Cyber Security Architect / Policy Lead

Saic

Virginia (MN)

Hybrid

USD 160,000 - 200,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

SAIC is seeking a Cyber Security Architect/Policy Lead who serves as the program's senior cybersecurity authority, designing and enforcing security architecture, managing the ATO/A&A lifecycle, and ensuring HELM Product Line systems comply with VA, federal, and FISMA requirements.

This role interfaces with VA ISOs, FSS, and OCS, leads RMF and Zero Trust initiatives, and supports vulnerability management and incident response to maintain ongoing compliance with FedRAMP, TIC 3.0, and VA

Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field; Master's preferred.
  • 13+ years of experience; Masters 11 years; PhD/JD 8 years equivalent.
  • 10+ years of cybersecurity experience, with at least 5 years on federal IT programs under FISMA/RMF.
  • Deep expertise in NIST SP 800-53 Rev 5, NIST SP 800-37 Rev 2 (RMF), and VA Handbook 6500.
  • Demonstrated experience obtaining and maintaining ATOs for federal information systems.
  • Proficiency with VA or federal security scanning tools (Fortify, WASA, Nessus).
  • Experience with Zero Trust Architecture principles and cloud environments (AWS, Azure, VAEC).
  • Demonstrated expertise in VA Zero Trust Architecture, TIC 3.0, and ATO compliance.
  • Knowledge of FedRAMP, FISMA, HIPAA/PHI security requirements, and VA Directive 6517 (cloud security).
  • Familiarity with CISA Binding Operational Directives (BOD 19-02, 22-01, 23-01).
  • Experience with FICAM, PIV/CAC, SAML, and identity assurance frameworks.
  • Must be eligible for VA background investigation; US-based.

Responsibilities

  • Lead development and maintenance of ATO artifacts to obtain and maintain ATO for HELM Product Line systems per NIST SP 800-37 Rev 2 and VA Handbook 6500.
  • Serve as primary technical lead for cybersecurity, ZTA, and RMF across HELM PL.
  • Participate in vulnerability scans and reviews; remediate high severity vulnerabilities.
  • Provide vulnerability reports and risk assessments per NIST SP 800-30 Rev 1.
  • Ensure cloud solutions comply with FedRAMP, VA directives and VA Zero Trust Architecture principles; TIC 3.0, IPv6.
  • Implement cloud security controls: encryption, boundary protection, audit logging, identity federation, secrets management.
  • Maintain cybersecurity policy docs, POA&Ms, and continuous monitoring artifacts.
  • Coordinate with VA ISOs, FSS, and OCS for ATO compliance and findings response.
  • Ensure all HELM systems comply with VA basic security controls and VA security memos.
  • Support FICAM/PIV logical access policy compliance (IAL 3, AAL 3, FAL 3).
  • Enforce cryptographic requirements per FIPS 140-2/140-3 and NIST SP 800-52; document protections.
  • Manage patch governance: patch management, vulnerability management, and mitigations.
  • Advise on AI/ML security implications and ensure compliance with EO/OMB memoranda.
  • Ensure contractor personnel complete VA mandatory cybersecurity training (TMS #10176).
  • Respond to security incidents; coordinate with VA PM and VA ISO within required timeframes.

Skills

NIST SP 800-53 Rev 5
NIST SP 800-37 Rev 2 (RMF)
Zero Trust Architecture
Cloud security
FIPS 140-2/140-3
PIV/CAC / FICAM
Vulnerability management
Incident response
ATO/A&A lifecycle
FedRAMP knowledge
AIO/ATO maintenance

Education

Bachelor's degree in Cybersecurity or related field
Master's degree preferred
PhD/JD with experience acceptable

Tools

Fortify
Nessus
WASA
VA security scanning tools

Job description

Description

The Cyber Security Architect/Policy Lead is the program's senior cybersecurity authority, responsible for designing and enforcing the security architecture, managing the ATO/A&A lifecycle, and ensuring all HELM Product Line systems comply with VA, federal, and FISMA cybersecurity requirements. This role also serves as the primary interface with VA Information Security Officers (ISOs), Field Security Services (FSS), and the Office of Cyber Security (OCS).

Key Responsibilities
  • Lead the development and maintenance of all Assessment and Authorization (A&A) artifacts required to obtain and maintain Authority to Operate (ATO) for all HELM Product Line systems, in accordance with NIST SP 800-37 Rev 2 and VA Handbook 6500
  • Serve as the primary technical lead for cybersecurity, Zero Trust Architecture (ZTA), and RMF compliance across the HELM PL
  • Participate in vulnerability scans and quality reviews in accordance with NIST SP 800-53 Rev 5; remediate critical and high severity vulnerabilities identified through government scans
  • Provide vulnerability scanning reports and risk assessments per NIST SP 800-30 Rev 1
  • Ensure cloud solutions comply with FedRAMP, VA Directive 6500/6517, VA Zero Trust Architecture principles, TIC 3.0, IPv6 requirements, and all VA cybersecurity policies
  • Implement required cloud security controls: encryption in transit and at rest, boundary protection, audit logging, identity federation, and secrets management
  • Develop and maintain cybersecurity policy documentation, POA&Ms, and continuous monitoring artifacts
  • Coordinate with VA ISOs, FSS, and OCS to support ATO compliance and respond to security findings
  • Ensure all HELM systems comply with VA Critical Security Controls (effective July 1, 2025) and VA Memorandum "VA Security Controls"
  • Support FICAM/PIV logical access policy compliance, including IAL 3, AAL 3, and FAL 3 assurance levels
  • Enforce cryptographic requirements per FIPS 140-2/140-3 and NIST SP 800-52; document cryptographic system protections
  • Manage patching governance: document patch management, vulnerability management, and mitigation processes
  • Advise on AI/ML security implications and ensure AI systems comply with applicable EOs and OMB memoranda (E.O. 13960, 14319, M-25-21, M-26-04)
  • Ensure all contractor personnel complete VA mandatory cybersecurity training (TMS #10176) and role-based security training
  • Respond to security incidents; coordinate with VA PM and VA Information Security Officer within required timeframes
Qualifications
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field; Master's preferred
  • Must have a Bachelors and 13 years of experience, Masters degree and 11 years of experience or a PhD or JD and 8 years of experience.
  • 10+ years of cybersecurity experience, with at least 5 years supporting federal IT programs under FISMA/RMF
  • Deep expertise in NIST SP 800-53 Rev 5, NIST SP 800-37 Rev 2 (RMF), and VA Handbook 6500
  • Demonstrated experience obtaining and maintaining ATOs for federal information systems
  • Proficiency with VA or federal security scanning tools (Fortify, WASA, Nessus, or equivalent)
  • Experience with Zero Trust Architecture principles and implementation in cloud environments (AWS, Azure, VAEC)
  • Demonstrated expertise in VA Zero Trust Architecture, TIC 3.0, and ATO compliance (required per program standards)
  • Knowledge of FedRAMP, FISMA, HIPAA/PHI security requirements, and VA Directive 6517 (cloud security)
  • Familiarity with CISA Binding Operational Directives (BOD 19-02, BOD 22-01, BOD 23-01)[43]
  • Experience with FICAM, PIV/CAC logical access, SAML, and identity assurance frameworks[36]
  • Must be eligible for VA background investigation (likely Tier 4/High Risk); must be US-based[26,29,30]
Preferred Certifications
  • CISSP-ISSAP
  • CISSP-ISSEP
  • GIAC GSLC
  • CISM
  • CompTIA Security+

Target salary range: $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Architect / Policy Lead
Cyber Security Architect / Policy Lead

Socket.dev • Town of Texas (WI)

On-site
USD 150,000 - 190,000
Senior Cyber Security Architect & RMF/Zero Trust Lead
Senior Cyber Security Architect & RMF/Zero Trust Lead

Socket.dev • Town of Texas (WI)

On-site
USD 150,000 - 190,000
Senior Cybersecurity Architect & Policy Leader
Senior Cybersecurity Architect & Policy Leader

Saic • Virginia (MN)

Hybrid
USD 160,000 - 200,000
Manager, Cyber Systems Engineering
Manager, Cyber Systems Engineering

Peraton • Herndon (VA)

On-site
USD 135,000 - 216,000
Cyber Systems Architect, Senior Advisor
Cyber Systems Architect, Senior Advisor

Peraton • Herndon (VA)

On-site
USD 140,000 - 170,000
ISSO Security Analyst, Senior
ISSO Security Analyst, Senior

Booz Allen Hamilton • McLean (VA)

On-site
USD 99,000 - 225,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Enterprise Systems Architect
Enterprise Systems Architect

Saic • Town of Texas (WI)

On-site
USD 160,000 - 200,000
Cybersecurity Engineer
Cybersecurity Engineer

CyberJobs.Com • Springfield (VA)

On-site
USD 130,000 - 140,000
Health, Dental, Vision
401(k) match
Paid time off (PTO)
+1
Cyber RMF/ATO Engineer
Cyber RMF/ATO Engineer

Integral • Tysons (VA)

Hybrid
USD 148,000 - 170,000
Medical, Dental & Vision Insurance
401(k) with immediate vesting
Paid Time Off & Holidays
+2