RMF and Authorization Lead

Posted 10 Days Ago
Be an Early Applicant
2 Locations
Hybrid
165K-185K Annually
Expert/Leader
Big Data • Information Technology • Software • Analytics
The Role
Lead Federal Risk Management Framework and Authorization and Assessment activities across multiple authorization boundaries. Maintain system security plans, assessment reports, plans of action and milestones, authority-to-operate documentation, and supporting evidence. Coordinate security assessments, GRC platform activities, risk analysis, remediation tracking, cloud and FedRAMP documentation, control inheritance, system changes, onboarding, and decommissioning. Serve as the senior technical authority while coordinating with system owners, ISSOs, privacy officials, assessors, and agency cybersecurity personnel.
Summary Generated by Built In

Empower, Innovate, Impact!  At Team A-TEK, we EMPOWER people to drive INNOVATION that IMPACTS mission!

A-TEK operates at the intersection of mission and innovation by applying our deep domain expertise across the federal markets. Embracing our digital-first strategy, A-TEK provides enhanced capabilities in application development, digital transformation, enterprise IT, and scientific services. Our solutions are designed to modernize, automate, secure, protect, and enhance the operations of our federal clients, ensuring they stay ahead in a rapidly evolving digital landscape.

Our work is fueled by a passion to serve our clients’ needs and to protect the safety and welfare of Americans. That passion shapes how we nurture our most valuable asset – Our Employees. A-TEK actively cultivates the talent that drives our success and fosters a creative, challenging, and mission-driven work environment for current and future employees.


A-TEK is seeking an experienced RMF/A&A Lead to support our federal customer.  The RMF/A&A Lead serves as the senior technical authority for RMF and A&A activities supporting an HHS-affiliated agency. This individual leads authorization readiness, authorization package development and maintenance, Governance, Risk, and Compliance activities, cybersecurity documentation, risk management, and system lifecycle support. The Lead coordinates with system owners, ISSOs, administrators, privacy officials, assessors, and agency cybersecurity personnel to maintain complete, current, and audit ready authorization packages. The ability to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle, NC area is required.

Responsibilities

  • Lead RMF activities across three primary authorization boundaries and the associated system inventory.
  • Maintain SSPs, SARs, POA&Ms, Executive Summaries, ATO documentation, and supporting evidence.
  • Coordinate three annual security control assessments and prepare evidence for the independent assessor.
  • Maintain assessor independence and avoid acting as the assessor of record unless the agency expressly authorizes an activity.
  • Direct system registration, inventory reconciliation, artifact maintenance, data quality review, and status validation in the agency’s designated GRC platform.
  • Lead POA&M management, residual risk analysis, risk reporting, and remediation tracking.
  • Support cloud and FedRAMP documentation, control inheritance analysis, and shared responsibility analysis.
  • Review major changes, prepare security impact analyses, and support onboarding and decommissioning.
  • Conduct technical and quality reviews before submitting cybersecurity artifacts.
  • Identify and escalate risks that could affect an authorization, assessment, or deliverable schedule.
  • Support transition activities and reconcile authorization boundaries, inventories, artifacts, and active work.

Required Experience and Qualifications

  • Demonstrated experience leading Federal RMF and A&A activities of comparable scope and complexity.
  • Knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA, and Federal continuous monitoring requirements.
  • Experience developing and maintaining Federal authorization packages.
  • Experience supporting independent security assessments, POA&M management, and risk-based decisions.
  • Strong technical writing, stakeholder coordination, and quality review skills.
  • Ability to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle area.
  • Education and experience that satisfy the proposed GSA labor category.

Preferred Experience and Qualifications 

  • Experience supporting HHS or another Federal health agency.
  • Experience using JCAM or a comparable Federal GRC platform.
  • Experience supporting cloud security, FedRAMP, inherited controls, and shared responsibility analysis.
  • Experience coordinating multiple concurrent authorization, assessment, and continuous monitoring activities.
  • CISSP, CAP/CGRC, CISM, Security+, or an applicable cloud security certification.

Compensation 

Salary Range: $165,000 – $185,000 annually (commensurate with experience) 
Benefits: Health, dental, and vision insurance; 401(k) with employer match; paid time off; professional development opportunities. 

Why Join Us? 

This is an opportunity to make a direct impact on healthcare data processes that support critical regulatory functions. You will collaborate with dedicated professionals, work on meaningful projects, and contribute to improvements in public health systems. 



Candidates may use tools (including AI) for proofreading or formatting; however, using any tool to fabricate, exaggerate, or misrepresent qualifications, experience, or work product is not permitted. We may assess application materials for job-related technical depth, internal consistency, and demonstrated hands-on experience, including through follow-up questions, skills assessments, or reference checks. Verification of education may be requested before or during the hiring process.

For security and identity verification purposes, participants may be asked to temporarily disable virtual backgrounds during portions of the call.

Misrepresentation or falsification may result in removal from further consideration. Candidates who need a reasonable accommodation in the application or interview process may request one.

A-TEK, Inc. is an Equal Opportunity/Affirmative Action employer.  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or status as a qualified individual with a disability, or Vietnam era or other protected Veteran status. 

Skills Required

  • Demonstrated experience leading Federal RMF and A&A activities of comparable scope and complexity
  • Knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA, and Federal continuous monitoring requirements
  • Experience developing and maintaining Federal authorization packages
  • Experience supporting independent security assessments, POA&M management, and risk-based decisions
  • Strong technical writing, stakeholder coordination, and quality review skills
  • Ability to support hybrid work in the Washington, DC metropolitan area or Research Triangle, NC area
  • Education and experience satisfying the proposed GSA labor category
  • Experience supporting HHS or another Federal health agency
  • Experience using JCAM or a comparable Federal GRC platform
  • Experience supporting cloud security, FedRAMP, inherited controls, and shared responsibility analysis
  • Experience coordinating multiple concurrent authorization, assessment, and continuous monitoring activities
  • CISSP, CAP/CGRC, CISM, Security+, or an applicable cloud security certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Mc Lean, VA
148 Employees
Year Founded: 1996

What We Do

A-TEK, and our wholly-owned subsidiary, Mackson Consulting | an A-TEK Company, are woman-owned small businesses with more than a 23-year history providing science and technology innovation. As a trusted services and solutions provider, we are a proud partner to U.S. Federal Civilian, Federal Health, and Homeland Security customers. A-TEK, and its subsidiary, Mackson Consulting, provides high-end IT services and solutions, coupled with a scientific staffing capability that supports health and national security missions. Our customers include U.S. Department of Homeland Security, Health and Human Services (National Institutes of Health (NIH), Food and Drug Administration (FDA), Centers for Medicare & Medicaid Services (CMS)), Department of Commerce (DoC), Department of Justice(DoJ), Veteran Affairs (VA), and the Library of Congress (Library). A-TEK maintains its competitiveness by applying domain expertise across the federal markets. We provide enhanced capabilities in application development, enterprise IT, and scientific services that optimize, modernize, secure, protect, improve, and comply with customers’ needs. A-TEK's program engagement model employs methodologies and strategies based on PMBOK and our ISO 9001:2015 certified quality assurance processes to successfully meet schedule, budget and performance objectives. A-TEK, Inc. is an Equal Opportunity, Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or status as a qualified individual with a disability, or Vietnam era or other protected Veteran status. Contract Vehicles: NIH CIO-SP3 IT Services - HHSN316201200006W GSA Schedule 70 - Information Technology Products and Services: GS-35F-0680K GSA Schedule 6211 - VA Affairs-Professional & Allied Healthcare Staffing: V77P-7135 GSA Schedule 874 MOBIS - GS-10F-0099Y

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

C5ISR Engineering Technologist II

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
California, MD, USA
40000 Employees
79K-135K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

IFF Engineering Technician (Navy Combat Systems)

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
St. Inigoes, MD, USA
40000 Employees
28-43 Hourly

BAE Systems, Inc. Logo BAE Systems, Inc.

Engineering Lead - Criticality, Trust and Assurance

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Rockville, MD, USA
40000 Employees
133K-226K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Project Manager

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Rockville, MD, USA
40000 Employees
118K-201K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account