> Markdown version of [/jobs/ext/616350-security-rmf-engineer](https://www.wearedevelopers.com/jobs/ext/616350-security-rmf-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security/RMF Engineer - **Company:** GigaTECH, LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing Security, Identity and Access Management, Key Management, Network Security, Role-Based Access Control, Security Information and Event Management, Software Vulnerability Management, Datadog, Data Logging, Tenable Nessus, Splunk, Devsecops, Servicenow, Vulnerability Analysis - **Published:** June 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=32a86fcea0aaadf4 ## About the Role * RMF Framework: NIST 88-53, control families, tailoring * ATO Process: SSP development, POA&M management, authorization frameworks * ServiceNow GRC (or similar): Documentation and tracking * Cloud security: AWS security controls, shared responsibility models * Identity & Access Management: RBAC, least privilege, federation concepts * Encryption: TLS, data-at-rest encryption, key management service (KMS) * Vulnerability Management: Scanning tools, remediation workflows * Logging and Monitoring: SIEM integration (Splunk, Datadog concepts) * Network Security: Segmentation, ingress/egress control, TIC awareness * Compliance Standards: HIPAA awareness, FISMA/FEDRAMP basics * DevSecOps Integration: Security in CI/CD pipelines ## Description GigaTECH is seeking a mid-level Security/RMF Engineer to join our growing Healthcare IT-focused practice. This position will work directly with the contract technical team to ensure compliance with the Department of Veterans Affairs (VA) security requirements and achieve, maintain, and manage the Authority to Operate (ATO) lifecycle. The successful candidate will demonstrate experience with AWS Cloud Security. Develop system security documentation (SSP, POA&M), implementing and assessing NIST 800-53 security controls, conducting vulnerability scanning, and facilitating continuous monitoring within VA environments. The successful candidate will be a self-starter who is an aggressive learner. Responsibilities: * Develop and maintain RMF documentation (SSP, POA&M, SAR inputs) * Map and implement security controls across system layers * Coordinate with VA security stakeholders * Support vulnerability scanning and remediation * Enable continuous monitoring and compliance ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)