Kryptek LLC

Security and ATO Engineer (Contract, 1099, Part Time, Remote, US)

Herndon, VA • Posted 2 days ago • $120 - $140 per hour
Remote Part Time General

Remote, United States Contract, part time

Reports to: Technical Lead and Solution Architect
Engagement type: Independent contractor, 1099
Term: Twelve months, with extension potential
Location: Fully remote within the United States. No travel required
Status: United States citizenship required. Engagement contingent on program start

ABOUT KRYPTEK

Kryptek LLC builds governed AI systems for clients operating under regulatory obligation. The work this role supports is agentic compliance monitoring at scale: pipelines that ingest public and client-furnished data, validate it against regulatory requirements using deterministic rules, detect drift over time, and assemble evidence packages a reviewer can defend months after the fact. The agentic layer drafts narratives, clusters findings to root cause, and reconciles conflicting sources. It never renders a determination. Every finding passes a recorded human review gate before it can leave the system. The platform runs on Amazon Bedrock inside AWS GovCloud (US) and is engineered to carry a federal Authority to Operate.

Kryptek also delivers managed detection and response, cloud security, and Zero Trust engineering on Microsoft Sentinel and Palo Alto Cortex XSIAM. We are a small, senior team, and the people we hire own their scope end to end rather than executing someone else's ticket queue.

YOUR CAREER

You own the implementation of the technical controls and boundaries. The Compliance and Assurance Lead owns the written representation of that fact to the client, and the division between those two jobs is deliberate and enforced. You implement the controls in AWS GovCloud, you collect and package the evidence, you attest to what is actually built, and you carry the assessor through technical walkthroughs and finding remediation. You will collaborate with the Compliance and Assurance Lead to build and maintain the System Security Plan.

YOUR IMPACT

- Implement technical security controls in AWS GovCloud: IAM least privilege with role separation aligned to the data flow, KMS customer-managed keys using FIPS 140 validated modules, Secrets Manager with rotation and no credential material in code or configuration or images, centralized logging with integrity protection, network controls, host and container hardening, and vulnerability management
- Own control evidence collection, artifact capture, and evidence package assembly against the applicable NIST SP 800-53 baseline
- Supply and attest to the underlying technical fact behind every control implementation statement the Compliance and Assurance Lead writes. Attestation is a recorded action with a date and an artifact reference, not a conversation
- Support authorization boundary definition and the informal boundary discussion with the agency security office inside the first sixty days
- Own assessor evidence requests, technical walkthroughs, and remediation of assessment findings
- Run automated dependency and container scanning with remediation windows by severity, and produce a software bill of materials per release
- Build and maintain the testable network control proving no egress path exists from the application subnets to any public model provider, which is the control that keeps every model invocation inside the authorization boundary
- Verify the append-only hash-chained audit log and the operator chain-verification command that the client will run itself after transition

YOUR EXPERIENCE

- 6 or more years of hands-on cloud security engineering, with substantial AWS experience
- NIST SP 800-53 Moderate technical control implementation, hands on keyboard. This is an implementation and evidence role, not a policy authorship role
- Direct experience producing evidence for a third-party assessment organization or an agency assessment team, including the unglamorous part where the assessor asks for something in a format nobody anticipated
- AWS GovCloud, FedRAMP, or DoD Impact Level environment experience strongly preferred
- Depth in IAM, KMS, Secrets Manager, CloudTrail, Config, GuardDuty, and Security Hub
- STIG or CIS benchmark remediation experience
- Experience in technical assistance related to submitting and/or achieving an Authority to Operate (ATO), Continuous Authority to Operate (cATO), or FedRAMP ATO
- Working familiarity with the Risk Management Framework, sufficient to collaborate with a compliance lead without duplicating that role's work
- Certifications a plus: AWS Certified Security Specialty, CISSP, GIAC GCSA, CompTIA Security+
- Relevant bachelor's degree, equivalent military experience, or equivalent professional experience
- United States citizenship is required. No security clearance is required for this role at present

COMPENSATION AND ENGAGEMENT TERMS

Rate. $120 to $140 per hour, paid as an independent contractor engagement. Placement within the range depends on depth of GovCloud and NIST SP 800-53 implementation experience.

This position is contingent on program start. Kryptek has committed to seating every open role within 30 days of go-ahead.

Your resume will be submitted to the client for approval before you begin work, so the client sees the individual performing rather than a labor category.

Fully remote within the United States. No travel is required for this role.

United States citizenship is required. No security clearance is required at present.

Kryptek delivers services and does not operate as a staffing agency. You will own a defined scope on our side of the work, not fill a seat on someone else's team.

TO APPLY

Send a resume to with "Security and ATO Engineer" in the subject line. Include a short note on the one item in Your Experience above that you consider your strongest claim, and how you would evidence it.

Security and ATO Engineer (Contract, 1099, Part Time, Remote, US) in Herndon at Kryptek LLC

Other openings
5

Kryptek LLC currently has 5 other roles open on LocalWork in Herndon. If this particular role is not the right fit, their other openings may be.

This position is listed as part time and able to be worked remotely. It was posted 2 days ago.

See all Kryptek LLC jobs on LocalWork →

Back to Job Search