Cybersecurity Architect / Policy Lead

Tista Science And Technology Corporation

• $182K — $198K *
US-AnywhereRemote in Rockville, MD
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years in information security, including 5+ years in a security architect or policy lead role for federal IT programs.
  • 5+ years with NIST Risk Management Framework and ATO lifecycle, including A&A package expertise.
  • Expertise in VA Zero Trust Architecture, TIC 3.0, and relevant VA and NIST security frameworks.
  • Experience securing hybrid environments, including legacy apps, SaaS, and cloud platforms.
  • Familiarity with integrating security into Agile and DevSecOps practices, including CI/CD controls.
  • Knowledge of security and privacy regulations for PHI/PII in federal healthcare settings.
  • VA OIT, VHA, or federal health cybersecurity experience preferred.

Responsibilities

  • Lead cybersecurity architecture and ATO strategy across a diverse product line.
  • Define and implement security requirements for multiple application types including cloud and SaaS.
  • Oversee ATO and Risk Management Framework activities to incorporate security controls into delivery.
  • Establish security standards and automate controls within Agile and DevSecOps pipelines.
  • Collaborate with VA stakeholders to identify security risks and resolve delivery issues.
  • Manage vulnerability assessments and governance for incident response and remediation.
  • Develop and maintain reusable security architecture standards focusing on Zero Trust and security-by-design.

Benefits

  • Comprehensive benefits plan available to associates.
  • Opportunity for professional growth and continuous improvement initiatives.
  • Flexible work location: Rockville, MD or remote within CONUS.
Full Job Description
Overview

TISTA is seeking a Cyber Security Architect / Policy Lead to support the Department of Veterans Affairs (VA) Supply Chain Management DevSecOps program. This Key Personnel role will lead cybersecurity architecture, Zero Trust alignment, security policy, and Authority to Operate (ATO) strategy across a portfolio of legacy, cloud, SaaS, and modernized applications.

 The Cyber Security Architect / Policy Lead will partner with VA security stakeholders and Agile delivery teams to establish security requirements, integrate security into DevSecOps delivery, manage ATO readiness, and support secure modernization across the product line. 

Responsibilities
  • Lead cybersecurity architecture, policy interpretation, Zero Trust alignment, and ATO strategy across the product line.
  • Define security requirements and architecture for legacy applications, SaaS platforms, cloud environments, containers, APIs, and system integrations.
  • Lead ATO and Risk Management Framework activities and ensure required security and privacy controls are incorporated throughout delivery.
  • Establish security standards and automated security controls within Agile and DevSecOps pipelines.
  • Partner with VA security stakeholders, Product Owners, architects, engineers, and program leadership to identify and resolve security risks and delivery blockers.
  • Lead vulnerability management, security risk, incident response, and remediation governance.
  • Develop and maintain reusable security architecture, Zero Trust, ATO, and security-by-design standards and practices.
  • Provide cybersecurity leadership, technical guidance, and mentorship across delivery teams.
  • Contribute to TISTA’s cybersecurity practice, business growth, and continuous improvement initiatives.
Qualifications
  • 12+ years of information security experience, including 5+ years as a security architect or security policy lead supporting federal IT programs.
  • 5+ years of hands-on experience with the NIST Risk Management Framework and ATO lifecycle, including authoring and defending A&A packages.
  • Demonstrated expertise with VA Zero Trust Architecture, TIC 3.0, VA Handbook 6500, VA Critical Security Controls, NIST security frameworks, and VA ICAM/PIV requirements.
  • Experience securing hybrid environments spanning legacy applications, SaaS, cloud platforms, and containerized workloads.
  • Experience integrating security into Agile and DevSecOps delivery, including CI/CD security controls, SAST/DAST, SBOM, and vulnerability management.
  • Experience with security and privacy requirements involving PHI/PII and federal healthcare environments.
  • VA OIT, VHA, or other federal health cybersecurity experience strongly preferred.
Certifications:
  • CISSP-ISSEP required or must be obtained within 12 months of hire.
  • CISSP-ISSAP required.

Education:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related field.
  • Master’s degree preferred.

Clearance:

  • Tier 2 / Moderate Risk Background Investigation; ability to obtain a VA PIV credential.

Location:

  • Rockville, MD / Remote (CONUS).

Pay Range:

  • The suggested pay for this position ranges from $182,546 to $198,875.
  • The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location.
  • Also, certain positions are eligible for additional forms of compensation, such as bonuses.
  • TISTA associates are eligible to participate in our comprehensive benefits plan! More information can be found here: https://tistatech.com/working-at-tista/

Similar Jobs

More Jobs at Tista Science And Technology Corporation

  • DevSecOps Engineer
    $161K — $176K *
    Remote
    Information Technology
    Remote in United States
  • PMO Lead
    $180K — $198K *
    Remote
    Education, Government & Non-Profit
    Remote in Rockville, MD
  • Deputy IT Program Manager
    $172K — $187K *
    Rockville, MD 20852 (Montgomery County)
    Education, Government & Non-Profit
    Hybrid
  • Test Automation Lead
    $166K — $178K *
    Remote
    Education, Government & Non-Profit
    Remote in Rockville, MD
  • Solution System Architect
    $171K — $183K *
    Remote
    Enterprise Technology
    Remote in Rockville, MD

More Information Technology Jobs

Find similar Cybersecurity Architect / Policy Lead jobs: