LMI

Innovation at the Pace of Need™

IT Security Lead

Security EngineerSecurity EngineerFull TimeRemoteTeam 1,001-5,000Since 1961H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

7 days ago

Salary

Not specified

No structured requirement data.

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

LMI is seeking an experienced Security Lead to support a key client at the General Services Administration (GSA) in delivering a modern, web-based acquisitions system. This initiative modernizes Governmentwide Indefinite Delivery Vehicle (IDV) contracting through modular, API-driven services deployed in federal cloud environments.

The Security Lead will serve as the senior authority responsible for defining and enforcing the program’s security and compliance approach in alignment with GSA requirements. This individual must possess a comprehensive understanding of the Authorization to Operate (ATO) process for cloud applications and collaborate closely with the client’s Information Technology Security Officers (ITSOs) to ensure the development team adheres to approved security controls and compliance standards.

The ideal candidate combines deep federal security expertise, hands-on cloud security experience in AWS, and the ability to integrate DevSecOps practices into modern Agile software delivery. This position is anticipated to be majority remote, but with the ability to travel and visit the client’s offices in Washington, D.C. as frequently as needed.

Responsibilities

  • Security Strategy & Governance
    • Serve as the primary authority for system security architecture and compliance
    • Collaborate directly with GSA security personnel to define and implement security and compliance controls for cloud-based applications
    • Ensure development teams adhere to approved security architecture and control implementations
    • Establish and maintain security documentation, policies, and procedures aligned with federal standards
    • Ensure compliance with FISMA and agency-specific security policies governing federal information systems
  • ATO & Federal Compliance
    • Lead the system through the full Authorization to Operate (ATO) lifecycle for applications
    • Develop and maintain System Security Plans (SSPs), security control documentation, and supporting artifacts
    • Manage Plans of Action and Milestones (POA&Ms) and track remediation activities
    • Support security control assessments and coordinate responses to findings
    • Align controls with guidance from the National Institute of Standards and Technology (NIST), FedRAMP requirements, and Trusted Internet Connections (TIC)/cloud security guidance
  • DevSecOps & CI/CD Integration
    • Embed automated security controls into CI/CD pipelines to enable secure, continuous delivery
    • Ensure static and dynamic code analysis, dependency scanning, container security, and infrastructure-as-code validation are integrated into build and deployment processes
    • Promote secure coding practices and continuous monitoring across development teams
  • Cloud Security (AWS)
    • Lead security architecture for applications and infrastructure deployed within AWS cloud environments
    • Configure and manage native AWS security services (e.g., IAM, Security Hub, GuardDuty)
    • Enforce least privilege access controls and secure identity and access management practices
    • Monitor cloud environments for threats, misconfigurations, and vulnerabilities
  • Risk Management & Audit Readiness
    • Conduct security risk assessments and oversee vulnerability scanning and penetration testing activities
    • Manage security incident response coordination and reporting
    • Maintain continuous monitoring practices and ensure audit readiness for all system components
    • Support ongoing authorization and continuous ATO practices through automated control monitoring and real-time risk visibility
    • Track, report, and mitigate identified risks throughout the system lifecycle
  • Team & Stakeholder Collaboration
    • Mentor development teams on security requirements and secure coding standards
    • Partner closely with team’s leadership to align security with system architecture and delivery timelines
    • Communicate security risks, compliance status, and remediation strategies clearly to both technical and non-technical stakeholders

Qualifications

  • Demonstrated experience serving as a Security Lead (or equivalent role) on federal IT programs
  • Extensive hands-on experience implementing federal security architectures aligned with NIST guidance, FedRAMP, and TIC/cloud security requirements
  • Proven track record leading systems through the full ATO lifecycle, including SSP development and POA&M management
  • Deep understanding of integrating security controls into CI/CD pipelines consistent with DevSecOps principles
  • Expert-level knowledge securing applications and infrastructure in AWS cloud environments
  • Experience conducting risk assessments, vulnerability management, and maintaining audit readiness
  • Strong written and verbal communication skills

Desired Qualifications

  • Experience supporting GSA or other federal cloud modernization initiatives
  • Relevant certifications (e.g., CISSP, CCSP, AWS Security Specialty, Security+)
  • Experience supporting systems at moderate or high impact levels under federal security frameworks
  • Familiarity with continuous monitoring tools and automated compliance validation solutions

Salary Information

The target salary range for this position is $135,000-$225,000. The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.

Job Requirements

  • Demonstrated experience serving as a Security Lead (or equivalent role) on federal IT programs
  • Extensive hands-on experience implementing federal security architectures aligned with NIST guidance, FedRAMP, and TIC/cloud security requirements
  • Proven track record leading systems through the full ATO lifecycle, including SSP development and POA&M management
  • Deep understanding of integrating security controls into CI/CD pipelines consistent with DevSecOps principles
  • Expert-level knowledge securing applications and infrastructure in AWS cloud environments
  • Experience conducting risk assessments, vulnerability management, and maintaining audit readiness
  • Strong written and verbal communication skills
  • Desired Qualifications
  • Experience supporting GSA or other federal cloud modernization initiatives
  • Relevant certifications (e.g., CISSP, CCSP, AWS Security Specialty, Security+)
  • Experience supporting systems at moderate or high impact levels under federal security frameworks
  • Familiarity with continuous monitoring tools and automated compliance validation solutions
  • Salary Information
  • The target salary range for this position is $135,000-$225,000. The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.

Related Categories

Related Job Pages

More Security Engineer Jobs

Security Engineer7 days ago
Full TimeRemoteTeam 501-1,000H1B No Sponsor

Public Trust Eligibility RequiredAbout AretumAretum is a mission-driven organization committed to delivering innovative, technology-enabled solutions to our customers across defense, civilian, and homeland security sectors. Our teams work at the inters...

Virginia

Senior Cloud Security Architect - State Project - Remote

ZIRLEN TECHNOLOGIES INCORPORATED

This is a remote position. If this opportunity aligns with your background and career goals, please respond with your updated resume and contact details to sivarajan.s@zirlen.com . You may also feel free to reach out at 972-433-6033, Ext. 1005.

Security Engineer7 days ago
Full TimeRemoteTeam 11-50

The role involves designing, implementing, and continuously improving enterprise security solutions, focusing heavily on securing public cloud environments and aligning security best practices with regulatory requirements. This includes addressing various cloud security risks, performing threat analysis, and designing mitigation strategies.

United States
$85 - $90 / hour

Senior Investigator Pharmacy

UnitedHealth Group

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone–of every race, gender, sexuality, age, location and income–deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes — an enterprise priority reflected in our mission. OptumCare is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. OptumCare is a drug-free workplace. Candidates are required to pass a drug test before beginning employment.

Security Engineer7 days ago
Full TimeRemoteTeam 10,001

At UnitedHealthcare, we’re simplifying the health care experience, creating healthier communities and removing barriers to quality care. The work you do here impacts the lives of millions of people for the better. Come build the health care system of tomorrow, making it more resp...

United States
Full TimeRemoteTeam 11-50

The Team Lead will ensure secure and efficient digital collaboration in highly sensitive environments by establishing secure platforms and workflows for clients, primarily in the public sector. Responsibilities include hands-on consulting, leading and developing the consulting team, and acting as a strategic interface between clients, sales, and development teams.

United States + 1 moreAll locations: United States, Germany
$100K - $120K / year