
Cybersecurity Engineer – System Steward
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States.
• Deliver cybersecurity consulting and technical assistance to VA stakeholders for ATO, security authorization, and NIST RMF initiatives.
• Assist with RMF Steps 1–7, encompassing security categorization, control implementation, assessment, authorization, and ongoing monitoring.
• Lead and coordinate security and privacy efforts within project teams.
• Create and maintain necessary RMF security artifacts and authorization documentation.
• Develop and sustain Incident Response, Contingency Planning, Disaster Recovery, POA&M, and other essential security documents.
• Examine authorization packages and security artifacts to pinpoint gaps, formulate remediation plans, and collaborate with system stakeholders for resolution.
• Execute security risk assessments, impact analyses, gap assessments, compensating control evaluations, and residual risk assessments.
• Evaluate IT products, operating systems, and security configurations for adherence to NIST SP 800-53 and relevant security policies.
• Formulate and enforce security controls while assisting in the remediation of identified vulnerabilities and compliance issues.
• Aid in security configuration and compliance efforts for infrastructure, operating system images, and IT product deployments.
• Prepare and deliver security reports, briefings, risk assessments, and recommendations to both technical and non-technical audiences.
• Collaborate with system administrators, developers, system owners, ISSOs, and internal/external clients to evaluate the security implications of hardware, software, and configuration modifications.
• Undertake additional tasks and responsibilities as necessary to support team objectives and ensure project success.
• Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, or a related discipline.
• Over 5 years of information security experience, including at least 3 years focused on cybersecurity and cloud security for a large government agency.
• Extensive experience in supporting NIST RMF, ATO, security authorization, and continuous monitoring efforts.
• Background in developing RMF security artifacts, implementing security controls, and managing POA&Ms.
• Familiarity with NIST SP 800-53, security compliance, GRC, and federal cybersecurity policies and practices.
• Experience in conducting security assessments, risk analyses, gap assessments, impact assessments, and vulnerability evaluations.
• Proficiency in cloud security and FedRAMP, including IaaS, PaaS, SaaS, and shared security responsibilities.
• Knowledge of security assessment and vulnerability tools such as Tenable Nessus, Nmap, SCAP, and Wireshark.
• Experience with ServiceNow Continuous Authorization and Monitoring (CAM) or similar security/GRC platforms.
• Understanding of network security, software development, systems engineering, cloud architecture, and infrastructure security.
• Strong skills in documentation, analysis, presentation, communication, and stakeholder coordination.
• Capability to translate technical cybersecurity requirements into actionable recommendations.
• Eligibility to obtain government clearance.
• Experience with the VA or other government entities.
• Required: ISC2 CISSP certification.
• Required: One or more certifications from the following categories: IAT II, IAM II, or IASAE II.
• Currently, we are unable to provide sponsorship.
• Selected candidates will need to complete fingerprinting at a government facility and undergo a background check as part of the hiring process.
• Medical/Dental/Vision.
• PTO + Federal Holidays.
• Corporate Laptop.
• Training opportunities.
• 401(k) with employer match.
• Remote work options.
Northern Arizona Healthcare
SkyGrid
Motional
Get handpicked remote jobs straight to your inbox weekly.