Job Requirements
Remote
Secret Polygraph Unspecified
Career Level not specified
$111,427 - $200,000
Job Description
Overview
We're looking for a Cybersecurity Engineer to support the secure deployment and continuous authorization of LIGER, an enterprise AI platform built for federal missions, into a U.S. Customs and Border Protection (CBP) environment. You'll join a small, high-visibility team and own the security work that lets LIGER reach production at CBP and stay there: maintaining the ATO posture, driving vulnerability management, and partnering with CBP cyber stakeholders to keep the platform compliant as it evolves. This position requires an active Secret clearance and the ability to obtain a CBP Background Investigation; U.S. citizenship is required.
This is hands-on cyber engineering, not paper compliance. You'll work alongside platform engineers, ISSOs, and the CBP security team to harden deployments, validate controls, and resolve findings against real systems. If you want to do federal cybersecurity in an environment that ships fast and treats security as part of the product, keep reading.
LIGER sits within LMI's Chief Technology Office. We're a small, high-visibility team building AI tools for federal agencies. The culture is more startup than traditional government contractor; we move fast, solve problems in design spikes rather than scheduled reviews, and care more about outcomes than process. That said, we're building for users who need reliability and trust, so craft and attention to detail matter, especially in security.
You'll work daily with the platform lead, engineering team, and product manager, and directly with CBP cyber stakeholders. Security and compliance are foundational to how LIGER ships, and this is a real opportunity to define how the platform maintains its CBP authorization while continuing to iterate.
LMI is a new breed of digital solutions provider dedicated to accelerating government impact with innovation and speed. Investing in technology and prototypes ahead of need, LMI brings commercial-grade platforms and mission-ready AI to federal agencies at commercial speed.
Leveraging our mission-ready technology and solutions, proven expertise in federal deployment, and strategic relationships, we enhance outcomes for the government, efficiently and effectively. With a focus on agility and collaboration, LMI serves the defense, space, healthcare, and energy sectors-helping agencies navigate complexity and outpace change. Headquartered in Tysons, Virginia, LMI is committed to delivering impactful results that strengthen missions and drive lasting value.
Responsibilities
What You'll Do
• Lead Risk Management Framework (RMF) activities for the LIGER deployment at CBP, including system categorization, control selection and tailoring, implementation, assessment, and continuous monitoring
• Own and maintain authorization artifacts: System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and supporting documentation aligned to CBP and DHS requirements
• Coordinate directly with CBP ISSOs, Authorizing Officials, and cyber working groups to advance ATO and continuous authorization activities
• Interpret NIST 800-53 controls in the context of the LIGER platform and translate them into actionable engineering requirements
• Run and review vulnerability scans across CI/CD pipelines and runtime environments, triage findings, and drive remediation through the engineering team
• Validate secure configurations and hardening baselines (e.g., CIS Benchmarks, DISA STIGs) on containers, hosts, and cloud resources
• Partner with platform engineers on cloud and container security in AWS GovCloud, including IAM, network controls, secrets management, logging, and runtime protection
• Develop and maintain security policies, procedures, and standard operating procedures (SOPs) specific to LIGER on CBP infrastructure
• Track audit findings, remediation actions, and POA&M items to closure
• Support FedRAMP-aligned control implementation and inheritance where applicable
• Advise senior LIGER and CBP leadership on system risk levels, control effectiveness, and emerging compliance considerations for AI/LLM systems in federal environments
Qualifications
What We're Looking For
• A ctive Secret clearance and the ability to obtain a CBP Background Investigation; U.S. citizenship is required.
• Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field
• 5+ years of experience designing, implementing, and monitoring cybersecurity solutions in federal environments
• 5+ years of hands-on RMF experience, including ATO development and continuous monitoring against NIST 800-53
• CISSP, CISM, or equivalent senior-level cybersecurity certification
• Strong working knowledge of cloud security, particularly AWS, with experience in GovCloud or similar high-compliance environments
• Experience with vulnerability management workflows: scanning, triage, remediation tracking, and reporting
• Experience hardening systems against secure baselines such as CIS Benchmarks or DISA STIGs
• Familiarity with secure software development practices: secrets management, access control, auditability, and CI/CD pipeline security
• Strong written communication skills, including the ability to produce ATO artifacts that hold up to assessor and AO review
• Ability to translate compliance requirements into specific engineering work and partner closely with developers
What Will Set You Apart
• Active CBP Background Investigation or prior CBP/DHS program support
• Direct experience supporting ATO or continuous authorization for systems hosted at CBP, DHS, or another DHS component
• Familiarity with DHS 4300A and CBP-specific cybersecurity policies and processes
• FedRAMP readiness or assessment experience (Moderate or High)
• Hands-on container and Kubernetes security experience (e.g., EKS, image scanning, admission control, runtime protection)
• DevSecOps experience integrating security scanning into GitLab CI/CD pipelines
• Experience securing LLM, GenAI, or agentic AI systems, including data handling, prompt and tool-call risk, and model output controls
• Experience with vulnerability management platforms such as Tenable
• Experience with ATO documentation tooling (e.g., Xacta, OpenRMF, or similar)
• Familiarity with CISA Binding Operational Directives, Continuous Diagnostics and Mitigation (CDM), or High Value Asset (HVA) program requirements
Target salary range: $111,427 - $200,000
Disclaimer: The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.
We're looking for a Cybersecurity Engineer to support the secure deployment and continuous authorization of LIGER, an enterprise AI platform built for federal missions, into a U.S. Customs and Border Protection (CBP) environment. You'll join a small, high-visibility team and own the security work that lets LIGER reach production at CBP and stay there: maintaining the ATO posture, driving vulnerability management, and partnering with CBP cyber stakeholders to keep the platform compliant as it evolves. This position requires an active Secret clearance and the ability to obtain a CBP Background Investigation; U.S. citizenship is required.
This is hands-on cyber engineering, not paper compliance. You'll work alongside platform engineers, ISSOs, and the CBP security team to harden deployments, validate controls, and resolve findings against real systems. If you want to do federal cybersecurity in an environment that ships fast and treats security as part of the product, keep reading.
LIGER sits within LMI's Chief Technology Office. We're a small, high-visibility team building AI tools for federal agencies. The culture is more startup than traditional government contractor; we move fast, solve problems in design spikes rather than scheduled reviews, and care more about outcomes than process. That said, we're building for users who need reliability and trust, so craft and attention to detail matter, especially in security.
You'll work daily with the platform lead, engineering team, and product manager, and directly with CBP cyber stakeholders. Security and compliance are foundational to how LIGER ships, and this is a real opportunity to define how the platform maintains its CBP authorization while continuing to iterate.
LMI is a new breed of digital solutions provider dedicated to accelerating government impact with innovation and speed. Investing in technology and prototypes ahead of need, LMI brings commercial-grade platforms and mission-ready AI to federal agencies at commercial speed.
Leveraging our mission-ready technology and solutions, proven expertise in federal deployment, and strategic relationships, we enhance outcomes for the government, efficiently and effectively. With a focus on agility and collaboration, LMI serves the defense, space, healthcare, and energy sectors-helping agencies navigate complexity and outpace change. Headquartered in Tysons, Virginia, LMI is committed to delivering impactful results that strengthen missions and drive lasting value.
Responsibilities
What You'll Do
• Lead Risk Management Framework (RMF) activities for the LIGER deployment at CBP, including system categorization, control selection and tailoring, implementation, assessment, and continuous monitoring
• Own and maintain authorization artifacts: System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and supporting documentation aligned to CBP and DHS requirements
• Coordinate directly with CBP ISSOs, Authorizing Officials, and cyber working groups to advance ATO and continuous authorization activities
• Interpret NIST 800-53 controls in the context of the LIGER platform and translate them into actionable engineering requirements
• Run and review vulnerability scans across CI/CD pipelines and runtime environments, triage findings, and drive remediation through the engineering team
• Validate secure configurations and hardening baselines (e.g., CIS Benchmarks, DISA STIGs) on containers, hosts, and cloud resources
• Partner with platform engineers on cloud and container security in AWS GovCloud, including IAM, network controls, secrets management, logging, and runtime protection
• Develop and maintain security policies, procedures, and standard operating procedures (SOPs) specific to LIGER on CBP infrastructure
• Track audit findings, remediation actions, and POA&M items to closure
• Support FedRAMP-aligned control implementation and inheritance where applicable
• Advise senior LIGER and CBP leadership on system risk levels, control effectiveness, and emerging compliance considerations for AI/LLM systems in federal environments
Qualifications
What We're Looking For
• A ctive Secret clearance and the ability to obtain a CBP Background Investigation; U.S. citizenship is required.
• Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field
• 5+ years of experience designing, implementing, and monitoring cybersecurity solutions in federal environments
• 5+ years of hands-on RMF experience, including ATO development and continuous monitoring against NIST 800-53
• CISSP, CISM, or equivalent senior-level cybersecurity certification
• Strong working knowledge of cloud security, particularly AWS, with experience in GovCloud or similar high-compliance environments
• Experience with vulnerability management workflows: scanning, triage, remediation tracking, and reporting
• Experience hardening systems against secure baselines such as CIS Benchmarks or DISA STIGs
• Familiarity with secure software development practices: secrets management, access control, auditability, and CI/CD pipeline security
• Strong written communication skills, including the ability to produce ATO artifacts that hold up to assessor and AO review
• Ability to translate compliance requirements into specific engineering work and partner closely with developers
What Will Set You Apart
• Active CBP Background Investigation or prior CBP/DHS program support
• Direct experience supporting ATO or continuous authorization for systems hosted at CBP, DHS, or another DHS component
• Familiarity with DHS 4300A and CBP-specific cybersecurity policies and processes
• FedRAMP readiness or assessment experience (Moderate or High)
• Hands-on container and Kubernetes security experience (e.g., EKS, image scanning, admission control, runtime protection)
• DevSecOps experience integrating security scanning into GitLab CI/CD pipelines
• Experience securing LLM, GenAI, or agentic AI systems, including data handling, prompt and tool-call risk, and model output controls
• Experience with vulnerability management platforms such as Tenable
• Experience with ATO documentation tooling (e.g., Xacta, OpenRMF, or similar)
• Familiarity with CISA Binding Operational Directives, Continuous Diagnostics and Mitigation (CDM), or High Value Asset (HVA) program requirements
Target salary range: $111,427 - $200,000
Disclaimer: The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.
group id: RTL412549