3 дня назад
Assessment & Authorization (A&A;) Lead (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Assessment & Authorization (A&A;) Lead (Cybersecurity) (NIST RMF/Federal ATO): Leading end-to-end security assessment, authorization, and continuous monitoring activities for federal information systems with an accent on NIST RMF, FISMA compliance, authorization packages, and team leadership. Focus on evaluating security controls and residual risks, managing POA&M remediation, coordinating concurrent ATO deadlines, and presenting authorization risks to government stakeholders.
Location: Rockville, Maryland, United States
What you will do
- Lead the end-to-end assessment and authorization process, including the full Authorization to Operate lifecycle, for federal information systems.
- Manage and mentor a team of five to eight Security Control Assessors, ISSOs, and cybersecurity professionals.
- Develop ATO schedules, milestones, priorities, and resource assignments while coordinating with system owners, technical teams, authorizing officials, and other stakeholders.
- Review security authorization packages, control evidence, risk assessments, contingency plans, and continuous monitoring documentation.
- Oversee security control assessments, risk ratings, vulnerability and POA&M remediation, quality assurance reviews, and authorization-readiness activities.
- Prepare executive dashboards and reports, identify delivery risks and documentation gaps, and support annual assessments, significant-change reviews, and authorization renewals.
Requirements
- Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related discipline.
- At least eight years of cybersecurity, information assurance, or information system security experience, including at least five years supporting federal A&A, ATO, or NIST RMF activities.
- Experience leading teams of Security Control Assessors, ISSOs, or cybersecurity analysts.
- Strong knowledge of NIST RMF, NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, NIST SP 800-30, FISMA, and federal continuous monitoring practices.
- Experience reviewing complex authorization packages, evaluating security control evidence, and managing security risks, vulnerabilities, POA&M items, and concurrent authorization activities.
- At least one active certification is required: CISSP or CISM.
Nice to have
- Experience supporting NIH, HHS, or other federal civilian cybersecurity programs.
- Experience with CSAM, JCAM, ServiceNow GRC, or similar governance, risk, and compliance platforms.
- Familiarity with FedRAMP and cloud security controls for AWS, Microsoft Azure, or other cloud environments.
- Additional certifications such as CAP/CGRC, CRISC, CCSP, PMP, or Security+.
- Experience supporting high-impact federal systems or managing portfolios with concurrent ATO deadlines.
Culture & Benefits
- Hands-on leadership focused on accountability, collaboration, coaching, and consistent delivery quality.
- Direct engagement with senior government stakeholders, system owners, engineers, cybersecurity teams, and third-party assessors.
- Success is measured by timely ATO milestones, complete documentation, reduced overdue assessments and POA&M items, accurate risk reporting, and consistent NIST RMF application.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
18 часов назад
Cybersecurity Assessment and Oversight Specialist (Cybersecurity)
1 день назад
Security Controls Assessor / ISSO (Cybersecurity & Compliance)
4 часа назад
Lead Cyber Security Data Visualizer (Cybersecurity)
5 дней назад
Vulnerability Management Leader (Cybersecurity)
3 дня назад
Security Manager HQ AFMC/A4/10-3007.0 (Cybersecurity)
140 000 - 160 000$
1 день назад