Cyber Security Architect / Policy Lead

SAIC

United States

Remote

USD 160,000 - 200,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SAIC is seeking a Cyber Security Architect / Policy Lead to serve as the program's senior cybersecurity authority. You will design and enforce security architecture, manage the ATO/A&A lifecycle, and ensure HELM Product Line systems meet VA, federal, and FISMA requirements.

You will interface with VA ISOs, FSS, and OCS to address findings and maintain compliance. The role emphasizes Zero Trust, RMF, and cloud security across AWS/Azure environments, with premiums on policy development,

Qualifications

  • Bachelor's degree in Cybersecurity or related field required; Master's preferred.
  • 10+ years of cybersecurity experience with 5+ years in federal IT/RMF programs.
  • Experience obtaining and maintaining federal ATOs.
  • Deep expertise in NIST SP 800-53 Rev 5 and 800-37 Rev 2; VA Handbook 6500.
  • Proficiency with VA/federal security scanning tools (Fortify, WASA, Nessus).
  • Experience with Zero Trust Architecture in cloud environments (AWS, Azure).
  • Demonstrated VA Zero Trust Architecture, TIC 3.0, and ATO compliance knowledge.
  • Familiarity with FedRAMP, FISMA, HIPAA/PHI, and VA cloud security directives.
  • Knowledge of FICAM, PIV/CAC, SAML, and identity assurance frameworks.
  • US-based and eligible for VA background investigation.

Responsibilities

  • Lead A&A artifact development to obtain and maintain ATO for HELM Product Line systems.
  • Serve as technical lead for cybersecurity, ZTA, and RMF compliance.
  • Conduct vulnerability scans and remediate high-severity findings per NIST SP 800-53 Rev 5.
  • Provide vulnerability reports and risk assessments per NIST SP 800-30 Rev 1.
  • Ensure cloud solutions comply with FedRAMP and VA/ZTA policies.
  • Implement encryption, boundary protection, audit logging, and identity federation.
  • Develop and maintain cybersecurity policy docs, POA&Ms, and monitoring artifacts.
  • Coordinate with VA ISOs, FSS, and OCS for ATO support and findings.
  • Ensure compliance with VA Critical Security Controls and VA security memoranda.
  • Support FICAM/PIV logical access levels and EO/OMB policy alignment.
  • Oversee patch governance and vulnerability management processes.
  • Advise on AI/ML security and regulatory EO implications.
  • Ensure VA training compliance for contractors and staff.
  • Respond to security incidents within required timeframes.

Skills

NIST SP 800-53 Rev 5
RMF/SP 800-37 Rev 2
Zero Trust Architecture
VA/Fed security controls
PIV/CAC/SSO concepts
FIPS 140-2/140-3 cryptography
Vulnerability management
A&A/ATO processes
Cloud security (AWS/Azure)
SAML/Identity assurance
Background investigation (Tier 4)

Education

Bachelor's degree in Cybersecurity / Information Assurance
Master's degree preferred

Tools

Fortify
WASA
Nessus

Job description

Cyber Security Architect / Policy Lead
Job Description

Description

Position Summary: The Cyber Security Architect/Policy Lead is the program's senior cybersecurity authority, responsible for designing and enforcing the security architecture, managing the ATO/A&A lifecycle, and ensuring all HELM Product Line systems comply with VA, federal, and FISMA cybersecurity requirements. This role also serves as the primary interface with VA Information Security Officers (ISOs), Field Security Services (FSS), and the Office of Cyber Security (OCS).

Key Responsibilities

  • Lead the development and maintenance of all Assessment and Authorization (A&A) artifacts required to obtain and maintain Authority to Operate (ATO) for all HELM Product Line systems, in accordance with NIST SP 800-37 Rev 2 and VA Handbook 6500
  • Serve as the primary technical lead for cybersecurity, Zero Trust Architecture (ZTA), and RMF compliance across the HELM PL
  • Participate in vulnerability scans and quality reviews in accordance with NIST SP 800-53 Rev 5; remediate critical and high severity vulnerabilities identified through government scans
  • Provide vulnerability scanning reports and risk assessments per NIST SP 800-30 Rev 1
  • Ensure cloud solutions comply with FedRAMP, VA Directive 6500/6517, VA Zero Trust Architecture principles, TIC 3.0, IPv6 requirements, and all VA cybersecurity policies
  • Implement required cloud security controls: encryption in transit and at rest, boundary protection, audit logging, identity federation, and secrets management
  • Develop and maintain cybersecurity policy documentation, POA&Ms, and continuous monitoring artifacts
  • Coordinate with VA ISOs, FSS, and OCS to support ATO compliance and respond to security findings
  • Ensure all HELM systems comply with VA Critical Security Controls (effective July 1, 2025) and VA Memorandum "VA Security Controls"
  • Support FICAM/PIV logical access policy compliance, including IAL 3, AAL 3, and FAL 3 assurance levels
  • Enforce cryptographic requirements per FIPS 140-2/140-3 and NIST SP 800-52; document cryptographic system protections
  • Manage patching governance: document patch management, vulnerability management, and mitigation processes
  • Advise on AI/ML security implications and ensure AI systems comply with applicable EOs and OMB memoranda (E.O. 13960, 14319, M-25-21, M-26-04)
  • Ensure all contractor personnel complete VA mandatory cybersecurity training (TMS #10176) and role-based security training
  • Respond to security incidents; coordinate with VA PM and VA Information Security Officer within required timeframes

Qualifications

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field; Master's preferred
  • Must have a Bachelors and 13 years of experience, Masters degree and 11 years of experience or a PhD or JD and 8 years of experience.
  • 10+ years of cybersecurity experience, with at least 5 years supporting federal IT programs under FISMA/RMF
  • Deep expertise in NIST SP 800-53 Rev 5, NIST SP 800-37 Rev 2 (RMF), and VA Handbook 6500
  • Demonstrated experience obtaining and maintaining ATOs for federal information systems
  • Proficiency with VA or federal security scanning tools (Fortify, WASA, Nessus, or equivalent)
  • Experience with Zero Trust Architecture principles and implementation in cloud environments (AWS, Azure, VAEC)
  • Demonstrated expertise in VA Zero Trust Architecture, TIC 3.0, and ATO compliance (required per program standards)
  • Knowledge of FedRAMP, FISMA, HIPAA/PHI security requirements, and VA Directive 6517 (cloud security)
  • Familiarity with CISA Binding Operational Directives (BOD 19-02, BOD 22-01, BOD 23-01) [43]
  • Experience with FICAM, PIV/CAC logical access, SAML, and identity assurance frameworks [36]
  • Must be eligible for VA background investigation (likely Tier 4/High Risk); must be US-based [26,29,30]

Preferred Certifications

  • CISSP-ISSAP
  • CISSP-ISSEP
  • GIAC GSLC
  • CISM
  • CompTIA Security+

Target salary range: $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Overview

SAIC accepts applications on an ongoing basis and there is no deadline.

SAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.

We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion.

For more information, visit saic.com. For ongoing news, please visit newsroom.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Architect / Policy Lead
Cyber Security Architect / Policy Lead

Saic • Town of Texas (WI)

On-site
USD 160,000 - 200,000
Cybersecurity Architect / Policy Lead
Cybersecurity Architect / Policy Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 183,000 - 199,000
Healthcare Benefits
Remote Work Options
Paid Time Off
+9
Senior Cyber Security Architect - RMF, Zero Trust & ATO Lead
Senior Cyber Security Architect - RMF, Zero Trust & ATO Lead

Saic • Town of Texas (WI)

On-site
USD 160,000 - 200,000
Information System Security Engineer
Information System Security Engineer

SAIC • McLean (VA)

On-site
USD 120,000 - 160,000
Zero Trust Cyber Architect & RMF Policy Lead
Zero Trust Cyber Architect & RMF Policy Lead

SAIC • United States

Remote
USD 160,000 - 200,000
Senior Business Development Leader - Cyber Focus
Senior Business Development Leader - Cyber Focus

SAIC • United States

Remote
USD 160,000 - 200,000
Remote work option
Travel opportunities
ISSO Security Analyst, Senior
ISSO Security Analyst, Senior

Booz Allen Hamilton • McLean (VA)

On-site
USD 99,000 - 225,000
Cybersecurity Engineer
Cybersecurity Engineer

CACI International • High Point (NC)

On-site
USD 72,000 - 150,000
Information Systems Security Officer II
Information Systems Security Officer II

SAIC • United States

Hybrid
USD 80,000 - 120,000
Cloud Security Architect / Engineer
Cloud Security Architect / Engineer

9th Way Insignia • Washington

On-site
USD 98,000 - 150,000