Cyber Security Architect / Policy Lead

Science Applications International Corporation
United States
2 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$160,001.0 - $200,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Audit Trail Microsoft Azure Cloud Computing Security CompTIA Security+ Cyber Security Information Systems Federated Identity Management Federal Information Processing Standards (FIPS) IPv6 Information Systems Security Architecture Professional
+12 more
Information Systems Security Engineering Professional Key Management Cloud Services Fortify (Software) Zero Trust Network Access Security Assertion Markup Language (SAML) Software Vulnerability Management Cloud Platform System Information Technology Patch Management Nessus Vulnerability Analysis

Job description

Position Summary: The Cyber Security Architect/Policy Lead is the program’s senior cybersecurity authority, responsible for designing and enforcing the security architecture, managing the ATO/A&A lifecycle, and ensuring all HELM Product Line systems comply with VA, federal, and FISMA cybersecurity requirements. This role also serves as the primary interface with VA Information Security Officers (ISOs), Field Security Services (FSS), and the Office of Cyber Security (OCS)., * Lead the development and maintenance of all Assessment and Authorization (A&A) artifacts required to obtain and maintain Authority to Operate (ATO) for all HELM Product Line systems, in accordance with NIST SP 800-37 Rev 2 and VA Handbook 6500

  • Serve as the primary technical lead for cybersecurity, Zero Trust Architecture (ZTA), and RMF compliance across the HELM PL
  • Participate in vulnerability scans and quality reviews in accordance with NIST SP 800-53 Rev 5; remediate critical and high severity vulnerabilities identified through government scans
  • Provide vulnerability scanning reports and risk assessments per NIST SP 800-30 Rev 1
  • Ensure cloud solutions comply with FedRAMP, VA Directive 6500/6517, VA Zero Trust Architecture principles, TIC 3.0 , IPv6 requirements, and all VA cybersecurity policies
  • Implement required cloud security controls: encryption in transit and at rest, boundary protection, audit logging, identity federation, and secrets management
  • Develop and maintain cybersecurity policy documentation, POA&Ms, and continuous monitoring artifacts
  • Coordinate with VA ISOs, FSS, and OCS to support ATO compliance and respond to security findings
  • Ensure all HELM systems comply with VA Critical Security Controls (effective July 1, 2025) and VA Memorandum “VA Security Controls”
  • Support FICAM/PIV logical access policy compliance, including IAL 3, AAL 3, and FAL 3 assurance levels
  • Enforce cryptographic requirements per FIPS 140-2/140-3 and NIST SP 800-52; document cryptographic system protections
  • Manage patching governance: document patch management, vulnerability management, and mitigation processes
  • Advise on AI/ML security implications and ensure AI systems comply with applicable EOs and OMB memoranda (E.O. 13960, 14319, M-25-21, M-26-04)
  • Ensure all contractor personnel complete VA mandatory cybersecurity training (TMS #10176) and role-based security training
  • Respond to security incidents; coordinate with VA PM and VA Information Security Officer within required timeframes

Requirements

  • Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, or related field; Master’s preferred
  • Must have a Bachelors and 13 years of experience, Masters degree and 11 years of experience or a PhD or JD and 8 years of experience.
  • 10+ years of cybersecurity experience, with at least 5 years supporting federal IT programs under FISMA/RMF
  • Deep expertise in NIST SP 800-53 Rev 5, NIST SP 800-37 Rev 2 (RMF), and VA Handbook 6500
  • Demonstrated experience obtaining and maintaining ATOs for federal information systems
  • Proficiency with VA or federal security scanning tools (Fortify, WASA, Nessus, or equivalent)
  • Experience with Zero Trust Architecture principles and implementation in cloud environments (AWS, Azure, VAEC)
  • Demonstrated expertise in VA Zero Trust Architecture, TIC 3.0, and ATO compliance (required per program standards)
  • Knowledge of FedRAMP, FISMA, HIPAA/PHI security requirements, and VA Directive 6517 (cloud security)
  • Familiarity with CISA Binding Operational Directives (BOD 19-02, BOD 22-01, BOD 23-01) [43]
  • Experience with FICAM, PIV/CAC logical access, SAML, and identity assurance frameworks [36]
  • Must be eligible for VA background investigation (likely Tier 4/High Risk); must be US-based [26,29,30]

Preferred Certifications

  • CISSP-ISSAP
  • CISSP-ISSEP
  • GIAC GSLC
  • CISM
  • CompTIA Security+

Benefits & conditions

Target salary range: $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

About the company

SAIC is a premier technology integrator, solving our nation’s most complex modernization and systems engineering challenges across the defense, space, federal civilian, and intelligence markets. Our robust portfolio of offerings includes high-end solutions in systems engineering and integration; enterprise IT, including cloud services; cyber; software; advanced analytics and simulation; and training. We are a team of 23,000 strong driven by mission, united purpose, and inspired by opportunity. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $6.5 billion. For more information, visit saic.com. For information on the benefits SAIC offers, see Working at SAIC. EOE AA M/F/Vet/Disability

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

The pros and cons of campus-wide IP authentication

Christoph Eicke Christoph Eicke · World Congress 2025

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:05 min

Exploring microcontrollers and communication protocols for amateur hardware

Philipp-Alexander Blum · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski · World Congress 2026 Europe

Videos

See all

Related articles

See all