Leads cybersecurity architecture, policy, ATO/A&A, RMF compliance, vulnerability management, cloud security, Zero Trust implementation, incident response, and continuous monitoring for federal VA systems. Coordinates with VA security stakeholders, maintains compliance artifacts and POA&Ms, enforces cryptographic and access-control requirements, and advises on AI/ML security. Requires extensive federal cybersecurity experience, ATO expertise, and knowledge of NIST, FISMA, FedRAMP, VA policies, and related security frameworks.
Position Summary: The Cyber Security Architect/Policy Lead is the program's senior cybersecurity authority, responsible for designing and enforcing the security architecture, managing the ATO/A&A lifecycle, and ensuring all HELM Product Line systems comply with VA, federal, and FISMA cybersecurity requirements. This role also serves as the primary interface with VA Information Security Officers (ISOs), Field Security Services (FSS), and the Office of Cyber Security (OCS).
Key Responsibilities
- Lead the development and maintenance of all Assessment and Authorization (A&A) artifacts required to obtain and maintain Authority to Operate (ATO) for all HELM Product Line systems, in accordance with NIST SP 800-37 Rev 2 and VA Handbook 6500
- Serve as the primary technical lead for cybersecurity, Zero Trust Architecture (ZTA), and RMF compliance across the HELM PL
- Participate in vulnerability scans and quality reviews in accordance with NIST SP 800-53 Rev 5; remediate critical and high severity vulnerabilities identified through government scans
- Provide vulnerability scanning reports and risk assessments per NIST SP 800-30 Rev 1
- Ensure cloud solutions comply with FedRAMP, VA Directive 6500/6517, VA Zero Trust Architecture principles, TIC 3.0, IPv6 requirements, and all VA cybersecurity policies
- Implement required cloud security controls: encryption in transit and at rest, boundary protection, audit logging, identity federation, and secrets management
- Develop and maintain cybersecurity policy documentation, POA&Ms, and continuous monitoring artifacts
- Coordinate with VA ISOs, FSS, and OCS to support ATO compliance and respond to security findings
- Ensure all HELM systems comply with VA Critical Security Controls (effective July 1, 2025) and VA Memorandum "VA Security Controls"
- Support FICAM/PIV logical access policy compliance, including IAL 3, AAL 3, and FAL 3 assurance levels
- Enforce cryptographic requirements per FIPS 140-2/140-3 and NIST SP 800-52; document cryptographic system protections
- Manage patching governance: document patch management, vulnerability management, and mitigation processes
- Advise on AI/ML security implications and ensure AI systems comply with applicable EOs and OMB memoranda (E.O. 13960, 14319, M-25-21, M-26-04)
- Ensure all contractor personnel complete VA mandatory cybersecurity training (TMS #10176) and role-based security training
- Respond to security incidents; coordinate with VA PM and VA Information Security Officer within required timeframes
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field; Master's preferred
- Must have a Bachelors and 13 years of experience, Masters degree and 11 years of experience or a PhD or JD and 8 years of experience.
- 10+ years of cybersecurity experience, with at least 5 years supporting federal IT programs under FISMA/RMF
- Deep expertise in NIST SP 800-53 Rev 5, NIST SP 800-37 Rev 2 (RMF), and VA Handbook 6500
- Demonstrated experience obtaining and maintaining ATOs for federal information systems
- Proficiency with VA or federal security scanning tools (Fortify, WASA, Nessus, or equivalent)
- Experience with Zero Trust Architecture principles and implementation in cloud environments (AWS, Azure, VAEC)
- Demonstrated expertise in VA Zero Trust Architecture, TIC 3.0, and ATO compliance (required per program standards)
- Knowledge of FedRAMP, FISMA, HIPAA/PHI security requirements, and VA Directive 6517 (cloud security)
- Familiarity with CISA Binding Operational Directives (BOD 19-02, BOD 22-01, BOD 23-01) [43]
- Experience with FICAM, PIV/CAC logical access, SAML, and identity assurance frameworks [36]
- Must be eligible for VA background investigation (likely Tier 4/High Risk); must be US-based [26,29,30]
Preferred Certifications
- CISSP-ISSAP
- CISSP-ISSEP
- GIAC GSLC
- CISM
- CompTIA Security+
We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.
Spectrum San Diego Alamosa, Colorado, USA Office
Alamosa, United States
Spectrum San Diego Broomfield, Colorado, USA Office
Broomfield, United States
Spectrum San Diego Centennial, Colorado, USA Office
Centennial, United States
Spectrum San Diego Denver, Colorado, USA Office
Denver, United States
Spectrum San Diego Englewood, Colorado, USA Office
Englewood, United States
Spectrum San Diego Greenwood Village, Colorado, USA Office
Greenwood Village, United States
Similar Jobs
Artificial Intelligence • Marketing Tech • Software
Lead product marketing for an AI-first compliance platform: own messaging and positioning across industries, build ICPs and personas, create sales enablement, run customer insight conversations, lead GTM for launches, and partner with content, social, events, and web to keep the story consistent.
Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Provides remote technical customer support for Dealertrack and Cox Automotive products through phone, email, and chat. Resolves routine application and product issues, documents cases in CRM, trains customers on product usage, coordinates with internal teams, and follows up through resolution. Requires strong troubleshooting, communication, customer service, and documentation skills, with flexibility for variable shifts, Saturdays, and overtime.
Top Skills:
Cox AutomotiveCRMDealertrackGenesys PurecloudSalesforce
Computer Vision • Digital Media • Kids + Family • Mobile • Software • Sports
Operate application security across the SDLC, including secure design, code reviews, threat modeling, API security, DevSecOps tooling, CI/CD security gates, cloud and container security, vulnerability management, and risk communication. Partner with engineering teams on secure coding standards, AWS, Kubernetes, Terraform, mobile ecosystems, and responsible AI integration. Participate in an on-call rotation and develop scalable security platforms, paved roads, documentation, and developer training.
Top Skills:
Ai/MlAndroidAWSBugcrowdCdnCi/CdGithub ActionsGithub Advanced Security (Ghas)GraphQLInfrastructure As Code (Iac)iOSKotlinKubernetesNowsecureOwasp Top 10RestSwiftTerraformTypescriptWeb Application Firewall (Waf)Wiz
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute



