FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in NIST Risk Management Framework (RMF) and security control assessments, with a strong focus on developing and maintaining security authorization artifacts. Proficient in translating compliance requirements into technical remediation and collaborating with engineering teams to enhance security posture.
Highest-signal resume keywords
NIST Risk Management Framework (RMF)Security Control AssessmentsSecurity Authorization ArtifactsCloud Infrastructure UnderstandingVulnerability Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security ReviewsGap AnalysesRisk AssessmentsSSPs DevelopmentControl NarrativesPOA&MsThreat ModelingSecure Architecture ReviewsContinuous Security MonitoringAutomated Evidence Collection
Soft Skills
Strong Written CommunicationCollaboration with Technical TeamsConsultation Skills
Tools & Technologies
AWSKubernetes/EKSGitHub ActionsOSCALInfrastructure-as-Code
Certifications & Qualifications
Public Trust Eligibility
Industry Keywords
VA CybersecurityFISMA High SystemsCATO ProcessesLarge Federal Digital Platforms
Tech Stack
Tools & technologiesAWSCloudCyber SecurityKubernetes
About the role
Key responsibilities & impact- Assess VA.gov Platform compliance with VA’s 18 Critical Controls and establish a baseline of implementation and remaining gaps
- Perform security reviews, gap analyses, and risk assessments across infrastructure, pipelines, applications, and component systems
- Support ongoing ATO and cATO readiness for the VA.gov Platform authorization boundary
- Develop, update, and maintain RMF and authorization artifacts, including SSPs, control narratives, POA&Ms, BIAs, PTAs, and supporting evidence
- Translate control deficiencies into prioritized technical remediation work with DevSecOps engineers
- Validate engineering remediation against security-control requirements and update authorization documentation and evidence
- Support OSCAL-based machine-readable security control models and automated evidence collection
- Develop and maintain POA&M processes and automate the POA&M lifecycle where feasible
- Conduct and support threat modeling, secure-design reviews, and security risk assessments
- Develop, coordinate, and maintain MOUs and ISAs
- Coordinate with VA security stakeholders, AODRs/AOs, OIS, CSOC, auditors, and other authorization stakeholders
- Provide security guidance and consultation to VA.gov Platform and product teams
- Develop security guidance, standards, decision trees, and training
- Support security incident response, post-incident analysis, and resulting remediation
- Participate in an on-call rotation for critical security events as required
- Keep ATO documentation and supporting evidence synchronized with engineering changes
Requirements
What you’ll need- Associate’s degree + four years of relevant professional experience OR Bachelor’s degree + two years of relevant professional experience OR five years of relevant Cyber Security Engineer experience in lieu of a degree
- U.S. Citizen or Permanent Resident required
- Ability to obtain a Public Trust
- Strong experience with NIST Risk Management Framework (RMF) and NIST 800-53 security controls
- Experience supporting ATOs for complex information systems
- Experience performing security control assessments, gap analyses, risk assessments, and remediation planning
- Experience developing and maintaining SSPs, control narratives, POA&Ms, and security authorization evidence
- Ability to understand cloud infrastructure, CI/CD pipelines, application architectures, and modern software-development practices
- Ability to translate compliance/control requirements into technical requirements and engineering backlog items
- Experience working directly with technical engineering teams on vulnerability and control remediation
- Strong written communication and documentation skills
- Ability to work with technical teams, security stakeholders, auditors, and government leadership
- Nice-to-have experience with VA cybersecurity, RMF, or ATO processes; FISMA High systems; cATO; OSCAL; AWS; Kubernetes/EKS; GitHub Actions; Infrastructure-as-Code; threat modeling; secure architecture reviews; vulnerability management; WASA/DAST; continuous security monitoring; and large federal digital platforms
Benefits
Comp & perks- Comprehensive benefits for you and your family
- Access to cutting-edge tools and technologies
- Career path that rewards ambition and performance
- Opportunity to support high visibility federal missions in IT and healthcare
- Culture that values innovation, growth, collaboration, and quality
