CronJobs

security jobs

Senior Security Risk Management Framework Engineer

Lts · United States - Remote

remotesenior$110,000–$125,000Posted Sep 23, 2026NIST RMFNIST 800-53AWSKubernetesCI/CDOSCALGitHub ActionsInfrastructure-as-Code

Apply on the employer site

About this role

**Senior Security Risk Management Framework Engineer** **Location:** Remote (U.S.) **Clearance:** U.S. Citizen or Permanent Resident Required with ability to obtain Public Trust **Salary Range:** $110K - $125K --- **About the Role** LTS is seeking a Senior Security RMF Engineer to join a cybersecurity transformation surge team supporting the VA.gov Platform. This role bridges VA security/RMF requirements and engineering implementation across VA.gov—translating control deficiencies, authorization requirements, and security risks into actionable engineering work. **Key Responsibilities** • Assess VA.gov Platform compliance with 18 Critical Controls and establish baseline implementation gaps • Perform security reviews, gap analyses, and risk assessments across infrastructure, pipelines, and applications • Support ongoing ATO and cATO readiness for VA.gov Platform authorization boundary • Develop and maintain RMF artifacts: SSPs, control narratives, POA&Ms, BIAs, PTAs, and evidence • Translate control deficiencies into prioritized technical remediation work with DevSecOps teams • Validate engineering remediation against security-control requirements • Support OSCAL-based, machine-readable security control models and automated evidence collection • Conduct threat modeling, secure-design reviews, and security risk assessments • Develop and maintain MOUs and Interconnection Security Agreements • Coordinate with VA security stakeholders, AODRs/AOs, OIS, CSOC, and auditors • Provide security guidance and develop standards for product teams • Support incident response and post-incident security remediation • Participate in on-call rotation for critical security events **Required Qualifications** • Associate's degree + 4 years relevant experience OR Bachelor's degree + 2 years relevant experience OR 5 years Cyber Security Engineer experience (meeting LCAT requirement) • Strong NIST RMF and NIST 800-53 security controls experience • ATO support experience for complex information systems • Security control assessments, gap analyses, and risk assessment expertise • SSP, control narrative, POA&M, and evidence development experience • Understanding of cloud infrastructure, CI/CD pipelines, and modern software development • Ability to translate compliance requirements into technical engineering work • Experience with technical engineering teams on vulnerability remediation • Strong written communication and documentation skills **Nice to Have** • VA cybersecurity, RMF, or ATO process experience • FISMA High systems experience • cATO or continuous authorization experience • OSCAL and automated security evidence collection • VA security artifacts (PTA, PIA, BIA, MOU/ISA, SERA) • AWS, Kubernetes/EKS, GitHub Actions, Infrastructure-as-Code • Threat modeling or secure architecture review experience • Vulnerability management, WASA/DAST scanning, continuous monitoring • Large federal digital platform experience **What We Offer** • Support for high-visibility federal IT and healthcare missions • Culture valuing innovation, growth, collaboration, and quality • Access to cutting-edge tools and technologies • Comprehensive benefits for you and your family • Career path rewarding ambition and performance

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord