Senior Security Risk Management Framework Engineer

atLTSRemoteUS flagUnited StatesFull-timeInsuranceSenior$110k – $125k/year

Posted 20 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Evaluate the compliance of the VA.gov Platform with VA's 18 Critical Controls and establish a baseline for implementation and identify any remaining gaps.

• Conduct security reviews, gap analyses, and risk assessments across infrastructure, pipelines, applications, and component systems.

• Assist in maintaining ongoing ATO and cATO readiness for the authorization boundary of the VA.gov Platform.

• Create, update, and sustain RMF and authorization artifacts, which include SSPs, control narratives, POA&Ms, BIAs, PTAs, and supporting evidence.

• Convert control deficiencies into prioritized technical remediation tasks for DevSecOps engineers.

• Verify engineering remediation in accordance with security-control requirements and revise authorization documentation and evidence as needed.

• Support OSCAL-based machine-readable security control models and automate evidence collection.

• Develop and streamline POA&M processes and automate the lifecycle of POA&Ms wherever possible.

• Conduct and assist with threat modeling, secure-design reviews, and security risk assessments.

• Create, coordinate, and maintain MOUs and ISAs.

• Collaborate with VA security stakeholders, AODRs/AOs, OIS, CSOC, auditors, and other authorization participants.

• Offer security guidance and consultation to VA.gov Platform and product teams.

• Produce security guidance, standards, decision trees, and training materials.

• Assist with security incident response, post-incident analysis, and subsequent remediation efforts.

• Participate in an on-call rotation for critical security incidents as required.

• Ensure ATO documentation and supporting evidence are aligned with engineering changes.


⛳️ Requirements

• Associate's degree combined with four years of relevant professional experience OR Bachelor's degree with two years of relevant professional experience OR five years of relevant Cyber Security Engineer experience in lieu of a degree.

• Must be a U.S. Citizen or Permanent Resident.

• Capability to obtain a Public Trust.

• Strong familiarity with the NIST Risk Management Framework (RMF) and NIST 800-53 security controls.

• Experience in supporting ATOs for complex information systems.

• Proficiency in performing security control assessments, gap analyses, risk assessments, and remediation planning.

• Experienced in developing and maintaining SSPs, control narratives, POA&Ms, and security authorization evidence.

• Understanding of cloud infrastructure, CI/CD pipelines, application architectures, and modern software development practices.

• Ability to translate compliance and control requirements into technical specifications and engineering backlog items.

• Experience collaborating directly with technical engineering teams on vulnerability and control remediation.

• Excellent written communication and documentation abilities.

• Capability to work alongside technical teams, security stakeholders, auditors, and government leadership.

• Preferred experience with VA cybersecurity, RMF, or ATO processes; FISMA High systems; cATO; OSCAL; AWS; Kubernetes/EKS; GitHub Actions; Infrastructure-as-Code; threat modeling; secure architecture reviews; vulnerability management; WASA/DAST; continuous security monitoring; and large federal digital platforms.


🏝️ Benefits

• Comprehensive benefits package for you and your family.

• Access to state-of-the-art tools and technologies.

• Career progression that recognizes ambition and performance.

• Opportunity to contribute to high-profile federal missions in IT and healthcare.

• A culture that promotes innovation, growth, collaboration, and quality.

People also viewed

UNIFISA ADM NACIONAL DE CONSORCIOS LTDA.17 hours ago

Commercial Sales Assistant – Auto Insurance

BR flagBrazil OnlyFull-timeInsurance
ApplyView job
Oscar Health20 hours ago

Manager, Insurance Product and Benefit Design

US flagArizona, +14 more statesFull-timeInsurance$122.2k – $160.4k/year
ApplyView job
Jerry20 hours ago

Insurance Sales and Service Associate

US flagArizona, +8 more statesFull-timeInsurance$19 – $21/hour
ApplyView job
Endurance21 hours ago

Crop Insurance Area Claims Supervisor

US flagNorth Dakota OnlyFull-timeInsurance
ApplyView job
Lightspeed Commerce22 hours ago

Director, Product & Technology Operations – Incident and Risk Management

CA flagCanada OnlyFull-timeInsurance
ApplyView job
CACI International Inc22 hours ago

SAP Process Control, Risk Management Specialist

US flagUnited States OnlyFull-timeInsurance$90.3k – $189.6k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers