Lumen · Jackson, MSremote

Salary
$105,786–$155,152from the description
Posted
Jul 1, 2026
Location
Jackson, MS
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

This fully remote role centers on managing the end-to-end Risk Management Framework lifecycle for assigned federal and DoD systems, with direct accountability for achieving and sustaining Authorization to Operate outcomes. Day-to-day work involves developing and maintaining authorization artifacts, tracking vulnerability remediation, coordinating with engineering and operations teams on control implementation, and representing the security posture during assessments and audits. It suits experienced information assurance professionals with hands-on RMF and FedRAMP/FISMA execution backgrounds.

Senior level · 5+ years · Remote · Full-time

Must have (9)
NIST RMF (SP 800-37)FedRAMP or FismaATO (Authorization to Operate)SSPPOA&Mvulnerability managementcontinuous monitoringpost-quantum cryptographyGRC tools
Nice to have (2)
CGRC or CisaCISSP or Ccsp

“or” means any one of them counts — you don't need all of them.

Posted 8 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
vulnerability management55%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (10)

The title 'Lead Information Security Engineer' carries no standard seniority level word (Junior/Mid/Senior/Staff/Principal), so the title states no level; the 5+ years minimum and end-to-end RMF ownership scope support a Senior classification.

Compensation is quoted as three location-based ranges ($105,786–$141,047 / $111,074–$148,099 / $116,364–$155,152); the overall min and max across all tiers are reported here.

A Bachelor's degree in information assurance, cybersecurity, or a related field is listed under 'What We Look For in a Candidate' with the qualifier 'or equivalent experience,' so the degree requirement is set to None.

No active US security clearance is required; the posting gates only on US citizenship and the ability to meet GSA public trust suitability requirements, which is not a formal security clearance.

FedRAMP and FISMA are listed together as a single authorization-process requirement; FISMA is captured as an alternative to FedRAMP rather than a separate skill.

GRC certifications (CGRC, CISA) and broad security certifications (CISSP, CCSP) are described as 'strongly preferred' or 'preferred,' placing them in the preferred category.

Post-quantum cryptography (PQC) appears in the main responsibilities block under 'working knowledge of cryptographic principles and emerging standards, including post-quantum cryptography' — treated as a hard requirement given its placement in the required responsibilities section.

DoD authorization experience is mentioned as context alongside FedRAMP/FISMA and is not broken out as a separate skill gate.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗