control assessment practices, ensuring controls are implemented correctly, operating as intended, and producing the desired outcomes for security and privacy requirements.

Due to the nature of our work as a federal consulting organization, employees may be expected to handle Controlled Unclassified Information (CUI) and must adhere to applicable safeguarding and compliance requirements.  

Responsibilities

  • Lead end-to-end delivery of cybersecurity assessments/audits of government systems, including assessment planning, evidence collection, technical testing, analysis, and reporting
  • Develop and execute Security Assessment Plans (SAP) and ensure assessment procedures align to required control assessment methodologies
  • Conduct and oversee technical testing activities (e.g., vulnerability scanning, penetration testing, configuration validation, and other security examinations) and translate results into clear, actionable findings
  • Evaluate the effectiveness of security controls (including inherited/common controls where applicable) and document whether controls meet intent and requirements
  • Produce high-quality deliverables (e.g., Security Assessment Reports/SARs, risk narratives, remediation recommendations) and support POA&M development and closure evidence
  • Provide technical leadership to assessors (tasking, mentorship, peer review, quality assurance, and consistency of methodology across engagements)
  • Partner with project leadership to manage scope, schedules, dependencies, and risks; communicate project status and constraints to stakeholders
  • Brief technical and non-technical stakeholders on risk, severity and prioritized remediations, and advise on practical mitigation strategies
  • Maintain professionalism and independence expected of assessment personnel and ensure assessments are defensible and audit-ready

Requirements

  • Minimum 7 years of experience conducting cybersecurity assessments, audits, or control assessments in government or regulated environments
  • Demonstrated experience across project management, network design concepts, and testing the security of government systems to identify vulnerabilities
  • Strong working knowledge of federal control assessment and risk management practices
  • Ability to develop/execute assessment of test plans and document results with clear pass/fail rationale and remediation guidance
  • Strong technical writing skills and experience producing assessment deliverables for audit/ATO packages and compliance reviews
  • Experience supporting A&A / authorization activities and maintaining audit-ready security documentation (e.g., SSP/SAP/SAR/POA&M)
  • Familiarity with common federal assessment artifacts and roles, including coordinating with system owners and stakeholders to execute assessments and record results
  • Experience leading teams delivering multiple concurrent assessments in enterprise environments (on-prem, cloud, hybrid)

Preferred Qualifications

  • Bachelor's degree in information systems, Computer Science, or related field
  • Preferred Certifications{{:}}

  • GIAC Web Application Penetration Tester (GWAPT)

  • Certified Ethical Hacker (CEH)
  • GIAC Systems and Network Auditor (GSNA)
  • Certified Penetration Tester (CPT)
  • Certified Expert Penetration Tester (CEPT)
  • GIAC Certified Web Application Defender (GWEB)
  • Offensive Security Certified Professional (OSCP)
  • CREST Penetration Testing Certifications

Travel Requirements

This is a hybrid position, with work performed both remotely and at designated client or corporate locations, as needed. Travel requirements may vary depending on project assignments, client meetings, or internal collaboration and will be communicated in advance whenever possible. 

EEO Statement

Aretum is committed to fostering a workplace rooted in excellence, integrity, and equal opportunity for all. We adhere to merit-based hiring practices, ensuring that all employment decisions are made based on qualifications, skills, and ability to perform the job, without preference or consideration of factors unrelated to job performance.

As an Equal Opportunity Employer, Aretum complies with all applicable federal, state, and local employment laws.

We are proud to support our nation's veterans and military families, providing career opportunities that honor their service and experience.

If you require reasonable accommodation during the hiring process due to a disability, please contact

for assistance.

Equal Opportunity Employer/Veterans/Disabled

U.S. Work Authorization

Due to federal contract requirements, only U.S. citizens are eligible for this position. This position supports a federal government contract and requires the ability to obtain and maintain a Public Trust or Suitability Determination, depending on the agency's background investigation requirements.  

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off
  • Family Leave (Maternity, Paternity)
  • Short Term & Long-Term Disability
  • Training & Development


  • Washington, Washington, D.C., United States ASSYST, Inc. Full time

    ASSYST is seeking a Cybersecurity Operations Technical Lead for our upcoming project in Washington D.C. The candidate will possess a deep technical mastery of security infrastructure and a proven track record of managing complex SOC environments. Job location: Washington D.C. or Maryland Requirements: Technical Experience & ExpertiseProfessional...

  • Cybersecurity Lead

    1 week ago


    Washington, Washington, D.C., United States Dhara Consulting Group Full time

    Posted todayTop Secret/SCI$120,800 - $265,800PolygraphIT - SecurityWashington, DC (ON-SITE/OFFICE)Cybersecurity Lead Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph Employee Type: Regular Percentage of Travel Required: Up to 25% Type of Travel: Continental US * * * The...


  • Washington, Washington, D.C., United States Ellumen, Inc Full time

    Lead Cybersecurity Specialist and Training AnalystLocation: Onsite – 1200 New Jersey Ave SE, Washington, DC 20590(Offsite work permitted only with prior written approval from the COR)Position OverviewThe Lead Cybersecurity Specialist and Training Analyst provides technical leadership in the design, management, and deployment of cybersecurity data...


  • Washington, Washington, D.C., United States ASRC Federal Full time

    ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to WorkSummaryThe Space Communications and Navigation (SCaN)...


  • Washington, Washington, D.C., United States Tyto Athene Full time

    :Tyto Athene is searching for a dynamic Senior Cybersecurity Policy Analyst Team Lead to support our Federal Customer in Washington, DC.Responsibilities:Serve as part of a team lead supporting the CISO knowledgeable in the field of information assurance and Cybersecurity Policy Analyst.Participate in working groups and cybersecurity committees that are...


  • Washington, Washington, D.C., United States ClearanceJobs Full time

    Overview Steampunk wants you to be a Cloud Security Control Assessor on our team to support a government customer. The primary responsibilities for the position are to support all security assessment activities that ensure risk with in the system is maintained at an acceptable level. The nature of the work requires that the candidate demonstrates initiative,...


  • Washington, Washington, D.C., United States WASHINGTON COUNTY HOSPITAL AND CLINICS Full time

    Job Details Job Location: Washington Co Hospital - Washington, IA 52353 Position Type: Full Time Job Shift: Any Job Category: Health CareSUMMARYThe Systems Support Technical Lead is responsible for overseeing the daily operations of end-user technology support, ensuring the reliability, performance, security, and usability of systems across the organization....


  • Washington, Washington, D.C., United States beBeeArchitect Full time

    Job Title: Proposal Architect LeadDescription:We are seeking an experienced Proposal Architect to lead our team in crafting and submitting compelling proposals for U.S. Government contracts.Main Responsibilities:To develop, write and edit all submission types including RFPs, RFIs, BAAs, OTAs and SBIRsTo manage critical government contracting compliance by...


  • Washington, Washington, D.C., United States Banner Health Full time $41 - $68

    Department Name: IT Network ServicesWork Shift: DayJob Category:Information TechnologyEstimated Pay Range:$ $68.19 / hour, based on location, education, & experience.In accordance with State Pay Transparency Rules.Banner Health was named to Fortune's Most Innovative Companies in America 2025 list for the third consecutive year and named to Newsweek's list of...


  • Washington, Washington, D.C., United States Alpha Omega Full time

    Job DetailsDescriptionJob Title:Cybersecurity EngineerClearance Required:ActiveSecret ClearanceWork Location:RemoteKey ResponsibilitiesThe Cybersecurity Engineer develops policies and procedures to ensure in the Cybersecurity IT environment information systems reliability and accessibility and to prevent and defend against unauthorized access to systems,...