← Back to jobs

Remote job

Senior Security Risk Management Framework Engineer

Other Full-time Permanent US

Job details

$110,000—$125,000 Salary
US Eligibility
Senior Experience
Full-time Employment

About this role

Role overview A senior security engineering role supporting the VA.gov platform as part of a cybersecurity transformation effort. The position acts as the bridge between federal security and RMF requirements and the engineers who implement them, ensuring documentation confirms actual security posture rather than defining it on paper.

Responsibilities - Assess platform compliance against a defined set of critical controls and establish a baseline of implementation and remaining gaps - Perform security reviews, gap analyses, and risk assessments across infrastructure, pipelines, applications, and component systems - Support ongoing ATO and cATO readiness for the platform authorization boundary - Develop and maintain RMF and authorization artifacts including System Security Plans, control narratives, POA&Ms, Business Impact Analyses, Privacy Threshold Analyses, and supporting evidence - Translate identified control deficiencies into prioritized technical remediation work for engineering teams - Validate completed remediation against applicable controls and keep supporting documentation and evidence current - Support OSCAL-based machine-readable security control models and automated evidence collection - Conduct threat modeling, secure-design reviews, and security risk assessments - Coordinate with security stakeholders, authorizing officials, auditors, and other authorization parties - Provide security guidance to platform and product teams and help develop standards, decision trees, and training - Support incident response, post-incident analysis, and resulting remediation, including participation in an on-call rotation

Requirements - Associate's degree plus four years of relevant experience, Bachelor's degree plus two years of relevant experience, or five years of relevant cybersecurity engineering experience in lieu of a degree - Strong experience with NIST Risk Management Framework and NIST 800-53 security controls - Experience supporting ATOs for complex information systems - Experience performing security control assessments, gap analyses, risk assessments, and remediation planning - Experience developing and maintaining SSPs, control narratives, POA&Ms, and security authorization evidence - Ability to understand cloud infrastructure, CI/CD pipelines, application architectures, and modern software development practices well enough to evaluate how controls are actually implemented - Ability to translate compliance requirements into specific technical requirements and engineering backlog items - Experience working directly with technical engineering teams on vulnerability and control remediation - Strong written communication and documentation skills - Ability to work with technical teams, security stakeholders, auditors, and government leadership

Nice to have - Experience supporting VA cybersecurity, RMF, or ATO processes - Experience with FISMA High systems and with cATO or continuous authorization approaches - Experience with OSCAL and automated security evidence collection - Familiarity with VA security artifacts and processes such as PTA, PIA, BIA, MOU/ISA, or comparable federal processes - Experience with cloud-native AWS environments, Kubernetes or EKS, GitHub Actions, and Infrastructure-as-Code - Experience performing threat modeling or secure architecture reviews - Familiarity with vulnerability management programs, WASA or DAST scanning, and continuous security monitoring - Experience working on large federal digital platforms or authorization boundaries containing multiple applications and teams

Benefits and work setup - Remote role based in the United States - Salary range of $110,000 to $125,000 USD - Comprehensive benefits for employees and their families - Access to modern tools and technologies supporting high-visibility federal missions in IT and healthcare - Culture emphasizing innovation, growth, collaboration, and quality - Career path that rewards ambition and performance

Skills detected in the listing

Stakeholder ManagementInformation SecurityAWSKubernetes
Detected Sep 29, 2026
Last verified Sep 29, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight