IT Security Lead

LMI Consulting, LLC

United States

On-site

USD 134,367 - 232,404

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

LMI Consulting, LLC is seeking an IT Security Lead to support a GSA project. The role focuses on defining and enforcing the security and compliance approach for cloud-based acquisitions systems, aligning with NIST, FedRAMP, and TIC guidance.

The candidate will drive ATO lifecycle activities in AWS, integrate DevSecOps into Agile delivery, and collaborate with ITSOs to ensure continuous security controls and real-time risk visibility.

Qualifications

  • Experience leading federal IT programs.
  • 400 characters
  • Hands-on AWS security and cloud controls.
  • Experience guiding ATO processes.

Responsibilities

  • Define security architecture and compliance for cloud-based apps.
  • Collaborate with GSA security personnel on controls.
  • Ensure secure SDLC with DevSecOps practices.
  • Maintain SSPs, POA&Ms, and audit readiness.
  • Monitor for threats and ensure least privilege access.

Skills

Federal security
NIST guidance
FedRAMP
DevSecOps
AWS security
ATO lifecycle
Security governance
Communication

Tools

CI/CD tooling
Cloud security services

Job description

IT Security Lead

Job Location: US-Remote

Overview

LMI is seeking an experienced Security Lead to support a key client at the General Services Administration (GSA) in delivering a modern web‑based acquisitions system. The initiative modernizes Governmentwide Indefinite Delivery Vehicle (IDV) contracting through modular, API‑driven services deployed in federal cloud environments.

The Security Lead will serve as the senior authority responsible for defining and enforcing the program’s security and compliance approach in alignment with GSA requirements. This individual must possess a comprehensive understanding of the Authorization to Operate (ATO) process for cloud applications and collaborate closely with the client’s Information Technology Security Officers (ITSOs) to ensure the development team adheres to approved security controls and compliance standards.

The ideal candidate combines deep federal security expertise, hands‑on cloud security experience in AWS, and the ability to integrate DevSecOps practices into modern Agile software delivery. The position is anticipated to be majority remote but requires travel to Washington, D.C. as frequently as needed.

Responsibilities
  • Security Strategy & Governance: Serve as the primary authority for system security architecture and compliance.
  • Collaborate with GSA security personnel to define and implement security and compliance controls required for cloud‑based applications.
  • Ensure development teams adhere to approved security architecture and control implementations.
  • Establish and maintain security documentation, policies, and procedures aligned with federal standards.
  • Ensure compliance with FISMA and agency‑specific security policies governing federal information systems.
  • ATO & Federal Compliance: Lead the system through the full Authorization to Operate (ATO) lifecycle.
  • Develop and maintain System Security Plans (SSPs), security control documentation, and supporting artifacts.
  • Manage Plans of Action and Milestones (POA&Ms) and track remediation activities.
  • Support security control assessments and coordinate responses to findings.
  • Align controls with guidance from NIST, FedRAMP requirements, and TIC/cloud security guidance.
  • DevSecOps & CI/CD Integration: Embed automated security controls into CI/CD pipelines to enable secure, continuous delivery.
  • Ensure static and dynamic code analysis, dependency scanning, container security, and infrastructure‑as‑code validation are integrated into build and deployment processes.
  • Promote secure coding practices and continuous monitoring across development teams.
  • Cloud Security (AWS): Lead security architecture for applications and infrastructure deployed within AWS cloud environments.
  • Configure and manage native AWS security services (IAM, Security Hub, GuardDuty).
  • Enforce least privilege access controls and secure identity and access management practices.
  • Monitor cloud environments for threats, misconfigurations, and vulnerabilities.
  • Risk Management & Audit Readiness: Conduct security risk assessments and oversee vulnerability scanning and penetration testing activities.
  • Manage security incident response coordination and reporting.
  • Maintain continuous monitoring practices and ensure audit readiness for all system components.
  • Support ongoing authorization and continuous ATO practices through automated control monitoring and real‑time risk visibility.
  • Track, report, and mitigate identified risks throughout the system lifecycle.
  • Team & Stakeholder Collaboration: Mentor development teams on security requirements and secure coding standards.
  • Partner closely with team leadership to align security with system architecture and delivery timelines.
  • Communicate security risks, compliance status, and remediation strategies clearly to both technical and non‑technical stakeholders.
Qualifications

Required Qualifications

  • Experience as a Security Lead (or equivalent role) on federal IT programs.
  • Hands‑on experience implementing federal security architectures aligned with NIST guidance, FedRAMP, and TIC/cloud security requirements.
  • Track record leading systems through the full ATO lifecycle, including SSP development and POA&M management.
  • Integration of security controls into CI/CD pipelines consistent with DevSecOps principles.
  • Expert knowledge securing applications and infrastructure in AWS cloud environments.
  • Experience conducting risk assessments, vulnerability management, and maintaining audit readiness.
  • Strong written and verbal communication skills.

Desired Qualifications

  • Experience supporting GSA or other federal cloud modernization initiatives.
  • Relevant certifications (e.g., CISSP, CCSP, AWS Security Specialty, Security+).
  • Experience supporting systems at moderate or high impact levels under federal security frameworks.
  • Familiarity with continuous monitoring tools and automated compliance validation solutions.
Salary

The target salary range for this position is $134,367 - $232,404.

Individual salaries are determined by various factors including location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.

Eligibility

Applicants must meet eligibility requirements for a U.S. Government security clearance. Only U.S. Citizens are eligible for a security clearance. LMI will only consider applicants with security clearances or who are eligible for security clearances.

Equal Opportunity

LMI is an Equal Opportunity Employer. LMI is committed to the fair treatment of all and to our policy of providing applicants and employees with equal employment opportunities. LMI recruits, hires, trains, and promotes people without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, pregnancy, disability, age, protected veteran status, citizenship status, genetic information, or any other characteristic protected by applicable federal, state, or local law. If you are a person with a disability needing assistance with the application process, please contact accommodations@lmi.org.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Lead
IT Security Lead

LMI • United States

Hybrid
USD 134,000 - 233,000
Technical Lead
Technical Lead

LMI Consulting, LLC • United States

On-site
USD 163,020 - 280,944
Remote Federal Security Lead - Cloud & DevSecOps
Remote Federal Security Lead - Cloud & DevSecOps

LMI Consulting, LLC • United States

On-site
USD 134,367 - 232,404
Technical Lead
Technical Lead

LMI • United States

On-site
USD 163,000 - 281,000
Senior Technical Lead: Cloud, DevSecOps & Federal Standards
Senior Technical Lead: Cloud, DevSecOps & Federal Standards

LMI Consulting, LLC • United States

Remote
USD 163,020 - 280,944
Cybersecurity Information System Security Engineer - Clearance Required
Cybersecurity Information System Security Engineer - Clearance Required

LMI Consulting, LLC • Fort Belvoir (VA)

On-site
USD 92,075 - 158,138
Artificial Intelligence Lead
Artificial Intelligence Lead

LMI Consulting, LLC • United States

On-site
USD 148,301 - 255,653
Artificial Intelligence Lead
Artificial Intelligence Lead

LMI • United States

Hybrid
USD 148,000 - 256,000
Information Assurance Specialist - Clearance Required
Information Assurance Specialist - Clearance Required

LMI Consulting, LLC • United States

On-site
USD 149,000 - 182,000
Cybersecurity Engineer
Cybersecurity Engineer

LMI • Tysons (VA)

On-site
USD 140,000 - 170,000