Position Overview
A Senior Staff/Senior Application Security Architect is needed to lead security integration across software development efforts in support of federal projects. This role ensures that all systems adhere to stringent cybersecurity standards, particularly NIST 800-53, and align with the Risk Management Framework (RMF). The individual will work directly with development teams and customer cybersecurity experts to embed security into every phase of the software lifecycle.
Key Responsibilities
- Translate federal security controls into actionable software requirements and implementation guidance
- Collaborate with customer cybersecurity personnel to align system designs with mandated security expectations
- Produce comprehensive documentation demonstrating compliance with NIST 800-53 and related frameworks
- Identify security gaps and lead the creation and tracking of Plans of Action and Milestones (POAMs)
- Analyze findings from penetration tests and security assessments to recommend corrective measures
- Guide development teams in designing secure system architectures that meet compliance and operational needs
- Support internal mentoring and continuous improvement initiatives within application security and engineering groups
Qualifications
- U.S. citizenship is required due to government contracting regulations
- Proven background in the Software Development Lifecycle (SDLC) with an emphasis on security integration
- Direct experience applying the Risk Management Framework (RMF) in federal or defense environments
- Strong ability to communicate technical security concepts clearly to diverse audiences
- Practical knowledge of secure software development methodologies and common vulnerabilities
Technical Focus Areas
- NIST 800-53 control interpretation and implementation
- Risk Management Framework (RMF) processes
- Software Development Lifecycle (SDLC) integration
- Plans of Action and Milestones (POAMs) development and tracking
- Penetration testing evaluation and response
Work Environment
This is an onsite position located in Boulder, CO. The role supports U.S. government contracts requiring strict adherence to security protocols and compliance standards.
