i4DM Logo

i4DM

Senior RMF & ATO Engineer

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Lead implementation and maintenance of NIST RMF and ATO processes for a VA cloud-native platform. Engineer security controls, automate compliance validation in CI/CD, support secure cloud deployments, manage continuous monitoring and vulnerability remediation, produce authorization artifacts, assist incident response, and mentor junior engineers.
The summary above was generated by AI
Description

About Our Team 

Our employees thrive in a culture that's fast-paced and ego-free, where innovation and collaboration are encouraged at every turn. We are an organization that provides federal agencies instant access to experienced and talented professionals who understand their unique challenges and know the most efficient ways to address them. We are continually investing in resources and talent, so we stay prepared with specialized teams in place who are experts in creating tailored technologies. Our solutions empower Federal organizations to grow, modernize, and succeed in a rapidly evolving landscape.  

We value all voices and want to attract talent from all backgrounds. We're on the lookout for individuals who are passionate about technology and thrive in environments where problem-solving is approached with creativity and enthusiasm. If you're someone who enjoys continuously expanding your skill set while tackling real-world business problems, you'll feel right at home with us. Veterans and military spouses are especially encouraged to bring your unique and valuable experience to our team. 


About the Role 

We are seeking an experienced Senior RMF & ATO Security Engineer to serve as the technical cybersecurity lead responsible for implementing and maintaining Risk Management Framework (RMF), Authorization to Operate (ATO), and continuous monitoring activities supporting a mission-critical cloud-native platform within the Department of Veterans Affairs (VA). 

This is a hands-on engineering role that partners closely with Cloud Engineers, DevSecOps Engineers, Site Reliability Engineers, Solution Architects, and Government cybersecurity stakeholders to integrate security throughout the system lifecycle. The Senior RMF & ATO Security Engineer will engineer security controls, automate compliance validation, support secure cloud deployments, and ensure continuous authorization through effective implementation of Federal cybersecurity requirements. 


RESPONSIBILITIES 

  • Implement security controls required throughout the NIST RMF lifecycle. 
  • Engineer technical solutions supporting Categorize, Select, Implement, Assess, Authorize, and Monitor activities. 
  • Develop and maintain SSPs, POA&Ms, Security Assessment Reports, contingency plans, and authorization artifacts. 
  • Implement continuous monitoring processes, vulnerability management, and compliance reporting. 
  • Integrate SAST, DAST, container scanning, IaC validation, and other security automation into CI/CD pipelines. 
  • Collaborate with Cloud, DevSecOps, SRE, and software engineering teams to implement secure cloud-native architectures. 
  • Review AWS and Kubernetes environments for compliance with NIST SP 800-53 and VA security requirements. 
  • Participate in incident response, root cause analysis, and corrective action implementation. 
  • Support security audits, assessments, and ATO renewals by producing technical evidence and documentation. 
  • Mentor junior engineers on RMF implementation and cloud security best practices. 

TAG: #LI-I4DM

TAG: INDMJC

Requirements

QUALIFICATIONS 

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field. 
  • 7+ years supporting RMF, ATO, cybersecurity engineering, or cloud security in Federal environments. 
  • Strong knowledge of NIST SP 800-53, RMF, FISMA, HIPAA, and VA cybersecurity requirements. 
  • Experience with AWS, Kubernetes, Docker, Terraform, and CI/CD security integration. 
  • Experience with vulnerability management, POA&M tracking, and continuous monitoring. 
  • CISSP, CISM, or equivalent certification. 
  • Eligible to obtain and maintain a Public Trust clearance. 

PREFERRED QUALIFICATIONS 

  • AWS GovCloud experience. 
  • Experience with eMASS, SNOWCAM, Nessus, Security Hub, GuardDuty, Vault, Prometheus, Grafana, ELK, or Splunk. 
  • Experience securing healthcare platforms handling PHI. 
  • Experience supporting Kafka/MSK and event-driven architectures. 
  • teams. 
  • Identify and mitigate risks related to deployment, security, and system availability. 

Similar Jobs

An Hour Ago
Remote or Hybrid
80K-120K Annually
Mid level
80K-120K Annually
Mid level
Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
The Data Scientist will analyze complex datasets, build predictive models, collaborate with stakeholders, and present insights for business decisions.
Top Skills: Power BIPythonRSQLTableau
2 Hours Ago
Remote or Hybrid
120K-180K Annually
Senior level
120K-180K Annually
Senior level
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Own end-to-end product experience for an observability pipeline domain: conduct user research, prototype, and ship production-ready React interfaces. Build and evolve component libraries and design systems, ensure accessibility and performance, collaborate with PMs and engineers, measure UX outcomes, and mentor junior team members.
Top Skills: CSSGraphQLHTMLJavaScriptOpentelemetryReactRest ApisTypescriptWcag
3 Hours Ago
In-Office or Remote
140K-190K Annually
Mid level
140K-190K Annually
Mid level
Greentech • Hardware • Internet of Things • Machine Learning • Software • Business Intelligence • Agriculture
Drive new business and ensure customer success across the Alabama South/Black Belt territory. Prospect and close sales in-field, expand existing accounts, manage onboarding and deployments, gather and relay field feedback, collaborate with product and support teams, attend industry events, and own territory performance while frequently traveling to ranches and regional meetings.

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account