Cyber Security Architect / Policy Lead
$160k - $200kSAIC
Job ID: 2617063-OTHLOC-043 Location: Remote Work, VA, US Date Posted: 2026-09-21 Category: Cyber Subcategory: Cyber GRC Schedule: Full-Time Shift: Day Job Travel: Yes - 10% of the time Minimum Clearance Required: None Clearance Level Must Be Able to Obtain: Public Trust Potential for Remote Work: ORA_REMOTE
Description
Position Summary: The Cyber Security Architect/Policy Lead is the program's senior cybersecurity authority, responsible for designing and enforcing the security architecture, managing the ATO/A&A lifecycle, and ensuring all HELM Product Line systems comply with VA, federal, and FISMA cybersecurity requirements. This role also serves as the primary interface with VA Information Security Officers (ISOs), Field Security Services (FSS), and the Office of Cyber Security (OCS). Key Responsibilities
Required Qualifications
Target salary range: $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors. SAIC is a premier technology integrator providing full life cycle services and solutions in the technical, engineering, intelligence, and enterprise information technology markets. SAIC is Redefining Ingenuity through its deep customer and domain knowledge to enable the delivery of systems engineering and integration offerings for large, complex projects. SAIC's approximately 15,000 employees are driven by integrity and mission focus to serve customers in the U.S. federal government. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $4.5 billion. For more information, visit saic.com. For information on the benefits SAIC offers, see .
Description
Position Summary: The Cyber Security Architect/Policy Lead is the program's senior cybersecurity authority, responsible for designing and enforcing the security architecture, managing the ATO/A&A lifecycle, and ensuring all HELM Product Line systems comply with VA, federal, and FISMA cybersecurity requirements. This role also serves as the primary interface with VA Information Security Officers (ISOs), Field Security Services (FSS), and the Office of Cyber Security (OCS). Key Responsibilities
- Lead the development and maintenance of all Assessment and Authorization (A&A) artifacts required to obtain and maintain Authority to Operate (ATO) for all HELM Product Line systems, in accordance with NIST SP 800-37 Rev 2 and VA Handbook 6500
- Serve as the primary technical lead for cybersecurity, Zero Trust Architecture (ZTA), and RMF compliance across the HELM PL
- Participate in vulnerability scans and quality reviews in accordance with NIST SP 800-53 Rev 5; remediate critical and high severity vulnerabilities identified through government scans
- Provide vulnerability scanning reports and risk assessments per NIST SP 800-30 Rev 1
- Ensure cloud solutions comply with FedRAMP, VA Directive 6500/6517, VA Zero Trust Architecture principles, TIC 3.0 , IPv6 requirements, and all VA cybersecurity policies
- Implement required cloud security controls: encryption in transit and at rest, boundary protection, audit logging, identity federation, and secrets management
- Develop and maintain cybersecurity policy documentation, POA&Ms, and continuous monitoring artifacts
- Coordinate with VA ISOs, FSS, and OCS to support ATO compliance and respond to security findings
- Ensure all HELM systems comply with VA Critical Security Controls (effective July 1, 2025) and VA Memorandum "VA Security Controls"
- Support FICAM/PIV logical access policy compliance, including IAL 3, AAL 3, and FAL 3 assurance levels
- Enforce cryptographic requirements per FIPS 140-2/140-3 and NIST SP 800-52; document cryptographic system protections
- Manage patching governance: document patch management, vulnerability management, and mitigation processes
- Advise on AI/ML security implications and ensure AI systems comply with applicable EOs and OMB memoranda (E.O. 13960, 14319, M-25-21, M-26-04)
- Ensure all contractor personnel complete VA mandatory cybersecurity training (TMS #10176) and role-based security training
- Respond to security incidents; coordinate with VA PM and VA Information Security Officer within required timeframes
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field; Master's preferred
- Must have a Bachelors and 13 years of experience, Masters degree and 11 years of experience or a PhD or JD and 8 years of experience.
- 10+ years of cybersecurity experience, with at least 5 years supporting federal IT programs under FISMA/RMF
- Deep expertise in NIST SP 800-53 Rev 5, NIST SP 800-37 Rev 2 (RMF), and VA Handbook 6500
- Demonstrated experience obtaining and maintaining ATOs for federal information systems
- Proficiency with VA or federal security scanning tools (Fortify, WASA, Nessus, or equivalent)
- Experience with Zero Trust Architecture principles and implementation in cloud environments (AWS, Azure, VAEC)
- Demonstrated expertise in VA Zero Trust Architecture, TIC 3.0, and ATO compliance (required per program standards)
- Knowledge of FedRAMP, FISMA, HIPAA/PHI security requirements, and VA Directive 6517 (cloud security)
- Familiarity with CISA Binding Operational Directives (BOD 19-02, BOD 22-01, BOD 23-01) [43]
- Experience with FICAM, PIV/CAC logical access, SAML, and identity assurance frameworks [36]
- Must be eligible for VA background investigation (likely Tier 4/High Risk); must be US-based [26,29,30]
- CISSP-ISSAP
- CISSP-ISSEP
- GIAC GSLC
- CISM
- CompTIA Security+
Target salary range: $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors. SAIC is a premier technology integrator providing full life cycle services and solutions in the technical, engineering, intelligence, and enterprise information technology markets. SAIC is Redefining Ingenuity through its deep customer and domain knowledge to enable the delivery of systems engineering and integration offerings for large, complex projects. SAIC's approximately 15,000 employees are driven by integrity and mission focus to serve customers in the U.S. federal government. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $4.5 billion. For more information, visit saic.com. For information on the benefits SAIC offers, see .
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Cyber Security Architect / Policy Lead in United States vacancy
$143k - $238.4k
...health today, we want to hear from you.Lead Cyber Security ArchitectLocation: Richmond, VA, USA -... ...OpportunityThe Lead Cyber Security Architect is a senior, advanced-skill role responsible... ...controls. Translate security policy, risk, and regulatory obligations into...PolicyFull time- ...Are you an experienced security engineer / architect looking to apply your strategic... ...lifecycle management, retention policies, audit logging, workspace... ...BI platforms Manage and lead end-to-end AI Security... ...Degree in Computer Science, Cyber Security, Information Systems...PolicyFull timeRemote work
- About this role:Wells Fargo is seeking a Lead Systems Architect - Application Security to join the Security Architecture organization. This role will provide... ...adhere to established Wells Fargo standards, policies, methodologies, and industry best practicesCollaborate...PolicyFull timeWork experience placement
- ...Group, Inc. (NYSE: CNO) is a leading insurance and financial services company focused on securing the future of middle‑income America... ...is hiring a Lead IT Security Architect who will impact the... ...preparing security standards, policies, and procedures; consulting with...PolicyFull timeWork experience placementWork at officeRemote workFlexible hours
- As a Senior Lead Cybersecurity Architect at JPMorganChase within the Cybersecurity... ...team—not only as an AI/ML security subject matter expert, but... ...research, and by evolving policies, testing protocols, and technical... ...product, data science, cyber, legal, and risk to understand...Policy
- Carpenter Technology is seeking an experienced Security Architect to lead the security strategy and implementation for our next-generation cloud... ...-on, multi-factor authentication, and conditional access policies. Define role-based access control (RBAC) models for data and...PolicyFull timeWork experience placementFlexible hours
$86.8k - $198k
Enterprise Security Architect, LeadThe Opportunity: Security must be architected, not bolted on.... ...implementing solutions that withstand advanced cyber threats. In this role, you will help... ...adherence to information security policies and procedures.In this role, you will apply...PolicyFull timeContract workPart timeWork at officeLocal areaRemote work- ...SummaryWe are seeking a highly experienced and meticulous Lead Network & Security Architect to join the IT Support team for the Hardware Platform... ...category under applicable federal, state, and local laws. This policy applies to hiring, promotion, discharge, pay, fringe...PolicyWork at officeLocal areaRemote workWorldwideShift work
$142.3k - $195.7k
...community Do you thrive on designing secure, enterprise-scale solutions that... ...critical systems, data, and networks? As a Lead Security Architect in Humana, you will play a key role in... ...Opportunity Employer It is the policy of Humana not to discriminate against...PolicyFull timeTemporary workWork at officeRemote workWork from homeHome office$148.5k - $247.5k
...ProfileCybersecurity Sr Lead ArchitectManagement... ...Senior Lead Cybersecurity Architect is responsible for defining... ...patterns to build secure products and enterprise... ...relevant cybersecurity policies, standards, procedures,... ...the development of non-cyber architecture-related governance...PolicyFull timeRemote workVisa sponsorshipFlexible hours- ...their best work.What We Need2K is looking for an experienced Lead Security Architect to grow our Security Engineering team.The ideal candidate... ...environments, with a focus on Cloud IAM, Network Security, Network Policy, and orchestration technologies.Maintain engineering and...Policy
- ...for designing and implementing security solutions to protect an... ...toSecurity Design and Integration: Lead the design, delivery, and... ...technological and process requirements.Policy and Architecture Development:... ...: Work collaboratively to architect and deliver agile, secure by...PolicyFull timeRemote workShift work
$125.8k - $209.7k
...for robust, scalable security architecture has never... ...Consultant within EY's Cyber practice focused on Enterprise... ...frameworks and leading practices. You will... ...architecture standards, policies, and governance frameworks... ...CCSP, SABSA Chartered Architect (SCF/SCM), TOGAF, or...PolicyImmediate start- ...futureWe are seeking a Cybersecurity Architect to help design, evaluate, and continuously improve security architecture across a complex... ..., and application environments.Lead the design of layered security... ..., peer review, automation, policy as code, and traceable change management...PolicyRemote work
- ...development, infrastructure, Cyber security, and enterprise content/data... ...Description: The Security Architect supports the Chief Program Architect... ...and procedures.Plans, leads, organizes and controls... ...Review and provide input to policies and standard operating procedures...PolicyFull timeWork experience placement
- The Cyber Security Architect role is primarily responsible for designing, building, and maintaining secure data, systems and applications.This... ...and infrastructure while ensuring compliance with relevant policies and regulations.A successful candidate will have a thorough...PolicyFull timeFlexible hours
$141.7k - $202.7k
...and make an impact. Join us!AI Security Standards Architect Key Responsibilities:• Define and lead the AI security strategy, including... ...at least 2 years focused on cyber assessment of Artificial... ...Strong understanding of frameworks, policies, and controls needed to govern...PolicyFull timeWork at officeFlexible hoursDay shift- Overview A Brief OverviewThe Security Architect is responsible for executing... ...to project teams and leads security consultations for enterprise... ...detection, centralized cyber security knowledge base and... ...assigned.Complies with all policies and standards. Qualifications...PolicyWork at office
$170.63k - $218.98k
...careers section of the system.Job Description:At Regions, the Cyber Security Architect contributes to the advancement of Regions’ cyber security... ...ensure team is complying with all applicable regulations, policies, and guidelines, both internally and externally, monitoring...PolicyFull timeWork at officeRelocationVisa sponsorshipWork visaRelocation packageFlexible hours3 days per week$170.63k - $218.98k
...careers section of the system.Job Description:At Regions, the Cyber Security Architect contributes to the advancement of Regions’ cyber security... ...ensure team is complying with all applicable regulations, policies, and guidelines, both internally and externally, monitoring...PolicyFull timeWork at officeRelocationVisa sponsorshipWork visaRelocation packageFlexible hours3 days per week$154.05k - $278.48k
...for you as our next TS/SCI Security Engineer Solution Architect supporting the creation of... ...with focus on leading teams through the Risk Management... ...improve, and maintain security policies and proceduresProvide... ...systemsExperience managing a team of Cyber Security Engineers (CSEs)...PolicyFull timeRemote work- ...Information Technology group delivers secure, reliable technology solutions... ...Strategy team, you will lead the design, governance, and... ...access architectures support: Policy consistency and traceabilityException... ...(including VPN modernization)Architect and guide implementation of...PolicyRemote workFlexible hours
- DescriptionSecurity Engineer Architect - TS/SCI Xcelerate... ...you as our next TS/SCI Security Engineer Architect... ...Engineering Architect Lead, your job is to provide... ...and maintain security policies and proceduresProvide operating... ...managing a team of Cyber Security Engineers (CSEs...PolicyContract workRemote workFlexible hours
$180k - $220k
We offer a flexible working policy that supports a healthy balance... ...balance. Being a Principal Security Architect at iManage Means… You will drive... ...least 4+ years operating as Lead, or Enterprise Architect... ...degree in Computer Science, Cyber Security, Engineering, or equivalent...PolicyWork at officeLocal areaWorldwideFlexible hours- Summary: The Security Architect has primary responsibility for leading the Security Engineering and Architecture function... ...strategy in accordance with the Bank’s policies, standards, and risk appetite.... ...in the Information / Cyber Security field.Provide technical...PolicyWork at officeWork from home
$150k - $190k
...work.Job Title:Corporate AI Security ArchitectReporting To:... ...for a Corporate AI Security Architect to join our Cyber Security Team!As the Corporate... ...Security Architect, you will lead the development,... ...continuously enhance AI security policies, standards, controls, and enforcement...PolicyFull timeWork at officeLocal areaRelocationFlexible hours$121.8k - $239.32k
...hiring a (Hybrid) Enterprise Security Architect at our Tysons, Virginia... ...First Line IT and Second Line Cyber Security, ensuring second-line... ...challenges. Translate security policies, standards, and control... .... PenFed offers market-leading certificates, checking and savings...PolicyWork at officeLocal areaWorldwide- ...teams across Power, Wind, and Electrification businesses, the full-time remote Cyber Security Architect will design secure architectures, lead threat modeling, and translate security policy into actionable engineering guidance. Key responsibilities Review and develop...PolicyFull timeRemote work
- ...Cyber Security Architect Location: Princeton, NJ & New York, NY - Hybrid Full-Time Job Summary: We are seeking... .... ~ Experience with security architecture frameworks, policies, control standards, and governance processes. ~...PolicyFull time
- ...Principal Security Architect Onsite Delivery DNB for Cyber Security and Risk Management Project in USA to manage complex security program development and... ...environment by ensuring compliance with standards, policies and procedures; also conduct incident response analysis...Policy
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security Architect / Policy Lead. Be the first to apply!
Related searches
- cloud security architect United States
- lead security architect United States
- security architect United States
- security solutions architect United States
- application security architect United States
- cyber security architect United States
- aws security architect United States
- cybersecurity project manager United States
- senior manager cyber security United States
- cybersecurity manager United States


