
Cyber Security Architect – Policy Lead
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Texas, +1 more state.
• Oversee the creation and upkeep of Assessment and Authorization documents to secure and sustain Authority to Operate (ATOs) for HELM Product Line systems.
• Act as the principal technical authority for cybersecurity, Zero Trust Architecture, and Risk Management Framework (RMF) compliance.
• Engage in vulnerability assessments and quality evaluations; address critical and high-severity vulnerabilities.
• Deliver vulnerability scanning results and risk evaluation reports.
• Guarantee that cloud solutions align with FedRAMP, VA directives, VA Zero Trust Architecture principles, TIC 3.0, IPv6 requirements, and VA cybersecurity regulations.
• Implement cloud security measures, including encryption, boundary protection, audit logging, identity federation, and secrets management.
• Create and uphold cybersecurity policies, Plans of Action and Milestones (POA&Ms), and continuous monitoring documentation.
• Collaborate with VA Information Security Officers (ISOs), Field Security Services (FSS), and Office of Cyber Security (OCS) regarding ATO compliance and security issues.
• Ensure HELM systems adhere to VA Critical Security Controls and the VA Security Controls memorandum.
• Assist with FICAM/PIV logical access policy adherence, including Identity Assurance Level (IAL) 3, Access Assurance Level (AAL) 3, and Federated Assurance Level (FAL) 3.
• Enforce cryptographic standards under FIPS 140-2/140-3 and NIST SP 800-52.
• Oversee patch management governance, vulnerability control, and mitigation strategies.
• Provide guidance on the security ramifications of AI/ML and relevant executive orders and OMB memoranda.
• Ensure that contractor staff fulfill mandatory VA cybersecurity and role-based security training requirements.
• Address security incidents and liaise with the VA Project Manager and Information Security Officer within stipulated timelines.
• Serve as the main point of contact for VA Information Security Officers, Field Security Services, and the Office of Cyber Security.
• Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or a related field.
• A Master's degree and PhD/JD are alternative educational paths with corresponding experience requisites.
• 13 years of experience with a bachelor's degree, 11 years with a master's degree, or 8 years with a PhD/JD.
• Over 10 years of experience in cybersecurity.
• At least 5 years of support for federal IT programs under FISMA/RMF.
• In-depth knowledge of NIST SP 800-53 Rev 5, NIST SP 800-37 Rev 2 (RMF), and VA Handbook 6500.
• Proven track record of obtaining and maintaining ATOs for federal information systems.
• Proficient in VA or federal security scanning tools, including Fortify, WASA, Nessus, or equivalent.
• Experience with Zero Trust Architecture principles and their implementation in AWS, Azure, or VAEC.
• Demonstrated expertise in VA Zero Trust Architecture, TIC 3.0, and ATO compliance.
• Understanding of FedRAMP, FISMA, HIPAA/PHI security requirements, and VA Directive 6517.
• Familiarity with CISA Binding Operational Directives BOD 19-02, BOD 22-01, and BOD 23-01.
• Experience with FICAM, PIV/CAC logical access, SAML, and identity assurance frameworks.
• Must qualify for a VA background investigation, likely Tier 4/High Risk.
• Must be based in the United States.
• Preferred certifications include CISSP-ISSAP, CISSP-ISSEP, GIAC GSLC, CISM, and CompTIA Security+.
• Remote work arrangement.
• Equal Opportunity Employer.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.