Security Operations Engineer
Pantheon · United States - Remote · Remote
Pay: USD 130,000 – 170,000 a year
Posted Aug 19, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Program context
This is a Federal AI Adoption Initiative for Healthcare. We are supporting a large-scale effort to accelerate the safe, effective, and responsible adoption of artificial intelligence across healthcare. Part of that work is making sure the public hub and everything behind it meets a real federal security bar before it's trusted with any data. This role owns getting there, and keeping it that way, for the life of the system.
What you'll own
You will lead development of the platform's Authority to Operate package, including the system security plan, privacy impact assessment, security assessment report, and plan of action and milestones.
You will implement and document NIST 800-53 controls across the platform.
You will own the platform's ongoing security operations once the Authority to Operate is granted, including continuous monitoring, vulnerability remediation, and incident response.
You will keep the plan of action and milestones current over the life of the system, closing findings rather than letting them accumulate.
You will work directly with federal information system security officers and authorizing officials through the security review process and for the life of the system afterward.
## Required qualifications (hard gates)
- Experience leading or majorly contributing to an Authority to Operate package for a FISMA Moderate or High system
- Working knowledge of NIST 800-53 controls, including hands-on implementation experience
- Experience owning ongoing security operations after an Authority to Operate is granted, including continuous monitoring and vulnerability remediation
- CISSP, CAP, CISM, or an equivalent security certification, or equivalent demonstrated experience
Strongly preferred
- Deep NIST 800-53 Rev 5 knowledge across all control families
- Direct experience working with a federal information system security officer or authorizing official over the life of a system, not only during initial authorization
- Additional cloud security certifications
## What we screen for in interview
We ask the candidate to walk through an Authority to Operate package they owned, including specific documentation deliverables.
We ask how they ran continuous monitoring and vulnerability remediation after authorization, including a specific finding they closed.
We ask about their experience navigating a federal security review process directly with agency stakeholders.
Disqualifiers
- Cannot pass the required background or Authority to Operate-adjacent security review
- No Authority to Operate documentation experience
- No ongoing security operations experience beyond initial authorization
- No security certification or equivalent demonstrated experience
## Equal Employment Opportunity & Legal Notices
Pantheon is an Equal Employment Opportunity employer. All qualified applicants are considered for employment without regard to race, color, religion, sex, sexual…