Hiring.Camp

RMF/ATO Analyst

Agil3 Technology Solutions (A3T)

·

Today

Salary
$100k – $115k
Location
Quantico, VA
Type
Full-time
Education
Bachelor
Closing date
Today
Source
ApplyToJob

Description

Agil3 Technology Solutions (A3T) is seeking an experienced Risk Management Framework (RMF) / Authorization to Operate (ATO) Analyst to support cybersecurity authorization, compliance, documentation, and continuous monitoring activities for the U.S. Government.

The RMF/ATO Analyst will support the development, maintenance, assessment, and management of RMF documentation and authorization packages for the customer’s information systems. The position will work closely with Government cybersecurity personnel, ISSOs/ISSMs, system owners, and A3T's cybersecurity and engineering teams to maintain system authorization and compliance throughout the system lifecycle.

Key Responsibilities
  • Support implementation and execution of the DoD Risk Management Framework (RMF) for assigned information systems.
  • Develop, maintain, review, and update RMF and cybersecurity authorization documentation.
  • Support preparation and maintenance of ATO packages throughout the authorization lifecycle.
  • Maintain system authorization information and cybersecurity artifacts within eMASS.
  • Support development, review, and maintenance of system security documentation and RMF artifacts.
  • Coordinate security-control implementation and documentation with system owners, ISSOs/ISSMs, Systems Engineers, Network Engineers, Cloud Engineers, and Systems Administrators.
  • Collect, review, organize, and validate technical evidence supporting security-control implementation and assessment.
  • Track security-control deficiencies and support development and maintenance of Plans of Action and Milestones (POA&Ms).
  • Monitor POA&M corrective actions and coordinate with responsible technical personnel to obtain evidence of remediation and closure.
  • Support RMF control assessments, security reviews, validation activities, and authorization decisions.
  • Review DISA STIG, vulnerability, configuration, and cybersecurity assessment results for inclusion in authorization documentation.
  • Assist technical teams with interpreting RMF documentation and evidence requirements.
  • Support continuous monitoring activities to maintain system authorization and cybersecurity compliance.
  • Evaluate proposed system changes to determine potential impacts to authorization boundaries, security controls, and existing ATOs.
  • Maintain accurate system inventories, authorization boundaries, architecture information, control documentation, and supporting artifacts.
  • Coordinate authorization activities with Government cybersecurity personnel and other applicable USMC/DoD stakeholders.
  • Track RMF milestones, deliverables, assessment findings, authorization expiration dates, and other compliance requirements.
  • Support recurring cybersecurity reviews and provide RMF/ATO status information for program and Government briefings.
  • Assist with development and delivery of RMF-related training and guidance to technical and program personnel.
  • Support reauthorization activities, system modifications, technology refreshes, migrations, and system decommissioning as required.
Minimum Experience:
  • Must have 5–8+ years of cybersecurity, information assurance, RMF, ATO, or security-compliance experience.
  • Must have an active DoD Secret security clearance.
  • Must satisfy applicable DoD 8140/DCWF requirements for Work Role 722 at the Advanced proficiency level.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related discipline.
  • Hands-on experience supporting the DoD Risk Management Framework and system authorization processes.
  • Experience developing and maintaining RMF/ATO documentation and supporting artifacts.
  • Demonstrated experience using eMASS.
  • Experience with security-control implementation, assessment, documentation, and evidence collection.
  • Experience developing and managing POA&Ms and tracking cybersecurity findings through remediation.
  • Working knowledge of DoD cybersecurity policies and authorization processes.
  • Knowledge of NIST security controls, DISA STIGs, vulnerability-management processes, and continuous monitoring.
  • Ability to interpret technical cybersecurity findings and translate them into appropriate RMF documentation.
  • Experience coordinating with ISSOs, ISSMs, system owners, engineers, administrators, and Government cybersecurity personnel.
  • Strong analytical, organizational, documentation, and communication skills.
Preferred Qualifications:
  • CISSP, CAP/CGRC, SecurityX/CASP+, Security+, or other certification appropriate to the assigned DCWF work role.
  • Extensive experience with eMASS and DoD RMF authorization packages.
  • Experience supporting USMC or Department of the Navy RMF processes.
  • Experience with NIST SP 800-53 security controls.
  • Familiarity with ACAS/Tenable vulnerability results and DISA STIG compliance.
  • Experience supporting cloud or hybrid environments, including Microsoft Azure.
  • Experience with Microsoft 365 security/compliance environments.
Previous USMC, Navy, DISA, or other DoD RMF/ATO experience

Compensation

A3T is committed to offering competitive compensation based on individual qualifications and business needs. The salary range posted for this position represents a reasonable estimate of the expected pay range; however, actual compensation may vary depending on factors such as geographic location, education, certifications, technical skills, relevant experience, knowledge, and overall qualifications. The posted range is intended to reflect the typical salary range for this role within A3T.

Target Salary for this Role: $100,000 - $115,000
 
Company Overview

Agil3 Technology Solutions LLC ("A3T") is a Northern Virginia based, ISO 9001, ISO 20000-1 & ISO 27001 Certified, Women-Owned (WOSB) and Service-disabled Veteran-Owned (SDVOSB) small business. A recent recipient of the prestigious Washington Technology TOP 50 (ranking #9, and on the list for last 4 years!), A3T is experiencing industry leading recognition and growth. In addition to the CEO’s recognition as an “All-Star Entrepreneur”, A3T is recognized by Inc Magazine as one of the fastest growing companies in the country, by Vet 50 as Fastest Growing Veteran-Owned Businesses, and is featured in CyberSecurity Ventures / Cybercrime Magazine! “As a go-to Women-Owned Cybersecurity company in US and internationally”. As part of our growth, we are looking for YOU to join our growing team.

A3T offers excellent benefits to enhance the work-life balance, including:

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Life Insurance
  • Short Term & Long-Term Disability
  • 401k Retirement Savings Plan with Company Match
  • Paid Holidays
  • Paid Time Off (PTO)
  • Tuition and Professional Development Assistance
  • Parking/Travel Reimbursement (metropolitan areas)

Skills

AzureCybersecurityRisk ManagementComplianceISO 27001CISSP