RMF and Authorization Lead

A-TEK Inc.

$165K — $185K *
Education, Government & Non-Profit
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years leading Federal RMF and A&A activities
  • Solid grasp of NIST standards and FISMA
  • Extensive experience with Federal authorization packages
  • Skill in stakeholder coordination and technical writing
  • Familiarity with security assessments and POA&M management
  • Hybrid work capability in designated locations

Responsibilities

  • Lead RMF activities for multiple authorization boundaries
  • Maintain essential cybersecurity documentation like SSPs and SARs
  • Coordinate annual security control assessments and manage evidence
  • Ensure assessor independence while managing security documentation
  • Direct inventory management and data quality processes in GRC platform
  • Oversee risk reporting, POA&M management, and remediation tracking
  • Support FedRAMP documentation and security impact analysis

Benefits

  • Health, dental, and vision insurance
  • 401(k) with employer match
  • Paid time off
  • Professional development opportunities
Full Job Description
A-TEK is seeking an experienced RMF/A&A Lead to support our federal customer. The RMF/A&A Lead serves as the senior technical authority for RMF and A&A activities supporting an HHS-affiliated agency. This individual leads authorization readiness, authorization package development and maintenance, Governance, Risk, and Compliance activities, cybersecurity documentation, risk management, and system lifecycle support. The Lead coordinates with system owners, ISSOs, administrators, privacy officials, assessors, and agency cybersecurity personnel to maintain complete, current, and audit ready authorization packages. The ability to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle, NC area is required. Responsibilities • Lead RMF activities across three primary authorization boundaries and the associated system inventory. • Maintain SSPs, SARs, POA&Ms, Executive Summaries, ATO documentation, and supporting evidence. • Coordinate three annual security control assessments and prepare evidence for the independent assessor. • Maintain assessor independence and avoid acting as the assessor of record unless the agency expressly authorizes an activity. • Direct system registration, inventory reconciliation, artifact maintenance, data quality review, and status validation in the agency's designated GRC platform. • Lead POA&M management, residual risk analysis, risk reporting, and remediation tracking. • Support cloud and FedRAMP documentation, control inheritance analysis, and shared responsibility analysis. • Review major changes, prepare security impact analyses, and support onboarding and decommissioning. • Conduct technical and quality reviews before submitting cybersecurity artifacts. • Identify and escalate risks that could affect an authorization, assessment, or deliverable schedule. • Support transition activities and reconcile authorization boundaries, inventories, artifacts, and active work. Required Experience and Qualifications • Demonstrated experience leading Federal RMF and A&A activities of comparable scope and complexity. • Knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA, and Federal continuous monitoring requirements. • Experience developing and maintaining Federal authorization packages. • Experience supporting independent security assessments, POA&M management, and risk-based decisions. • Strong technical writing, stakeholder coordination, and quality review skills. • Ability to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle area. • Education and experience that satisfy the proposed GSA labor category. Preferred Experience and Qualifications • Experience supporting HHS or another Federal health agency. • Experience using JCAM or a comparable Federal GRC platform. • Experience supporting cloud security, FedRAMP, inherited controls, and shared responsibility analysis. • Experience coordinating multiple concurrent authorization, assessment, and continuous monitoring activities. • CISSP, CAP/CGRC, CISM, Security+, or an applicable cloud security certification. Compensation Salary Range: $165,000 - $185,000 annually (commensurate with experience) Benefits: Health, dental, and vision insurance; 401(k) with employer match; paid time off; professional development opportunities. Why Join Us? This is an opportunity to make a direct impact on healthcare data processes that support critical regulatory functions. You will collaborate with dedicated professionals, work on meaningful projects, and contribute to improvements in public health systems. Candidates may use tools (including AI) for proofreading or formatting; however, using any tool to fabricate, exaggerate, or misrepresent qualifications, experience, or work product is not permitted. We may assess application materials for job-related technical depth, internal consistency, and demonstrated hands-on experience, including through follow-up questions, skills assessments, or reference checks. Verification of education may be requested before or during the hiring process. For security and identity verification purposes, participants may be asked to temporarily disable virtual backgrounds during portions of the call. Misrepresentation or falsification may result in removal from further consideration. Candidates who need a reasonable accommodation in the application or interview process may request one.

Similar Jobs

More Jobs at A-TEK Inc.

More Education, Government & Non-Profit Jobs

Find similar RMF and Authorization Lead jobs: