SAIC

Cyber Security Architect / Policy Lead

SAIC$125K — $150K *
US-Anywhere
+ 2 other locationsRemote
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's in Cybersecurity, Information Assurance, Computer Science, or related field; Master's preferred
  • 13+ years of experience with Bachelor's, or 11+ years with a Master's, or 8+ years with a PhD/JD
  • 10+ years in cybersecurity, including 5 years in federal IT programs under FISMA/RMF
  • Deep knowledge of NIST SP 800-53 Rev 5, NIST SP 800-37 Rev 2, and VA Handbook 6500
  • Proven track record in obtaining and maintaining ATOs for federal information systems
  • Experience with security scanning tools like Fortify, WASA, Nessus, or similar
  • Knowledge of requirements for VA Zero Trust Architecture, TIC 3.0, and FedRAMP compliance.

Responsibilities

  • Lead development and maintenance of A&A artifacts for ATO compliance
  • Act as primary technical lead for cybersecurity and RMF compliance
  • Conduct vulnerability scans and address identified issues according to NIST standards
  • Provide and analyze vulnerability scanning reports and risk assessments
  • Ensure cloud solutions meet stringent compliance requirements including FedRAMP and VA policies
  • Implement vital cloud security controls including encryption and identity management
  • Develop and uphold cybersecurity policy documentation and monitoring artifacts

Benefits

  • Opportunities for professional development and ongoing training
  • Supportive work environment promoting innovative cybersecurity solutions
  • Engagement with cutting-edge security technologies and frameworks
  • Collaborative partnerships with VA Information Security elements
  • Contribute to vital national security efforts through VA compliance
Full Job Description
Job Description

Position Summary: The Cyber Security Architect/Policy Lead is the program's senior cybersecurity authority, responsible for designing and enforcing the security architecture, managing the ATO/A&A lifecycle, and ensuring all HELM Product Line systems comply with VA, federal, and FISMA cybersecurity requirements. This role also serves as the primary interface with VA Information Security Officers (ISOs), Field Security Services (FSS), and the Office of Cyber Security (OCS).

Key Responsibilities
  • Lead the development and maintenance of all Assessment and Authorization (A&A) artifacts required to obtain and maintain Authority to Operate (ATO) for all HELM Product Line systems, in accordance with NIST SP 800-37 Rev 2 and VA Handbook 6500
  • Serve as the primary technical lead for cybersecurity, Zero Trust Architecture (ZTA), and RMF compliance across the HELM PL
  • Participate in vulnerability scans and quality reviews in accordance with NIST SP 800-53 Rev 5; remediate critical and high severity vulnerabilities identified through government scans
  • Provide vulnerability scanning reports and risk assessments per NIST SP 800-30 Rev 1
  • Ensure cloud solutions comply with FedRAMP, VA Directive 6500/6517, VA Zero Trust Architecture principles, TIC 3.0, IPv6 requirements, and all VA cybersecurity policies
  • Implement required cloud security controls: encryption in transit and at rest, boundary protection, audit logging, identity federation, and secrets management
  • Develop and maintain cybersecurity policy documentation, POA&Ms, and continuous monitoring artifacts
  • Coordinate with VA ISOs, FSS, and OCS to support ATO compliance and respond to security findings
  • Ensure all HELM systems comply with VA Critical Security Controls (effective July 1, 2025) and VA Memorandum "VA Security Controls"
  • Support FICAM/PIV logical access policy compliance, including IAL 3, AAL 3, and FAL 3 assurance levels
  • Enforce cryptographic requirements per FIPS 140-2/140-3 and NIST SP 800-52; document cryptographic system protections
  • Manage patching governance: document patch management, vulnerability management, and mitigation processes
  • Advise on AI/ML security implications and ensure AI systems comply with applicable EOs and OMB memoranda (E.O. 13960, 14319, M-25-21, M-26-04)
  • Ensure all contractor personnel complete VA mandatory cybersecurity training (TMS #10176) and role-based security training
  • Respond to security incidents; coordinate with VA PM and VA Information Security Officer within required timeframes


Qualifications

Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field; Master's preferred
  • Must have a Bachelors and 13 years of experience, Masters degree and 11 years of experience or a PhD or JD and 8 years of experience.
  • 10+ years of cybersecurity experience, with at least 5 years supporting federal IT programs under FISMA/RMF
  • Deep expertise in NIST SP 800-53 Rev 5, NIST SP 800-37 Rev 2 (RMF), and VA Handbook 6500
  • Demonstrated experience obtaining and maintaining ATOs for federal information systems
  • Proficiency with VA or federal security scanning tools (Fortify, WASA, Nessus, or equivalent)
  • Experience with Zero Trust Architecture principles and implementation in cloud environments (AWS, Azure, VAEC)
  • Demonstrated expertise in VA Zero Trust Architecture, TIC 3.0, and ATO compliance (required per program standards)
  • Knowledge of FedRAMP, FISMA, HIPAA/PHI security requirements, and VA Directive 6517 (cloud security)
  • Familiarity with CISA Binding Operational Directives (BOD 19-02, BOD 22-01, BOD 23-01) [43]
  • Experience with FICAM, PIV/CAC logical access, SAML, and identity assurance frameworks [36]
  • Must be eligible for VA background investigation (likely Tier 4/High Risk); must be US-based [26,29,30]

Preferred Certifications
  • CISSP-ISSAP
  • CISSP-ISSEP
  • GIAC GSLC
  • CISM
  • CompTIA Security+


About SAIC

Science Applications International Corporation (SAIC) is a technology integrator in the technical, engineering, intelligence, and enterprise information technology markets. SAIC has approximately 26,000 employees and operates in more than 70 countries. The company was founded in 1969 and is headquartered in Reston, Virginia. SAIC provides services to the U.S. government, including the Department of Defense, the intelligence community, and civilian agencies. The company also serves commercial customers in the healthcare, energy, and financial services sectors.
Learn more about SAIC
Size
26,000 employees
Market Cap
$6 billion
Industry
Net Income
$206 million
Founded
1969
5 Year Trend
+10.7%
Revenue
$6.8 billion
NASDAQ

Similar Jobs

More Jobs at SAIC

More Information Technology Jobs

Find similar Cyber Security Architect / Policy Lead jobs: