Responsibilities
- Establish and manage the path to Authority to Operate, assigning roles between government and contractor teams
- Create and maintain RMF documentation such as the System Security Plan, Security Assessment Plan, and Plan of Action & Milestones in compliance with DoDI 8510.01 and NIST 800-53
- Collaborate with eMASS administrators and Authorizing Officials to support assessment and authorization workflows
- Lead continuous monitoring initiatives and reauthorization processes throughout the system lifecycle
- Define security controls for data transfers across classification boundaries, including IL-5, IL-6, and tactical edge environments
- Assess and recommend approved DoD cross-domain solutions based on mission needs
- Ensure data segmentation strategies enforce classification policies such as NOFORN, REL_TO, and ORCON in a verifiable manner
- Evaluate system designs to confirm secure handling of classified information across networks
- Support secure operations across NIPRNet, SIPRNet, and higher classification domains
- Determine appropriate authorization models, including inherited or standalone ATOs, for different enclaves
- Design scalable security postures that do not require architectural changes as systems grow
- Stay current with joint and service-specific security policies to maintain compliance
- Serve as the internal expert on DoD security and Risk Management Framework inquiries
- Provide guidance on securing containers, role-based access controls, service meshes, PKI/CAC integration, and secrets management
- Set standards for security scanning, container hardening, and vulnerability remediation without direct pipeline ownership
- Assess new capabilities for security and authorization implications before deployment
Compensation
Competitive salary, bonus, and equity package
Work Arrangement
Remote (Worldwide)
Team
Results-based, fully remote team with flexible scheduling and unlimited PTO
Other
- U.S. Citizenship is required
- Active Secret security clearance
- Willingness to travel up to 25% for business purposes
- Fully remote, results-based environment
- Unlimited PTO with manager approval
- Flexible work environment with self-managed scheduling
- 14 weeks of fully paid parental leave