Skip to content

Principal Security Lead (6850)

MetroStar

Tysons Corner, VA$220,000 – $250,000 a year

Applying for this one?

We write the CV against this exact posting — its wording, its requirements — not a template with your name in it.

Get my CV for this job

$25, one-time. No subscription.

As the Principal Security Team Lead, you are the main senior POC for all security related items for the overall program. You will lead and support government clients through the full lifecycle of obtaining and maintaining Authority to Operate (ATO) for their information systems. Leveraging your expertise in federal cybersecurity standards and regulations, you will assess system security posture, manage compliance activities and monitor, analyze, and respond to potential security risks and incidents. The ideal candidate brings deep expertise in AWS security, identity and access management, security monitoring, secure software development, and regulatory frameworks such as NIST, RMF, and FedRAMP, while providing technical leadership and guidance across engineering teams. In this role, you will ensure client systems meet stringent ATO requirements while maintaining alignment with government‐specific cybersecurity frameworks, policies, and best practices. You are also the leader for approximately 6-8 members of the Security Team.

We know that you can’t have great technology services without amazing people. At MetroStar, we are obsessed with our people and have led a two-decade legacy of building the best and brightest teams. Because we know our future relies on our deep understanding and relentless focus on our people, we live by our mission: A passion for our people. Value for our customers.

If you think you can see yourself delivering our mission and pursuing our goals with us, then check out the job description below!

What you’ll do:

  • Lead the overall cybersecurity strategy, architecture, and implementation for mission-critical applications and data platforms in classified cloud environments.
  • Partner with engineering, architecture, and program teams to ensure security requirements are integrated throughout solution design, development, deployment, and operations.
  • Drive security governance activities, including risk assessments, compliance efforts, security reviews, and audit readiness across applicable government security frameworks.
  • Oversee security monitoring, incident response, and threat mitigation efforts to maintain a strong security posture and address emerging risks.
  • Serve as the primary security advisor to technical and business stakeholders, providing guidance on security best practices, architecture decisions, and operational risk management.
  • Mentor and provide technical leadership to engineering teams while helping establish security standards, roadmaps, and long-term strategic objectives.
  • Partner with government stakeholders to gain a deep understanding of system architectures, security requirements, and mission objectives related to achieving and sustaining Authority to Operate (ATO) in compliance with federal regulations.
  • Perform comprehensive security assessments and risk analyses aligned with government compliance standards, identifying system vulnerabilities, threat vectors, and areas of risk specific to federal and classified environments.
  • Monitor security tools, logs, and network activity in accordance with government cybersecurity guidelines to detect suspicious behavior, potential intrusions, or unauthorized access attempts.
  • Collaborate with cross functional technical teams to design, implement, and maintain government aligned security controls, including firewalls, intrusion detection/prevention systems, encryption mechanisms, and access controls.
  • Investigate and analyze security incidents, determining root cause, scope, impact, and appropriate remediation actions.
  • Develop, execute, and refine incident response plans, including containment, eradication, recovery, and post incident analysis to strengthen security posture and prevent recurrence.
  • Provide team leadership for the 6-8 members of the Security team, delegating work, providing coaching and guidance, and constructive feedback for professional development.

What you’ll need to succeed:

  • Active TS/SCI clearance with CI Polygraph.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related technical field.
  • 10+ years of cybersecurity experience supporting federal government systems, including extensive hands-on experience with Risk Management Framework (RMF), Authority to Operate (ATO) authorization packages, and continuous ATO sustainment activities.
  • Strong experience as a Team Lead, leading and managing a small (6-8 FTE) team of Security professionals. Ability to delegate and track work across the team to meet overall outcomes. People leadership experience to coach team members, conduct performance evaluations, and provide career development guidance.
  • Strong experience working as part of a larger IT solution/development effort, working with the technical leads to raise security considerations as part of the design process (rather than addressing later in the lifecycle)
  • Deep expertise with federal cybersecurity frameworks, standards, and compliance requirements, including NIST SP 800-53, RMF, ICD 503, FISMA, FedRAMP, and associated security overlays, with demonstrated success achieving and maintaining ATOs for cloud-based systems operating in IL5, IL6, SIPR, and JWICS environments.
  • Experience partnering with architects, engineers, and software development teams to integrate security requirements throughout system design, cloud architecture, and the software development lifecycle (SDLC), including secure design and secure coding practices.
  • Hands-on experience implementing and assessing security controls for cloud and data-centric solutions, including Zero Trust architectures, authentication and authorization frameworks (OAuth 2.0, OIDC, SAML), identity and access management (IAM) platforms, and fine-grained access control models such as Attribute-Based Access Control (ABAC) and row-level security.
  • Experience designing, deploying, and securing applications leveraging AWS cloud services within IL6+ classified environments.
  • Hands-on experience with cybersecurity operations, risk management, and continuous monitoring capabilities, including eMASS, Xacta, vulnerability management tools, intrusion detection/prevention systems, and log aggregation and analysis platforms such as Splunk.
  • CISSP or equivalent DoD 8140 IAT Level III certification

SALARY RANGE: $220,000 - $250,000

The salary range for this position is determined based on qualifications, skills, and relevant experience. The final salary offered will be determined based on several factors including:

  • The candidate's professional background and relevant work experience
  • The specific responsibilities of the role and organizational needs
  • Internal equity and alignment with current team compensation
  • This role is also eligible for additional compensation, subject to the terms and policies of MetroStar, which may include:
  • Performance-based bonuses
  • Company-paid training and/or certifications
  • Referral bonuses

Application Deadline: Applications will be accepted on a rolling basis until the position is filled; candidates are encouraged to apply as early as possible for full consideration.

Additional Compensation: This role may also be eligible for bonuses and/or additional incentives based on individual and company performance.

Benefits: All full-time employees are eligible to participate in our benefits programs:

  • Health, dental, and vision insurance
  • 401(k) retirement plan with company match
  • Paid time off (PTO) and holidays
  • Parental Leave and dependent care
  • Flexible work arrangements
  • Professional development opportunities
  • Employee assistance and wellness programs

Like we said, we are big fans of our people. That’s why we offer a generous benefits package, professional growth, and valuable time to recharge. Learn more about our company culture code and benefits. Plus, check out our accolades.

Commitment to Non-Discrimination All qualified applicants will receive consideration for employment based on merit and without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.

What we want you to know:

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

Not ready to apply now?

Sign up to join our newsletter here.

Seen 2 hours ago · MetroStar postings close after a median of 5 days.

Original posting on MetroStar's site ↗

Posting text belongs to the employer. Removal requests: contact us.

One job at a time

One posting. One CV. $25.

Pick the job you actually want and we write for it.

Get my CV for this job