About Our Team
Our employees thrive in a culture that's fast-paced and ego-free, where innovation and collaboration are encouraged at every turn. We are an organization that provides federal agencies instant access to experienced and talented professionals who understand their unique challenges and know the most efficient ways to address them. We are continually investing in resources and talent, so we stay prepared with specialized teams in place who are experts in creating tailored technologies. Our solutions empower Federal organizations to grow, modernize, and succeed in a rapidly evolving landscape.
We value all voices and want to attract talent from all backgrounds. We're on the lookout for individuals who are passionate about technology and thrive in environments where problem-solving is approached with creativity and enthusiasm. If you're someone who enjoys continuously expanding your skill set while tackling real-world business problems, you'll feel right at home with us. Veterans and military spouses are especially encouraged to bring your unique and valuable experience to our team.
About the Role
We are seeking an experienced Senior RMF & ATO Security Engineer to serve as the technical cybersecurity lead responsible for implementing and maintaining Risk Management Framework (RMF), Authorization to Operate (ATO), and continuous monitoring activities supporting a mission-critical cloud-native platform within the Department of Veterans Affairs (VA).
This is a hands-on engineering role that partners closely with Cloud Engineers, DevSecOps Engineers, Site Reliability Engineers, Solution Architects, and Government cybersecurity stakeholders to integrate security throughout the system lifecycle. The Senior RMF & ATO Security Engineer will engineer security controls, automate compliance validation, support secure cloud deployments, and ensure continuous authorization through effective implementation of Federal cybersecurity requirements.
RESPONSIBILITIES
- Implement security controls required throughout the NIST RMF lifecycle.
- Engineer technical solutions supporting Categorize, Select, Implement, Assess, Authorize, and Monitor activities.
- Develop and maintain SSPs, POA&Ms, Security Assessment Reports, contingency plans, and authorization artifacts.
- Implement continuous monitoring processes, vulnerability management, and compliance reporting.
- Integrate SAST, DAST, container scanning, IaC validation, and other security automation into CI/CD pipelines.
- Collaborate with Cloud, DevSecOps, SRE, and software engineering teams to implement secure cloud-native architectures.
- Review AWS and Kubernetes environments for compliance with NIST SP 800-53 and VA security requirements.
- Participate in incident response, root cause analysis, and corrective action implementation.
- Support security audits, assessments, and ATO renewals by producing technical evidence and documentation.
- Mentor junior engineers on RMF implementation and cloud security best practices.
TAG: #LI-I4DM
TAG: INDMJC
RequirementsQUALIFICATIONS
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field.
- 7+ years supporting RMF, ATO, cybersecurity engineering, or cloud security in Federal environments.
- Strong knowledge of NIST SP 800-53, RMF, FISMA, HIPAA, and VA cybersecurity requirements.
- Experience with AWS, Kubernetes, Docker, Terraform, and CI/CD security integration.
- Experience with vulnerability management, POA&M tracking, and continuous monitoring.
- CISSP, CISM, or equivalent certification.
- Eligible to obtain and maintain a Public Trust clearance.
PREFERRED QUALIFICATIONS
- AWS GovCloud experience.
- Experience with eMASS, SNOWCAM, Nessus, Security Hub, GuardDuty, Vault, Prometheus, Grafana, ELK, or Splunk.
- Experience securing healthcare platforms handling PHI.
- Experience supporting Kafka/MSK and event-driven architectures.
- teams.
- Identify and mitigate risks related to deployment, security, and system availability.
Similar Jobs
What you need to know about the Los Angeles Tech Scene
Key Facts About Los Angeles Tech
- Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
- Key Industries: Artificial intelligence, adtech, media, software, game development
- Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
- Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering


.png)