Mind Computing is seeking a full-time, 100% remote Cybersecurity Engineer (System Steward) to support a Department of Veterans Affairs (VA) project by identifying, mitigating cybersecurity risks and maintaining a strong information system security posture. The ideal candidate will provide expertise in Authority to Operate (ATO), the NIST Risk Management Framework (RMF), security controls, cloud security, and governance, risk, and compliance (GRC). The Cybersecurity Engineer will support RMF activities across the full ATO lifecycle, develop and maintain security documentation and artifacts, assess system risks and vulnerabilities, and coordinate with system administrators, developers, system owners, ISSOs, and other stakeholders to address security requirements and authorization gaps.
The candidate must reside within the continental US.
Responsibilities:
- Provide cybersecurity consulting and technical support to VA stakeholders for ATO, security authorization, and NIST RMF activities.
- Support RMF Steps 1–7, including security categorization, control implementation, assessment, authorization, and continuous monitoring.
- Lead and coordinate security and privacy activities within project teams, including development and maintenance of required RMF security artifacts.
- Develop and maintain security documentation, including Incident Response, Contingency Planning, Disaster Recovery, POA&M, and other authorization documentation.
- Analyze authorization packages and security artifacts to identify gaps, establish remediation plans, and coordinate resolution with system stakeholders.
- Conduct security risk assessments, impact analyses, gap assessments, compensating control evaluations, and residual risk assessments.
- Assess IT products, operating systems, and security configurations for compliance with NIST SP 800-53 and applicable security policies.
- Develop and implement security controls and support remediation of identified vulnerabilities and compliance findings.
- Support security configuration and compliance activities for infrastructure, operating system images, and IT product deployments.
- Prepare and present security reports, briefings, risk assessments, and recommendations to technical and non-technical stakeholders.
- Collaborate with system administrators, developers, system owners, ISSOs, and internal/external customers to assess the security impact of hardware, software, and configuration changes.
- Take on additional tasks and responsibilities as needed to support team objectives and ensure the success of the project.
Qualifications:
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, or a related field.
- 5+ years of information security experience, including at least 3 years of cybersecurity and cloud security experience supporting a large government agency.
- Strong experience supporting NIST RMF, ATO, security authorization, and continuous monitoring activities.
- Experience developing RMF security artifacts, implementing security controls, and managing POA&Ms.
- Knowledge of NIST SP 800-53, security compliance, GRC, and federal cybersecurity policies and practices.
- Experience conducting security assessments, risk analyses, gap assessments, impact assessments, and vulnerability assessments.
- Experience with cloud security and FedRAMP, including IaaS, PaaS, SaaS, and shared security responsibilities.
- Experience with security assessment and vulnerability tools such as Tenable Nessus, Nmap, SCAP, and Wireshark.
- Experience with ServiceNow Continuous Authorization and Monitoring (CAM) or similar security/GRC platforms.
- Knowledge of network security, software development, systems engineering, cloud architecture, and infrastructure security.
- Strong documentation, analytical, presentation, communication, and stakeholder coordination skills.
- Ability to translate technical cybersecurity requirements into actionable recommendations.
Additional Qualifications:
- Ability to obtain government clearance.
- Experience with the VA or other Government agencies.
- Required: ISC2 CISSP certification.
- Required: One or more of the following certification categories: IAT II, IAM II, or IASAE II.
- Additional relevant certifications may include:
- ISC2 CAP, SSCP, CCSP, or ISSEP
- ISACA CISM or CISA
- EC-Council CEH
- CompTIA Security+, Network+, SecurityX, or Linux+
- ISC2 CAP, SSCP, CCSP, or ISSEP
Benefits:
- Medical/Dental/Vision
- PTO + Federal Holidays
- Corporate Laptop
- Training opportunities
- 401(k) with employer match
- Remote work options
Note: Selected candidates will be required to complete fingerprinting at a government facility and undergo a background check as part of the hiring process.
Mind Computing is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or protected veteran status.
At this time, we are unable to offer sponsorship.
Skills Required
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, or a related field
- 5+ years of information security experience
- At least 3 years of cybersecurity and cloud security experience supporting a large government agency
- Experience supporting NIST RMF, ATO, security authorization, and continuous monitoring activities
- Experience developing RMF security artifacts, implementing security controls, and managing POA&Ms
- Knowledge of NIST SP 800-53, security compliance, GRC, and federal cybersecurity policies and practices
- Experience conducting security, risk, gap, impact, and vulnerability assessments
- Experience with cloud security and FedRAMP across IaaS, PaaS, SaaS, and shared security responsibilities
- Experience with Tenable Nessus, Nmap, SCAP, and Wireshark or similar security assessment and vulnerability tools
- Experience with ServiceNow Continuous Authorization and Monitoring or similar security/GRC platforms
- Knowledge of network security, software development, systems engineering, cloud architecture, and infrastructure security
- Strong documentation, analytical, presentation, communication, and stakeholder coordination skills
- Ability to translate technical cybersecurity requirements into actionable recommendations
- ISC2 CISSP certification
- One or more certification categories: IAT II, IAM II, or IASAE II
- Ability to obtain government clearance
- Experience with the Department of Veterans Affairs or other government agencies
- ISC2 CAP, SSCP, CCSP, or ISSEP certification
- ISACA CISM or CISA certification
- EC-Council CEH certification
- CompTIA Security+, Network+, SecurityX, or Linux+ certification
What We Do
Mind Computing is a next-generation digital services consulting firm. We enable our clients to be on the forefront and experience the NEXT – the next innovation, the next optimization and the next advantage! By synchronizing, orchestrating and implementing next-gen concepts such as integrative blockchain, smart internet of things, human-centric artificial intelligence & predictive analytics, we work with our clients for creating a better tomorrow. We support our clients on their most critical issues and opportunities related to implementing and integrating with cutting edge tools and technologies in the areas of business strategy, technology roadmap, technology implementation, program management, advisory services, organizational change management, training and managed contact centers. This enables our clients make better decisions, convert those decisions to actions, and deliver the sustainable success they desire. for more information, please visit us at www.mindcomputing.com
.png)

.png)





