> Markdown version of [/jobs/ext/3560561-cybersecurity-architect-policy-lead](https://www.wearedevelopers.com/jobs/ext/3560561-cybersecurity-architect-policy-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Architect / Policy Lead - **Company:** TISTA Science and Technology Corporation - **Location:** Rockville, MD, United States (Remote available) - **Experience:** Expert - **Salary:** $182,546.0 - $198,875.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Agile Methodology, Software as a Service, Cloud Computing, Cyber Security, Information Systems, Continuous Integration, Data Architecture, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Zero Trust Network Access, Systems Integration, Software Vulnerability Management, Privacy Controls, Cloud Platform System, Containerization, Information Technology, Devsecops, Legacy Systems, Static Application Security Testing, Dynamic Application Security Testing - **Published:** October 2, 2026 - **Apply:** https://www.careerjet.com/job/us1f75782db36a2448545ee49791d63c99/eaa ## About the Role * 12+ years of information security experience, including 5+ years as a security architect or security policy lead supporting federal IT programs. 5+ years of hands-on experience with the NIST Risk Management Framework and ATO lifecycle, including authoring and defending A&A packages. Demonstrated expertise with VA Zero Trust Architecture, TIC 3.0, VA Handbook 6500, VA Critical Security Controls, NIST security frameworks, and VA ICAM/PIV requirements. * Experience securing hybrid environments spanning legacy applications, SaaS, cloud platforms, and containerized workloads. * Experience integrating security into Agile and DevSecOps delivery, including CI/CD security controls, SAST/DAST, SBOM, and vulnerability management. * Experience with security and privacy requirements involving PHI/PII and federal healthcare environments. * VA OIT, VHA, or other federal health cybersecurity experience strongly preferred. Certifications: * CISSP-ISSEP required or must be obtained within 12 months of hire. CISSP-ISSAP required. Education: * Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related field. Master's degree preferred. Clearance: * Tier 2 / Moderate Risk Background Investigation; ability to obtain a VA PIV credential. ## Description TISTA is seeking a Cyber Security Architect / Policy Lead to support the Department of Veterans Affairs (VA) Supply Chain Management DevSecOps program. This Key Personnel role will lead cybersecurity architecture, Zero Trust alignment, security policy, and Authority to Operate (ATO) strategy across a portfolio of legacy, cloud, SaaS, and modernized applications. The Cyber Security Architect / Policy Lead will partner with VA security stakeholders and Agile delivery teams to establish security requirements, integrate security into DevSecOps delivery, manage ATO readiness, and support secure modernization across the product line. At TISTA, you'll do meaningful, mission-driven work that improves lives alongside teammates you trust and leaders who are transparent and supportive. We invest in your learning and internal mobility so you can build a career that keeps advancing. We're proud to serve and hire Veterans, and we put people first in everything we do. TISTA associates enjoy above Industry Healthcare Benefits, Remote Working Options, Paid Time Off, Training/Certification opportunities, Healthcare Savings Account & Flexible Savings Account, Paid Life Insurance, Short-term & Long-term Disability, 401K Match, Tuition Reimbursement, Employee Assistance Program, Paid Holidays, Military Leave, and much more! Responsibilities * Lead cybersecurity architecture, policy interpretation, Zero Trust alignment, and ATO strategy across the product line. * Define security requirements and architecture for legacy applications, SaaS platforms, cloud environments, containers, APIs, and system integrations. * Lead ATO and Risk Management Framework activities and ensure required security and privacy controls are incorporated throughout delivery. * Establish security standards and automated security controls within Agile and DevSecOps pipelines. * Partner with VA security stakeholders, Product Owners, architects, engineers, and program leadership to identify and resolve security risks and delivery blockers. * Lead vulnerability management, security risk, incident response, and remediation governance. * Develop and maintain reusable security architecture, Zero Trust, ATO, and security-by-design standards and practices. * Provide cybersecurity leadership, technical guidance, and mentorship across delivery teams. Contribute to TISTA's cybersecurity practice, business growth, and continuous improvement initiatives., Overview: TISTA is seeking a Cyber Security Architect / Policy Lead to support the Department of Veterans Affairs (VA) Supply Chain Management DevSecOps program. This Key Personn… + 14 hours ago, Job Description: Overview TISTA is seeking a Data Architect Lead to support the Department of Veterans Affairs (VA) Supply Chain Management DevSecOps program. This Key Personne… + 18 hours ago + ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to TDD in legacy code](https://www.wearedevelopers.com/videos/309-how-to-tdd-in-legacy-code) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship)