Remote Senior RMF Engineer: Security & Compliance

LTS

Northern (KY)

Hybrid

USD 110,000 - 125,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Remote work

Job summary

LTS is seeking a Senior Security RMF Engineer to join a cybersecurity transformation surge team supporting the VA.gov Platform. This role bridges VA security/RMF requirements and engineers implementing those controls across VA.gov, requiring hands-on security control implementation in cloud and CI/CD environments.

You will develop RMF artifacts, support ATO/cATO readiness, translate deficiencies into engineering work, and automate evidence collection.

Qualifications

  • Associate’s degree + four years of relevant professional experience OR Bachelor’s degree + two years of relevant professional experience OR five years of relevant Cyber Security Engineer experience in lieu of a degree.
  • Strong experience with NIST Risk Management Framework (RMF) and NIST 800-53 security controls.
  • Experience supporting ATOs for complex information systems.
  • Experience performing security control assessments, gap analyses, risk assessments, and remediation planning.
  • Experience developing and maintaining SSPs, control narratives, POA&Ms, and security authorization evidence.
  • Ability to understand cloud infrastructure, CI/CD pipelines, application architectures, and modern software-development practices well enough to evaluate how security controls are actually implemented.
  • Ability to translate compliance/control requirements into specific technical requirements and engineering backlog items.
  • Experience working directly with technical engineering teams on vulnerability and control remediation.
  • Strong written communication and documentation skills.
  • Ability to work with technical teams, security stakeholders, auditors, and government leadership.

Responsibilities

  • Assess VA.gov Platform compliance with the 18 Critical Controls identified by VA and help establish a baseline of current implementation and remaining gaps.
  • Perform security reviews, gap analyses, and risk assessments across VA.gov Platform infrastructure, pipelines, applications, and component systems.
  • Support ongoing ATO and cATO readiness for the VA.gov Platform authorization boundary.
  • Develop, update, and maintain RMF and authorization artifacts, including System Security Plans (SSPs), control narratives, POA&Ms, BIAs, PTAs, and supporting evidence.
  • Evaluate identified control deficiencies and work with DevSecOps engineers to translate them into prioritized technical remediation work.
  • Validate completed engineering remediation against applicable security-control requirements and update supporting authorization documentation and evidence.
  • Support implementation of OSCAL-based, machine-readable security control models and automated evidence collection.
  • Develop and maintain POA&M processes and support automation of the POA&M lifecycle where feasible.
  • Conduct and support threat modeling, secure-design reviews, and security risk assessments.
  • Develop, coordinate, and maintain Memorandums of Understanding (MOUs) and Interconnection Security Agreements (ISAs) as required.
  • Coordinate with VA security stakeholders, AODRs/AOs, OIS, CSOC, auditors, and other authorization stakeholders.
  • Provide security guidance and consultation to VA.gov Platform and product teams.
  • Help develop security guidance, standards, decision trees, and training that allow product teams to better understand and own their security responsibilities.
  • Support security incident response, post-incident analysis, and identification of resulting security/control remediation.
  • Participate in an on-call rotation for critical security events as required.
  • Ensure ATO documentation and supporting evidence remain synchronized with technical changes implemented by the engineering team.
  • The PWS specifically requires the team to determine current compliance with VA's Critical Controls, collaborate with the team managing the existing ATO, and ensure authorization documentation is updated as technical work is completed.

Skills

NIST RMF
NIST 800-53
Cloud security
Threat modeling
Security automation
Vulnerability remediation
Written communication

Education

Associate's degree + 4 years
Bachelor's degree + 2 years
Cyber Security Engineer experience (5 years in lieu of degree)

Tools

AWS
Kubernetes
GitHub Actions
Infrastructure as Code

Job description

LTS is seeking a Senior Security RMF Engineer to join a cybersecurity transformation surge team supporting the VA.gov Platform. This role bridges VA security/RMF requirements and engineers implementing those controls across VA.gov, requiring hands-on security control implementation in cloud and CI/CD environments.

You will develop RMF artifacts, support ATO/cATO readiness, translate deficiencies into engineering work, and automate evidence collection.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior RMF Engineer: Cloud Security & ATO Readiness
Senior RMF Engineer: Cloud Security & ATO Readiness

LTS • United States

Remote
USD 110,000 - 125,000
Comprehensive benefits
Career growth opportunities
Access to cutting-edge tools
Senior Security Risk Management Framework Engineer New United States - Remote
Senior Security Risk Management Framework Engineer New United States - Remote

LTS • Northern (KY)

Hybrid
USD 110,000 - 125,000
Remote work
Senior Security Risk Management Framework Engineer
Senior Security Risk Management Framework Engineer

LTS • United States

Remote
USD 110,000 - 125,000
Comprehensive benefits
Career growth opportunities
Access to cutting-edge tools
Lead Security Engineer – Federal RMF & On-Prem DevSecOps
Lead Security Engineer – Federal RMF & On-Prem DevSecOps

analyticallc • Bethesda (MD)

On-site
USD 140,000 - 210,000
Employer paid health care
Training and development funds
401k match
+1
RMF/ATO Cyber Engineer for VA Compliance
RMF/ATO Cyber Engineer for VA Compliance

Integral • Tysons (VA)

Hybrid
USD 148,000 - 170,000
Medical, Dental & Vision Insurance
401(k) with immediate vesting
Paid Time Off & Holidays
+2
Remote Senior ISSO — RMF & NIST 800-53 Lead
Remote Senior ISSO — RMF & NIST 800-53 Lead

AnaVation, LLC • Washington

Remote
USD 140,000 - 190,000
Medical insurance
Dental insurance
Disability insurance
+6
Remote Senior Software & Security Engineer (RMF/ATO)
Remote Senior Software & Security Engineer (RMF/ATO)

Applied Training Solutions • United States

On-site
USD 140,000 - 195,000
Federal RMF & Governance Engineer | Cloud Security Lead
Federal RMF & Governance Engineer | Cloud Security Lead

CALIBRE Systems, Inc. • Washington

Hybrid
USD 125,000 - 145,000
Remote Cybersecurity Engineer - RMF/ATO Expert
Remote Cybersecurity Engineer - RMF/ATO Expert

Mind Computing, Inc. • Northern (KY)

Hybrid
USD 110,000 - 170,000
Medical/Dental/Vision
PTO + Federal Holidays
Corporate Laptop
+3
Senior DevSecOps Platform Engineer — Kubernetes & RMF
Senior DevSecOps Platform Engineer — Kubernetes & RMF

Defense Unicorns • Springfield (VA)

Hybrid
CAD 212,000 - 286,000
Health insurance
HSA
Stock options
+5