Who We Are
Proactive Logic Consulting INC is a boutique technology consulting firm specializing in security assessments and roadmaps, cloud modernization, application modernization, process automation and AI, and regulated healthcare delivery.
We bring together senior independent consultants who combine deep technical judgment, high EQ, a customer-obsessed mindset, and an entrepreneurial approach to delivery.
Opportunity Context
We are building a vetted consulting bench for anticipated VA and federal-health cloud-security engagements. This is a future or contingent consulting opportunity. It is not federal employment and does not imply that Proactive Logic currently holds a Department of Veterans Affairs award. Engagement timing depends on client demand and contracting approvals.
What We're Looking For
We are seeking a Senior Federal Health Cloud Security & RMF/ATO Consultant who can turn federal security requirements into working application, identity, cloud, delivery-pipeline, and evidence practices.
This is a remote, 1099 Corp-to-Corp opportunity for a senior independent consultant. You must be equally comfortable reviewing architecture, facilitating control decisions, implementing security patterns, testing the result, producing authorization evidence, and helping delivery teams adopt sustainable practices.
Key Requirements
VA or Federal-Health Security Delivery
- At least 3 years of hands-on security delivery for VA, VHA, HHS, CMS, DoD health, or a comparable federal-health environment.
- Direct experience supporting RMF or ATO work for a production federal information system.
- Familiarity with VA Technical Reference Model alignment, federal system boundaries, inherited controls, continuous monitoring, and authorization stakeholders.
Security Authorization and Controls
- At least 10 years across application, cloud, identity, DevSecOps, or information-system security.
- Working depth with NIST 800-53 Rev. 5, FISMA, RMF, security categorization, control implementation, assessment evidence, SSPs, POA&Ms, risk acceptance, and continuous monitoring.
- Ability to distinguish implemented controls from inherited, planned, compensating, and unsupported claims.
- Experience producing clear diagrams, control narratives, evidence packages, test results, findings, and remediation plans.
Identity and Zero Trust
- OAuth 2.0, OpenID Connect, JWT or JWS, PKI, mTLS, key rotation, workload identity, short-lived credentials, and service authorization.
- Familiarity with PIV or CAC and VA identity patterns such as SSOe or SSOi is strongly preferred.
- Practical zero-trust design across users, workloads, APIs, networks, devices, data, and telemetry.
- Threat modeling tied to real system boundaries, attacker paths, data sensitivity, and operational constraints.
Cloud and DevSecOps
- At least 3 years securing AWS GovCloud, Azure Government, VA Enterprise Cloud, or comparable regulated cloud environments.
- IAM, KMS or Key Vault, secrets management, network controls, security logging, detection, vulnerability management, configuration baselines, backup, recovery, and incident response.
- Containers and Kubernetes security, infrastructure as code, policy as code, CI/CD gates, SAST, DAST, dependency scanning, SBOMs, artifact signing, and supply-chain controls.
- Experience using FedRAMP-authorized services and documenting shared-responsibility and inherited-control decisions.
Federal Health and Data Protection
- Strong handling of PHI, PII, CUI, least privilege, data minimization, retention, auditability, and secure operational troubleshooting.
- Working knowledge of Section 508 implications for authentication, security workflows, and administrative experiences.
- Ability to collaborate with privacy, accessibility, clinical, program, engineering, platform, and security stakeholders.
AI-Forward Delivery and AI Security
- At least 1 year of daily use of Claude Code, OpenAI Codex, Cursor, GitHub Copilot, or equivalent coding agents.
- Strong review practices for agent-generated security, identity, infrastructure, policy, and cryptographic code.
- Experience using approved AI tools without exposing PHI, PII, CUI, credentials, production data, or sensitive architecture to uncontrolled services.
- Ability to define safe AI-use boundaries, human approval gates, tests, logging, and evidence for regulated delivery.
Consulting and Business Structure
- At least 5 years of client-facing consulting, assessment, authorization, or equivalent senior stakeholder delivery.
- Excellent facilitation and communication; able to explain risk and tradeoffs without fearmongering or security theater.
- Active owner-operated LLC or S-Corp required.
- 1099 Corp-to-Corp only. No W-2 and no staffing agencies.
- Ability to satisfy federal suitability or Public Trust requirements when an engagement requires it.
What You'll Do
- Assess application, identity, cloud, data, DevSecOps, and authorization boundaries.
- Build a practical control and evidence roadmap aligned to mission risk and delivery constraints.
- Support RMF and ATO activities, including control implementation, evidence collection, assessment preparation, POA&M remediation, and continuous monitoring.
- Design and implement reusable identity, secrets, IAM, logging, container, pipeline, and policy patterns.
- Threat-model systems and validate controls with automated and manual testing.
- Produce concise, auditable architecture, control, test, remediation, and operational artifacts.
- Pair with engineering and security teams so controls remain usable and sustainable.
- Use AI coding agents to accelerate delivery within approved federal-health data and security boundaries.
Preferred Experience
- VA Directive or Handbook 6500, VA TRM, VA Enterprise Cloud, VA Lighthouse security patterns
- NIST 800-53 Rev. 5, NIST RMF, FISMA Moderate or High, FedRAMP, and federal continuous monitoring
- AWS GovCloud, Azure Government, Kubernetes, Terraform, Bicep, GitHub Actions, or Azure DevOps
- OAuth, OIDC, PIV, CAC, SSOe, SSOi, API gateways, workload identity, PKI, and service mesh
- Healthcare APIs, FHIR, Veteran or patient identity, clinical systems, benefits systems, or regulated data platforms
How to Apply
Please provide:
- A resume or consultant profile showing federal-health security and authorization engagements and dates.
- A short description of an RMF or ATO effort you personally supported and your specific responsibilities.
- One example of a cloud, identity, application-security, or DevSecOps control you implemented and how you proved it worked.
- A description of your LLC or S-Corp, including its legal name and state.
- A brief example of how you use AI coding agents without exposing federal or healthcare data.
- Sanitized control narratives, diagrams, assessments, technical writing, or references when available.
Equal Opportunity
We welcome all qualified applicants.
Agencies
We are not engaging staffing agencies for this opportunity.
Job Type: Contract
Compensation Package: 1099 contract
Work Location: Remote
Pay: $77.19 - $110.00 per hour
Work Location: Remote