V

InfoSec Engineer - Compliance (ATO)

Vannevarlabs
1 month ago
Full-time
Remote
Worldwide
Remote Cybersecurity

Vannevar is a defense technology company building AI to deter our adversaries. In the 21st century, conflict moves at algorithmic speed and foresight equals firepower. Our agentic AI is purpose-built to compete with China—from cross-Strait conflict to gray zone coercion. Trained on the most mission-relevant datasets in defense, our technology models adversary behavior, simulates campaigns, and recommends the best course of action to decision makers. Our AI systems are some of the most trusted in the industry and actively used on the front lines of the Indo-Pacific to keep the peace and save lives.

Exceptional technology starts with exceptional people. Vannevar is a small agile team combining world-class engineers with veteran strategists who bring deep expertise in defense and tradecraft. We’re building a company defined by mission impact, user empathy, and disciplined growth. In just three years, we grew from $3M to $80M in ARR, achieved early profitability, and reached unicorn status—proving that disruption doesn’t require an ego, and staying power doesn’t mean standing still.

About the role

Vannevar Labs is seeking an experienced Information Security Engineer to lead our IL-6 / IL-7 ATO (Authority to Operate) and follow-on compliance efforts. This role will be critical to unlocking our ability to deploy classified capabilities for defense and intelligence customers. You will serve as the dedicated technical leader responsible for achieving platform operation on classified networks, working directly with government ISSMs, AOs, and security stakeholders to navigate the RMF process and achieve ATOs across Navy, Joint, and COCOM user groups.

What you’ll do

  • Own and execute our strategy for how we approach ATOs across our customers.
  • Lead the end-to-end ATO process for IL-6 (SIPR) and IL-7(JWICS) environments, through full authorization and follow-on compliance.
  • Own RMF (Risk Management Framework) documentation and control implementation across multiple simultaneous ATOs
  • Work with 3PAOs and federal government AOs to achieve compliance certifications and reports
  • Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures • Serve as a liaison between system owners and other security personnel, ensuring that selected security controls are effectively implemented and maintained throughout the lifecycle of projects
  • Interface directly with government ISSMs, AOs, and security stakeholders to manage authorization packages and navigate accreditation tools (XACTA, eMASS)
  • Design and implement role-based access controls, data classific