Security/RMF Engineer

GigaTECH, LLC
United States
2 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Cloud Computing Security Identity and Access Management Key Management Network Security Role-Based Access Control Security Information and Event Management Software Vulnerability Management Datadog Data Logging Tenable Nessus Splunk
+3 more
Devsecops Servicenow Vulnerability Analysis

Job description

GigaTECH is seeking a mid-level Security/RMF Engineer to join our growing Healthcare IT-focused practice. This position will work directly with the contract technical team to ensure compliance with the Department of Veterans Affairs (VA) security requirements and achieve, maintain, and manage the Authority to Operate (ATO) lifecycle. The successful candidate will demonstrate experience with AWS Cloud Security. Develop system security documentation (SSP, POA&M), implementing and assessing NIST 800-53 security controls, conducting vulnerability scanning, and facilitating continuous monitoring within VA environments. The successful candidate will be a self-starter who is an aggressive learner. Responsibilities:

  • Develop and maintain RMF documentation (SSP, POA&M, SAR inputs)
  • Map and implement security controls across system layers
  • Coordinate with VA security stakeholders
  • Support vulnerability scanning and remediation
  • Enable continuous monitoring and compliance

Requirements

  • RMF Framework: NIST 88-53, control families, tailoring
  • ATO Process: SSP development, POA&M management, authorization frameworks
  • ServiceNow GRC (or similar): Documentation and tracking
  • Cloud security: AWS security controls, shared responsibility models
  • Identity & Access Management: RBAC, least privilege, federation concepts
  • Encryption: TLS, data-at-rest encryption, key management service (KMS)
  • Vulnerability Management: Scanning tools, remediation workflows
  • Logging and Monitoring: SIEM integration (Splunk, Datadog concepts)
  • Network Security: Segmentation, ingress/egress control, TIC awareness
  • Compliance Standards: HIPAA awareness, FISMA/FEDRAMP basics
  • DevSecOps Integration: Security in CI/CD pipelines

About the company

About GigaTECH GigaTECH is a dynamic, full-service Information Technology and Healthcare IT SDVOSB proudly serving our military, Veterans, and other Government and commercial agencies. We believe in effective and transparent collaboration; we believe our entire staff to be one team; we believe in corporate integrity and customer satisfaction; we believe hard work should be generously rewarded. We look forward to you joining our team! We actively seek candidates who challenge the status quo by wanting to significantly improve the user experience (patient, provider, payor) of healthcare IT applications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:36 min

Visualizing memory limits and isolating suspicious endpoints

Dina Matveev Dina Matveev · Europe 2026 Virtual

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all