Cybersecurity Architect / Policy Lead

TISTA Science and Technology Corporation

Rockville (MD)

Hybrid

USD 183,000 - 199,000

Full time

48 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Healthcare Benefits
Remote Work Options
Paid Time Off
Training/Certification opportunities
HSA / FSA
Life Insurance
Disability Insurance
401K Match
Tuition Reimbursement
Employee Assistance Program
Paid Holidays
Military Leave

Job summary

TISTA Science and Technology Corporation in Rockville, MD is seeking a Cyber Security Architect / Policy Lead to guide security architecture, policy interpretation, and ATO strategy across a diverse portfolio of applications for the VA DevSecOps program.

The role requires 12+ years in information security with 5+ years in architecture or policy leadership, plus strong experience with NIST RMF and VA security frameworks. Remote CONUS options and strong benefits accompany this mission-driven role.

Qualifications

  • 12+ years of information security experience, including 5+ years as a security architect or security policy lead supporting federal IT programs.
  • 5+ years of hands-on experience with the NIST Risk Management Framework and ATO lifecycle, including authoring and defending A&A packages.
  • Demonstrated expertise with VA Zero Trust Architecture, TIC 3.0, VA Handbook 6500, VA Critical Security Controls, NIST security frameworks, and VA ICAM/PIV requirements.
  • Experience securing hybrid environments spanning legacy applications, SaaS, cloud platforms, and containerized workloads.
  • Experience integrating security into Agile and DevSecOps delivery, including CI/CD security controls, SAST/DAST, SBOM, and vulnerability management.
  • Experience with security and privacy requirements involving PHI/PII and federal healthcare environments.
  • VA OIT, VHA, or other federal health cybersecurity experience strongly preferred.

Responsibilities

  • Lead cybersecurity architecture, policy interpretation, Zero Trust alignment, and ATO strategy across the product line.
  • Define security requirements and architecture for legacy applications, SaaS platforms, cloud environments, containers, APIs, and system integrations.
  • Lead ATO and Risk Management Framework activities and ensure required security and privacy controls are incorporated throughout delivery.
  • Establish security standards and automated security controls within Agile and DevSecOps pipelines.
  • Partner with VA security stakeholders, Product Owners, architects, engineers, and program leadership to identify and resolve security risks and delivery blockers.
  • Lead vulnerability management, security risk, incident response, and remediation governance.
  • Develop and maintain reusable security architecture, Zero Trust, ATO, and security-by-design standards and practices.
  • Provide cybersecurity leadership, technical guidance, and mentorship across delivery teams.
  • Contribute to TISTA’s cybersecurity practice, business growth, and continuous improvement initiatives.

Skills

Cybersecurity architecture
Security policy
Zero Trust
DevSecOps
Risk Management Framework

Education

Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering
Master’s degree

Tools

SAST/DAST
SBOM
CI/CD security controls

Job description

Overview

TISTA is seeking a Cyber Security Architect / Policy Lead to support the Department of Veterans Affairs (VA) Supply Chain Management DevSecOps program. This Key Personnel role will lead cybersecurity architecture, Zero Trust alignment, security policy, and Authority to Operate (ATO) strategy across a portfolio of legacy, cloud, SaaS, and modernized applications.

The Cyber Security Architect / Policy Lead will partner with VA security stakeholders and Agile delivery teams to establish security requirements, integrate security into DevSecOps delivery, manage ATO readiness, and support secure modernization across the product line.

At TISTA, you’ll do meaningful, mission-driven work that improves lives alongside teammates you trust and leaders who are transparent and supportive. We invest in your learning and internal mobility so you can build a career that keeps advancing. We’re proud to serve and hire Veterans, and we put people first in everything we do.

TISTA associates enjoy above Industry Healthcare Benefits, Remote Working Options, Paid Time Off, Training/Certification opportunities, Healthcare Savings Account & Flexible Savings Account, Paid Life Insurance, Short-term & Long-term Disability, 401K Match, Tuition Reimbursement, Employee Assistance Program, Paid Holidays, Military Leave, and much more!

Responsibilities
  • Lead cybersecurity architecture, policy interpretation, Zero Trust alignment, and ATO strategy across the product line.
  • Define security requirements and architecture for legacy applications, SaaS platforms, cloud environments, containers, APIs, and system integrations.
  • Lead ATO and Risk Management Framework activities and ensure required security and privacy controls are incorporated throughout delivery.
  • Establish security standards and automated security controls within Agile and DevSecOps pipelines.
  • Partner with VA security stakeholders, Product Owners, architects, engineers, and program leadership to identify and resolve security risks and delivery blockers.
  • Lead vulnerability management, security risk, incident response, and remediation governance.
  • Develop and maintain reusable security architecture, Zero Trust, ATO, and security-by-design standards and practices.
  • Provide cybersecurity leadership, technical guidance, and mentorship across delivery teams.
  • Contribute to TISTA’s cybersecurity practice, business growth, and continuous improvement initiatives.
Qualifications
  • 12+ years of information security experience, including 5+ years as a security architect or security policy lead supporting federal IT programs.
  • 5+ years of hands-on experience with the NIST Risk Management Framework and ATO lifecycle, including authoring and defending A&A packages.
  • Demonstrated expertise with VA Zero Trust Architecture, TIC 3.0, VA Handbook 6500, VA Critical Security Controls, NIST security frameworks, and VA ICAM/PIV requirements.
  • Experience securing hybrid environments spanning legacy applications, SaaS, cloud platforms, and containerized workloads.
  • Experience integrating security into Agile and DevSecOps delivery, including CI/CD security controls, SAST/DAST, SBOM, and vulnerability management.
  • Experience with security and privacy requirements involving PHI/PII and federal healthcare environments.
  • VA OIT, VHA, or other federal health cybersecurity experience strongly preferred.
Certifications:
  • CISSP-ISSEP required or must be obtained within 12 months of hire.
  • CISSP-ISSAP required.
Education:
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related field.
  • Master’s degree preferred.
Clearance:
  • Tier 2 / Moderate Risk Background Investigation; ability to obtain a VA PIV credential.
Location:
  • Rockville, MD / Remote (CONUS).
Pay Range:
  • The suggested pay for this position ranges from $182,546 to $198,875.
  • The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location.
  • Also, certain positions are eligible for additional forms of compensation, such as bonuses.
  • TISTA associates are eligible to participate in our comprehensive benefits plan! More information can be found here: https://tistatech.com/working-at-tista/
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Risk Lead
Cyber Security Risk Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 193,000 - 201,000
Healthcare benefits
Remote working
Paid time off
+9
DevSecOps Engineer
DevSecOps Engineer

TISTA Science and Technology Corporation • United States

Remote
USD 161,000 - 176,000
Remote working options
Paid Time Off
401K Match
+4
Solution Technical Lead
Solution Technical Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 173,000 - 187,000
Industry healthcare benefits
Remote working options
Paid time off
+9
Enterprise/Solution System Architect
Enterprise/Solution System Architect

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 172,000 - 190,000
Remote Working Options
Paid Time Off
Training/Certification opportunities
+10
Overarching Program Lead
Overarching Program Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 186,000 - 202,000
Healthcare benefits
Remote work options
Paid time off
+9
Solution System Architect
Solution System Architect

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 171,000 - 183,000
Healthcare benefits
Remote work options
Paid time off
+2
Data Architect Lead
Data Architect Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 171,000 - 189,000
Healthcare benefits
Remote working options
Paid time off
+2
Engineer Solution Lead
Engineer Solution Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 171,000 - 183,000
Remote working options
Healthcare benefits
Paid time off
+6
IT Program Manager
IT Program Manager

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 176,000 - 189,000
Intake Lead
Intake Lead

TISTA Science and Technology Corporation • Rockville (MD)

Hybrid
USD 148,000 - 160,000
Healthcare benefits
Remote option
Paid time off
+7