About the roleConcept Plus is seeking a Security Compliance (ATO) Specialist to ensure the client OCI/ExaCC and Cloudflare solutions meet FedRAMP High, NIST 800-53 r5, and HIPAA requirements, and supports continuous Authorization to Operate (cATO) processes across the program.
What you'll do- Map solution designs and configurations to FedRAMP High and NIST 800-53 r5 controls.
- Support continuous ATO activities: control assessment, POA&M management, and evidence collection.
- Advise architecture and engineering teams on compliant-by-design patterns and guardrails.
- Review IaC and cloud configurations for security control coverage.
- Support HIPAA and client security requirements and Section 508 compliance of deliverables.
Required Qualifications- US Citizen
- Deep knowledge of FedRAMP High and NIST 800-53 r5.
- Experience with ATO / continuous ATO processes in federal environments.
- Cloud security assessment experience (OCI, AWS, or Azure).
- Familiarity with HIPAA and healthcare data protection.
- Ability to translate controls into actionable engineering guidance.
- 7+ years information security/compliance with 3+ years supporting federal ATO.
- Must satisfy client security requirements and obtain/maintain applicable client background investigation and clearance.
Preferred Qualifications- Prior CMS ATO experience.
- Experience with GRC tooling and cloud-native security services (Cloud Guard).
- CISSP, CCSP, or CAP certification.