We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Cyber Tools Lead

Paragon Technology Group, Inc.
United States, D.C., Washington
Aug 28, 2026

Paragon Technology Group is seeking an experienced Cyber Tools Lead (CTL) to provide technical leadership and subject matter expertise for the operation, integration, modernization, and lifecycle management of an enterprise cybersecurity tool ecosystem supporting a Federal Government customer.

The Cyber Tools Lead will serve as the primary contractor technical lead for cybersecurity tools, providing technical direction to cybersecurity engineers, tool administrators, developers, and other technical personnel. The CTL will lead the architecture, engineering, integration, deployment, configuration, operation, maintenance, and optimization of cybersecurity tools and supporting technologies.

The successful candidate will be responsible for ensuring cybersecurity tools are reliable, integrated, securely configured, and optimized to support security operations, vulnerability management, continuous monitoring, risk management, compliance, and incident detection and response.

Key Responsibilities

  • Lead the architecture, engineering, integration, deployment, configuration, operation, maintenance, and optimization of enterprise cybersecurity tools and supporting technologies.
  • Provide technical leadership and oversight to cybersecurity engineers, tool administrators, developers, and other technical personnel.
  • Maintain cybersecurity tool architectures, configuration standards, integration requirements, deployment plans, operating procedures, and maintenance plans.
  • Manage and optimize capabilities supporting SIEM/log analytics, EDR/XDR, SOAR, vulnerability management, cloud security posture management, identity security monitoring, and service-management/ticketing integration.
  • Monitor tool health, availability, connector status, data ingestion, storage, capacity, licensing, and integration performance and lead resolution of outages, degradation, and other technical issues.
  • Lead upgrades, patches, migrations, modernization, technology refresh, and replacement activities while maintaining operational continuity.
  • Coordinate testing and validation of new tools, configurations, integrations, upgrades, patches, and releases prior to production implementation.
  • Lead integration of cybersecurity tools with enterprise infrastructure, cloud environments, applications, databases, identity services, security platforms, ticketing systems, dashboards, and other Government systems.
  • Develop and maintain APIs, connectors, data feeds, automation, and other mechanisms necessary to exchange cybersecurity information across systems and tools.
  • Support onboarding, validation, normalization, and monitoring of security telemetry and identify and resolve logging gaps, parser issues, ingestion failures, and data-quality problems.
  • Lead development, testing, tuning, and implementation of detection content, automation playbooks, scripts, workflows, and integrations designed to improve threat detection and response and reduce manual analyst effort.
  • Support vulnerability management capabilities, including vulnerability scanning, asset correlation, scan coverage, remediation tracking, dashboards, metrics, and reporting.
  • Support cloud security posture management, including security baselines, cloud logging, identity events, configuration findings, detection content, and compliance reporting.
  • Develop and maintain dashboards, metrics, reports, and automated workflows that provide stakeholders with visibility into cybersecurity posture, vulnerabilities, risks, compliance, and operational performance.
  • Identify opportunities to automate repetitive cybersecurity processes, improve data accuracy, reduce manual effort, and increase operational efficiency.
  • Ensure cybersecurity tools are configured and maintained in accordance with applicable Federal cybersecurity requirements, Department policies, Government security standards, vendor guidance, and approved technical baselines.
  • Support cybersecurity tool security assessments, authorization activities, vulnerability remediation, configuration management, change management, and continuous monitoring.
  • Coordinate cybersecurity tool requirements and activities with system owners, ISSOs, security engineers, network and cloud teams, application teams, enterprise architects, cybersecurity operations personnel, vendors, and other stakeholders.
  • Identify technical risks, dependencies, capability gaps, end-of-life technologies, and other issues affecting the cybersecurity tool environment and recommend mitigation strategies.
  • Evaluate emerging cybersecurity technologies and provide recommendations concerning adoption, integration, consolidation, modernization, or replacement of existing capabilities.
  • Support cybersecurity tool acquisition and technical evaluations, including development and review of technical requirements, specifications, capability assessments, proofs of concept, and evaluation criteria.
  • Maintain accurate technical documentation, configuration information, inventories, licenses, dependencies, interfaces, SOPs, runbooks, architecture diagrams, and other operational records.
  • Provide cybersecurity tool status, performance metrics, technical risks, capability gaps, accomplishments, and recommendations to Government and contractor leadership.

Required Qualifications

  • Bachelor's degree and a minimum of eight (8) years of relevant experience.
  • CISSP or equivalent cybersecurity certification.
  • Demonstrated experience supporting enterprise cybersecurity tools in Federal Government or similarly regulated environments.
  • Demonstrated technical leadership experience overseeing cybersecurity engineering, administration, integration, and sustainment activities.
  • Experience with multiple enterprise cybersecurity technology areas, such as:
    • SIEM and security log management
    • SOAR and security automation
    • EDR/XDR
    • Vulnerability management and scanning
    • Cloud security and CSPM
    • Identity security and monitoring
    • Security dashboards, metrics, and reporting
    • APIs, connectors, integrations, and data feeds
  • Experience troubleshooting complex issues involving cybersecurity tool availability, performance, integrations, data quality, interoperability, and scalability.
  • Experience planning and implementing cybersecurity tool upgrades, migrations, integrations, and modernization efforts.
  • Knowledge of cybersecurity configuration management, change management, continuous monitoring, vulnerability management, and security assessment/authorization processes.
  • Working knowledge of applicable Federal cybersecurity frameworks and requirements, including FISMA, NIST RMF, NIST SP 800-53, Zero Trust guidance, CISA directives, and FedRAMP requirements where applicable.
  • Strong written and verbal communication skills with the ability to communicate technical issues, risks, recommendations, and performance information to both technical personnel and Government decision-makers.

Preferred Qualifications

  • Experience leading cybersecurity tool operations in a large, distributed hybrid environment spanning on-premises, cloud, endpoint, identity, application, and network environments.
  • Hands-on experience with enterprise SIEM, SOAR, EDR/XDR, vulnerability management, CSPM, or comparable security platforms.
  • Experience developing or integrating security automation, APIs, scripts, connectors, workflows, and data pipelines.
  • Experience with detection engineering, security telemetry management, log-source onboarding, normalization, and data-quality validation.
  • Experience developing security dashboards, operational metrics, compliance reports, and executive-level cybersecurity reporting.
  • Experience supporting RMF, FISMA assessments, audit evidence collection, and continuous monitoring in a Federal environment.
  • Experience coordinating technical activities across cybersecurity operations, infrastructure, cloud, application, identity, and enterprise architecture teams.

Work Location

The position may primarily be performed remotely; however, because the Cyber Tools Lead is designated as Key Personnel, the individual must reside within reasonable commuting distance of the Government facility at State Annex 17 (SA-17), 600 19th Street NW, Washington, D.C., and be available for onsite meetings or mission-critical support as required.

Applied = 0

(web-665cd84569-nr9qh)