IT Security Lead
Listed on 2026-08-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Overview
LMI isseeking an experienced
Security Lead
to supporta key client atthe General Services Administration (GSA) in delivering a modern, web-basedacquisitions system.
This initiative modernizes Government wide Indefinite Delivery Vehicle (IDV) contracting through modular, API-driven services deployed in federal cloud environments.
The Security Lead will serve as the senior authority responsible for defining and enforcing the program’s security and compliance approach in alignment with GSA requirements. This individual mustpossessa comprehensive understanding of the Authorization to Operate (ATO) process for cloud applications and collaborate closely withthe client’sInformation Technology Security Officers (ITSOs) to ensure the development team adheres to approved security controls and compliance standards.
The ideal candidate combines deep federal securityexpertise, hands-on cloud security experience in AWS, and the ability to integrate
Dev Sec Ops practices into modern Agile software delivery.
This position isanticipatedto be majority remote, but with the ability to travel and visit the client’s offices in Washington, D.C. asfrequentlyas needed.
LMI is a new breed of digital solutions provider dedicated to accelerating government impact with innovation and speed. Investing in technology and prototypes ahead of need, LMI brings commercial-grade platforms and mission-ready AI to federal agencies at commercial speed.
Leveraging our mission-ready technology and solutions, proven expertise in federal deployment, and strategic relationships, we enhance outcomes for the government, efficiently and effectively. With a focus on agility and collaboration, LMI serves the defense, space, healthcare, and energy sectors—helping agencies navigate complexity and outpace change. Headquartered in Tysons, Virginia, LMI is committed to delivering impactful results that strengthen missions and drive lasting value
ResponsibilitiesSecurity Strategy & Governance
- Serve as the primary authority for system security architecture and compliance
- Collaborate directly with GSA security personnel to define and implement security and compliance controlsrequiredfor cloud-based applications
- Ensure development teams adhere to approved security architecture and control implementations
- Establish andmaintainsecurity documentation, policies, and procedures aligned with federal standards
- Ensure compliance with FISMA and agency-specific security policies governing federal information systems.
ATO & Federal Compliance
- Lead the system through the full Authorization to Operate (ATO) lifecycle for applications
- Develop and maintain
System Security Plans (SSPs), security control documentation, and supporting artifacts
- Manage Plans of Action and Milestones (POA&Ms) and track remediation activities
- Support security control assessments and coordinate responses to findings
- Align controls with guidance from the National Institute of Standards and Technology (NIST), FedRAMP requirements, and Trusted Internet Connections (TIC)/cloud security guidance
Dev Sec Ops & CI/CD Integration
- Embed automated security controls into CI/CD pipelines to enable secure, continuous delivery
- Ensure static and dynamic code analysis, dependency scanning, container security, and infrastructure-as-code validation are integrated into build and deployment processes
- Promote secure coding practices and continuous monitoring across development teams
Cloud Security (AWS)
- Lead security architecture for applications and infrastructure deployed within AWS cloud environments
- Configure and manage native AWS security services (e.g., IAM, Security Hub,Guard Duty)
- Enforce least privilege access controls and secure identity and access management practices
- Monitor cloud environments for threats, misconfigurations, and vulnerabilities
Risk Management & Audit Readiness
- Conduct security risk assessments and oversee vulnerability scanning and penetration testing activities
- Manage security incident response coordination and reporting
- Maintain continuous monitoring practices and ensure audit readiness for all system components
- Support ongoing authorization and continuous ATO practices through automated control monitoring…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).