- Source
- ApplicantStack
Description
SUMMARY:
We are seeking an experienced Assessment and Authorization (A&A) Lead to oversee cybersecurity assessment, authorization, and continuous monitoring activities for federal information systems. The successful candidate will possess strong knowledge of the NIST Risk Management Framework (RMF), federal security requirements, and the complete Authorization to Operate (ATO) lifecycle.
This position will lead and manage a team of approximately five to eight Security Control Assessors, Information System Security Officers (ISSOs), and other cybersecurity professionals. The A&A Lead will be responsible for ensuring that security authorization packages are accurate, complete, compliant, and delivered according to established schedules.
Key ResponsibilitiesRequired Qualifications
- Lead the end-to-end A&A and ATO process for federal information systems.
- Manage and mentor a team of five to eight Security Control Assessors and ISSOs.
- Develop and maintain integrated ATO schedules, milestones, priorities, and resource assignments.
- Coordinate security authorization activities with system owners, technical teams, ISSOs, assessors, authorizing officials, and other stakeholders.
- Apply the NIST Risk Management Framework throughout the system development and authorization lifecycle.
- Review and validate security authorization documentation, including:
- System Security Plans
- Security Assessment Plans
- Security Assessment Reports
- Plans of Action and Milestones
- Risk assessments
- Contingency plans
- Continuous monitoring plans
- Security control implementation evidence
- Oversee security control assessments and ensure findings are clearly documented, supported by evidence, and assigned appropriate risk ratings.
- Evaluate system vulnerabilities, control deficiencies, and residual risks to support authorization decisions.
- Monitor remediation activities and ensure POA&M items are properly documented, tracked, updated, and closed.
- Conduct quality assurance reviews of A&A packages before submission to the Authorizing Official.
- Identify risks, schedule delays, documentation gaps, and resource constraints and communicate them to program leadership.
- Establish standardized A&A procedures, templates, checklists, and quality-control processes.
- Facilitate status meetings, risk-review sessions, and authorization-readiness reviews.
- Support continuous monitoring, annual assessments, significant-change reviews, and authorization renewals.
- Prepare executive-level dashboards, metrics, and reports describing ATO status, risks, findings, and remediation progress.
- Provide guidance to system teams on federal cybersecurity policies, control implementation, and compliance expectations.
- Promote accountability, collaboration, and consistent performance across the A&A team.
Required Certification
- Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related discipline.
- At least eight years of cybersecurity, information assurance, or information system security experience.
- At least five years of direct experience supporting federal A&A, ATO, or NIST RMF activities.
- Demonstrated experience managing or leading teams of Security Control Assessors, ISSOs, or cybersecurity analysts.
- Strong knowledge of:
- NIST Risk Management Framework
- NIST SP 800-37
- NIST SP 800-53
- NIST SP 800-53A
- NIST SP 800-30
- FISMA requirements
- Federal continuous monitoring practices
- Experience reviewing complex security authorization packages and evaluating security control evidence.
- Strong understanding of security risk management, vulnerability management, POA&M management, and continuous monitoring.
- Ability to manage multiple systems and authorization activities simultaneously.
- Strong leadership, analytical, organizational, and problem-solving skills.
- Excellent written and verbal communication skills, including the ability to communicate technical risks to executive and nontechnical stakeholders.
- Ability to work effectively with government leadership, system owners, engineers, cybersecurity teams, and third-party assessors.
Candidates must hold at least one of the following active certifications:Preferred Qualifications
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
Leadership Expectations
- Experience supporting cybersecurity programs within NIH, HHS, or another federal civilian agency.
- Experience with federal governance, risk, and compliance platforms such as CSAM, JCAM, ServiceNow GRC, or similar tools.
- Experience managing a portfolio of systems with concurrent ATO deadlines.
- Familiarity with cloud security requirements, including FedRAMP and NIST controls for AWS, Microsoft Azure, or other cloud environments.
- Experience developing A&A standard operating procedures, playbooks, templates, and performance metrics.
- Additional certifications such as CAP/CGRC, CRISC, CCSP, PMP, or Security+.
- Experience supporting high-impact or mission-critical federal information systems.
The A&A Lead must be a hands-on leader who can establish priorities, assign responsibilities, remove obstacles, coach team members, and maintain high-quality deliverables. The individual must be comfortable engaging directly with senior government stakeholders, presenting authorization risks, and recommending practical solutions that balance mission requirements with cybersecurity compliance.
Success Measures
Success in this role will be measured through:Effective leadership, development, and retention of the A&A team.
- Timely completion of ATO packages and authorization milestones.
- Quality and completeness of security documentation.
- Reduction in overdue assessments and POA&M items.
- Accuracy of risk assessments and executive reporting.
- Improved coordination among system owners, ISSOs, assessors, and technical teams.
- Consistent application of NIST RMF requirements across the system portfolio.
Skills
AWSAzureServiceNowCybersecurityRisk ManagementCompliancePMPCISSP