Senior Security Risk Management Framework Engineer

LTS

United States

Remote

USD 110,000 - 125,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Comprehensive benefits
Career growth opportunities
Access to cutting-edge tools

Job summary

LTS seeks a Senior Security RMF Engineer to join a cybersecurity transformation surge for the VA.gov Platform. You’ll bridge VA security/RMF requirements with engineering teams implementing controls across cloud and software pipelines.

The role emphasizes translating control deficiencies into engineering work, supporting ATO readiness, and driving security outcomes with DevSecOps partners. Remote US-based role with strong compensation.

Qualifications

  • NIST RMF and NIST 800-53 expertise
  • Experience supporting ATOs for complex information systems
  • Experience conducting security control assessments and risk analyses
  • Ability to translate compliance into technical backlog items
  • Strong written communication and documentation skills

Responsibilities

  • Assess VA.gov Platform compliance with the 18 Critical Controls and identify gaps
  • Perform security reviews, gap analyses, and risk assessments across Platform
  • Support ongoing ATO and cATO readiness for VA.gov Platform authorization boundary
  • Develop and maintain SSPs, control narratives, POA&Ms, BIAs, PTAs and evidence
  • Translate identified deficiencies into prioritized remediation work with engineering teams
  • Validate remediation against security-control requirements and update documentation
  • Support OSCAL-based security models and automated evidence collection
  • Develop and maintain POA&M processes and lifecycle automation
  • Conduct threat modeling and secure-design reviews
  • Coordinate MOUs and ISAs as required
  • Engage with VA security stakeholders and auditors
  • Provide security guidance to product teams and training resources
  • Assist incident response and post-incident analysis

Skills

NIST RMF
ATO support
SSP & POAM
Cloud infrastructure
CI/CD pipelines
Threat modeling
Communication

Education

Associate/Bachelor degree options in lieu of degree
Five years cyber security engineer experience in lieu of degree

Tools

OSCAL
AWS
Kubernetes
GitHub Actions
Infrastructure-as-Code

Job description

Location:Remote (U.S.)
Clearance: U.S. Citizen or Permanent Resident Required with the ability to obtain a Public Trust
Salary Range: 110K – 125K

LTSis seeking a Senior Security RMF Engineer to join a cybersecurity transformation surge team supporting the VA.gov Platform. This role will serve as the bridge between VA security/RMF requirements and the engineers responsible for implementing those requirements across VA.gov.

The Senior Security / RMF Engineer must understand how security controls are implemented in modern cloud infrastructure and software delivery environments and be able to translate control deficiencies, authorization requirements, and security risks into actionable engineering work.This is not intended to be a documentation-only compliance role.

This individual will work closely with DevSecOps engineers and the existing VA.gov Platform ATO/security team to assess the current security posture, address gaps in VA.gov's Critical Controls, support ATO/cATO readiness, improve authorization artifacts, and automate evidence and control assessment wherever possible. The PWS specifically describes the desired model as one in which ATO/RMF documentation confirms security rather than defines it, with success measured through risk reduction and security outcomes rather than paperwork completeness.

What You’ll Do:
  • Assess VA.gov Platform compliance with the 18 Critical Controls identified by VA and help establish a baseline of current implementation and remaining gaps.
  • Perform security reviews, gap analyses, and risk assessments across VA.gov Platform infrastructure, pipelines, applications, and component systems.
  • Support ongoing ATO and cATO readiness for the VA.gov Platform authorization boundary.
  • Develop, update, and maintain RMF and authorization artifacts, including System Security Plans (SSPs), control narratives, POA&Ms, Business Impact Analyses (BIAs), Privacy Threshold Analyses (PTAs), and supporting evidence.
  • Evaluate identified control deficiencies and work with DevSecOps engineers to translate them into prioritized technical remediation work.
  • Validate completed engineering remediation against applicable security-control requirements and update supporting authorization documentation and evidence.
  • Support implementation of OSCAL-based, machine-readable security control models and automated evidence collection.
  • Develop and maintain POA&M processes and support automation of the POA&M lifecycle where feasible.
  • Conduct and support threat modeling, secure-design reviews, and security risk assessments.
  • Develop, coordinate, and maintain Memorandums of Understanding (MOUs) and Interconnection Security Agreements (ISAs) as required.
  • Coordinate with VA security stakeholders, AODRs/AOs, OIS, CSOC, auditors, and other authorization stakeholders.
  • Provide security guidance and consultation to VA.gov Platform and product teams.
  • Help develop security guidance, standards, decision trees, and training that allow product teams to better understand and own their security responsibilities.
  • Support security incident response, post-incident analysis, and identification of resulting security/control remediation.
  • Participate in an on-call rotation for critical security events as required.
  • Ensure ATO documentation and supporting evidence remain synchronized with technical changes implemented by the engineering team.
  • The PWS specifically requires the team to determine current compliance with VA's Critical Controls, collaborate with the team managing the existing ATO, and ensure authorization documentation is updated as technical work is completed.
What We're Looking For:
  • Associate’s degree + four years ofrelevant professionalexperience OR Bachelor’s degree + two years of relevant professionalexperience OR five years of relevant Cyber Security Engineer experience in lieu of a degree - Meeting the government-defined Cyber Security Engineer LCAT requirement
  • Strong experience with NIST Risk Management Framework (RMF) and NIST 800-53 security controls.
  • Experience supporting ATOs for complex information systems.
  • Experience performing security control assessments, gap analyses, risk assessments, and remediation planning.
  • Experience developing and maintaining SSPs, control narratives, POA&Ms, and security authorization evidence.
  • Ability to understand cloud infrastructure, CI/CD pipelines, application architectures, and modern software-development practices well enough to evaluate how security controls are actually implemented.
  • Ability to translate compliance/control requirements into specific technical requirements and engineering backlog items.
  • Experience working directly with technical engineering teams on vulnerability and control remediation.
  • Strong written communication and documentation skills.
  • Ability to work with technical teams, security stakeholders, auditors, and government leadership.
Nice to Have
  • Experience supporting VA cybersecurity, RMF, or ATO processes.
  • Experience with FISMA High systems.
  • Experience with cATO or continuous authorization approaches.
  • Experience with OSCAL and automated security evidence collection.
  • Experience with VA security artifacts and processes, including PTA, PIA, BIA, MOU/ISA, SERA, or comparable federal processes.
  • Experience with cloud-native AWS environments, Kubernetes/EKS, GitHub Actions, and Infrastructure-as-Code.
  • Experience performing threat modeling or secure architecture reviews.
  • Familiarity with vulnerability-management programs, WASA/DAST scanning, and continuous security monitoring.
  • Experience working on large federal digital platforms or authorization boundaries containing multiple applications, services, and development teams
What’s in it for you?

The opportunity to support high visibility federal missions in IT and healthcare
A culture that values innovation, growth, collaboration, and quality
Access to cutting-edge tools and technologies
Comprehensive benefits for you and your family
A career path that rewards ambition and performance

$110,000 — $125,000 USD

LTS shares salary ranges to promote transparency. Compensation ranges are provided for informational purposes, and final compensation may vary based on experience, skills, location, and role requirements.

LTSis committed to offering eligible employees comprehensive benefits that will provide them with options intended to meet their needs and the needs of their family.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Risk Management Framework Engineer New United States - Remote
Senior Security Risk Management Framework Engineer New United States - Remote

LTS • Northern (KY)

Hybrid
USD 110,000 - 125,000
Remote work
Security Engineer (Pipeline)
Security Engineer (Pipeline)

Page Mechanical Group, Inc. • Fort Meade (MD)

On-site
USD 145,000 - 155,000
Medical, Dental & Vision
Mental Health Resources
Paid Time Off & Holidays
+5
Senior Cyber ISSE: RMF/ATO & Cloud Security (Secret)
Senior Cyber ISSE: RMF/ATO & Cloud Security (Secret)

LMI Consulting, LLC • Fort Belvoir (VA)

On-site
USD 92,075 - 158,138
Senior RMF Engineer: Cloud Security & ATO Readiness
Senior RMF Engineer: Cloud Security & ATO Readiness

LTS • United States

Remote
USD 110,000 - 125,000
Comprehensive benefits
Career growth opportunities
Access to cutting-edge tools
ISSO Security Analyst, Senior
ISSO Security Analyst, Senior

Booz Allen Hamilton • McLean (VA)

On-site
USD 99,000 - 225,000
Remote Senior RMF Engineer: Security & Compliance
Remote Senior RMF Engineer: Security & Compliance

LTS • Northern (KY)

Hybrid
USD 110,000 - 125,000
Remote work
Cybersecurity Engineer
Cybersecurity Engineer

LMI • Tysons (VA)

On-site
USD 140,000 - 170,000
Cybersecurity & Governance Engineer
Cybersecurity & Governance Engineer

CALIBRE Systems, Inc. • Washington

On-site
USD 125,000 - 145,000
Cybersecurity Information System Security Engineer - Clearance Required
Cybersecurity Information System Security Engineer - Clearance Required

LMI • Fort Belvoir (VA)

On-site
USD 92,000 - 158,000
Principal Engineer, Cybersecurity RMF (Onsite - Largo, FL) TS/SCI clearance required
Principal Engineer, Cybersecurity RMF (Onsite - Largo, FL) TS/SCI clearance required

Collins Aerospace • Largo (FL)

On-site
USD 120,000 - 180,000
Restaurant d'entreprise
Indemnités de stage/alternance