LTSremote

Salary
Posted
Jul 1, 2026
Location
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

This role centers on securing a federal healthcare modernization program within the Department of Veterans Affairs, with day-to-day work spanning AWS cloud security, Risk Management Framework (RMF) and ATO support, and compliance documentation. The engineer will configure and monitor AWS security services, manage vulnerability remediation and STIG hardening, and embed security into DevSecOps pipelines. It suits someone with federal cybersecurity experience who is comfortable bridging technical controls and compliance documentation across cloud and hybrid environments.

Senior level · 5+ years · Remote · Bachelor's required

Must have (14)
AWSAWS Security HubAWS GuardDutyAWS InspectorIAMRMFATOeMASS or Servicenow GrcFISMAFedRAMPZero TrustDISA STIGsDevSecOpsCI/CD
Nice to have (6)
AWS GovCloudKubernetesTerraformHL7FHIRCISSP, Security+, Ceh, Ccsp, Aws Security Specialty or Aws Solutions Architect

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 1,250 people nationally plausibly meet what this posting asks for (information security analysts). range 250–1,850

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
IAM45%CI/CD45%RMF40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The JD requires the ability to obtain and maintain a Public Trust — this is a federal suitability determination, not a national-security clearance, so the clearance requirement is set to None.

No compensation figures are provided; the posting only states that salary ranges are shared 'to promote transparency' without actually publishing them.

The Bachelor's degree requirement is a hard gate — the JD lists a specific field of study with no 'or equivalent experience' language.

eMASS is listed as required with 'ServiceNow GRC, or similar' as an acceptable substitute; both are captured under one skill with ServiceNow GRC as an alternative.

Terraform is inferred as the primary IaC tool under the 'Nice to Have' mention of 'infrastructure as code'; it is preferred, not required.

CISSP and the other certifications appear under 'Nice to Have' and are consolidated into one preferred skill with alternatives.

VistA, CPRS, and MUMPS appear under 'Nice to Have' but name legacy healthcare applications rather than transferable security tools; they are omitted as they do not represent a named technology skill relevant to the security engineering role.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗