- Location
- Linthicum Heights, MD
- Type
- Contract
- Department
- IT
- Seniority
- Senior
- Education
- Master
- Clearance
- Required
- Closing date
- Today
- Source
- ApplyToJob
Description

We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward-thinking candidates that have strong experience in operational support and can help take to the next level in a proactive stance.
Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity. We secure some of the most sensitive data for the Department of Defense and for other U.S. federal government agencies. We are known for the great care we take with clients and employees, and we believe in promoting from within.
We offer a Full Benefits package including:
- Competitive Employee Health Insurance options including dental
- 100% company paid vision plan
- 401K plan with generous company match and no vesting period
- 100% company paid life insurance
- 100% company paid long and short-term disability insurance
- Training allowance
- PTO and more
Location: Linthicum Heights, MD
Employment Type: Full-Time / Contingent Upon Contract Award
Clearance Required: TS/SCI clearance eligibility preferred;
U.S. Citizenship required
Required Certifications: Must hold a certified Information Systems Security Manager (ISSM) or equivalent credential compliant with DoD 8140/8570 requirements (e.g., CISSP, CISM, or GSLC).
Position Note
Chameleon Integrated Services is actively bidding on a proposal to provide Cyberspace Operations and Development for the Enterprise (CODE) services under the DC3 Technical, Analytical, and Business Operations (TABO) requirement. This position is contingent upon contract award.
Position Overview
Chameleon Integrated Services is seeking an ISSM / Senior Cybersecurity & GRC Lead to serve as the primary cybersecurity risk advisor to the Government Program Manager and Authorizing Official (AO).
This role requires a unique, comprehensive skill set. While you will maintain the overarching enterprise Risk Management Framework (RMF) package and lead Governance, Risk, and Compliance (GRC) efforts, you must also be deeply familiar with the live, operational cyber environment. This position encompasses overseeing technical boundaries that include penetration testing, vulnerability assessments, threat hunting, incident response, and Security Operations Center (SOC) operations.
Responsibilities
- Manage and maintain the overarching enterprise RMF package, validating the security compliance of all interconnected agency systems.
- Execute dual RMF tracks: Steady-State Continuous Monitoring for systems with existing valid ATOs, and ATO Attainment ("Get-Well") authoring for newly onboarded systems.
- Author and compile initial System Security Plans (SSPs), Security Assessment Plans, and coordinate AO-ready eMASS packages delivered within rigid 180-day windows.
- Consolidate, manage, and track the enterprise-level Plan of Action and Milestones (POA&M) on behalf of the government, providing formal Risk Acceptance recommendations to the AO.
- Guide the rapid evolution of agency networks away from a static ATO process and toward an automated Continuous ATO (cATO) framework.
- Direct and coordinate teams of Information System Security Officers (ISSOs) and technical assessors.
- Interface directly with live cyber operations to ensure vulnerability scans, automated patching windows, Infrastructure as Code (IaC) change repositories, and incident response procedures are fully compliant with DoD mandates.
- Proven track record executing the end-to-end RMF lifecycle and submitting packages through eMASS.
- Demonstrated experience writing, reviewing, or consolidating enterprise SSPs, POA&Ms, and STIG compliance documentation.
- Direct experience advising an Authorizing Official (AO) or senior government program manager on risk acceptance boundaries.
- Strong understanding of operational cybersecurity environments, including standard tools or workflows for penetration testing, threat hunting, and incident response.
- Active TS/SCI security clearance.
- Familiarity with continuous monitoring automation or cATO transition models inside a DoD enterprise.
“We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status”
Texting Privacy Policy
- Message type: Informational; you will receive text messages regarding your application and potentially regarding interview scheduling.
- No mobile information will be shared with third parties/affiliates for marketing/promotional purposes.
- Message frequency will vary depending on the application process.Msg & data rates may apply.
- OPT out at any time by texting "Stop".