Location: Rockville, MD (Primarily Onsite)
Position Summary:
Support federal Assessment & Authorization (A&A), Authorization to Operate (ATO), and continuous monitoring activities by independently assessing security controls, reviewing authorization documentation, identifying risks, and validating remediation.
Key Responsibilities:
• Conduct security control assessments in accordance with the NIST Risk Management Framework.
• Support A&A/ATO activities, including initial authorizations, renewals, significant-change assessments, and continuous monitoring.
• Develop and execute Security Assessment Plans and prepare Security Assessment Reports.
• Review SSPs, SAPs, SARs, POA&Ms, risk assessments, contingency plans, vulnerability scans, and supporting evidence.
• Document findings, assess risk, validate corrective actions, and support closure of security deficiencies.
• Coordinate with system owners, engineers, ISSOs, cybersecurity teams, and government stakeholders.
Required Qualifications:
• Bachelor's degree in cybersecurity, IT, computer science, engineering, or related field.
• 5+ years of cybersecurity/information security experience.
• 3+ years of direct federal A&A, ATO, or NIST RMF experience.
• Hands-on Security Control Assessor experience.
• Strong knowledge of NIST SP 800-37, 800-53, 800-53A, and 800-30.
• Experience reviewing federal security authorization packages and technical security evidence.
• Strong written and verbal communication skills.
Required Certification:
• Active CISSP or CISM.
Preferred:
• NIH/HHS or other federal civilian agency experience.
• Experience with GRC platforms, FedRAMP/cloud environments, and tools such as Tenable, Nessus, Qualys, or Splunk