About The Position

The ATO / Risk Management Framework Lead plans and drives the path to an Authorization to Operate (ATO) and then keeps the system authorized. ACF won't let any production system, MIS, dashboard, portal, data repository, or external facing platform that processes Federal information operate until ACF confirms the authorization path, whether a full ATO, a provisional ATO, or a written ACF OCIO determination that no ATO is required. ACF expects the ATO process to take about six months, on a schedule the ACF OCIO approves no later than 30 days after award. The lead builds the authorization package, coordinates assessment and testing, resolves findings, runs continuous monitoring, and owns the privacy and security activities Task 9 requires, including incident reporting and the flow down of requirements to anyone CDIT brings onto the work. The lead works most closely with the Cloud / Solution Architect, who designs the environment the package describes.

Requirements

  • Bachelor's degree.
  • At least 7 years in federal information security, with hands on Risk Management Framework work under NIST SP 800-37 and NIST SP 800-53.
  • Has led at least one federal system through assessment to a signed ATO, including writing the System Security Plan, supporting the assessment, and managing the POA&M.
  • FedRAMP knowledge, including control inheritance from an authorized cloud environment and the customer responsibility matrix.
  • Continuous monitoring and vulnerability management with enterprise scanning tools, including reading results and driving remediation.
  • Working knowledge of FISMA, the Privacy Act, HIPAA security requirements, and federal incident reporting obligations.
  • Clear technical writing and the ability to coordinate assessors, developers, and Government reviewers to a schedule.
  • Public Trust Tier 2 clearance, held or obtainable.

Nice To Haves

  • CISSP, CGRC (formerly CAP), CISM, or an equivalent security certification.
  • Prior ATO work at HHS or an HHS operating division, and familiarity with the HHS and ACF security program and templates.
  • Experience with a governance, risk, and compliance tool used for federal authorization packages.
  • Experience producing Zero Trust scorecards against the CISA Zero Trust Maturity Model.
  • Privacy credential such as CIPP/G, or experience preparing Privacy Threshold Analyses and Privacy Impact Assessments.

Responsibilities

  • Within 30 days after award, lead the draft Privacy Threshold Analysis and Privacy Impact Assessment support package and the Data Security Plan for the COR and the ACF OCIO reviewers, describing data flows, system boundaries, user roles, encryption, access controls, audit logging, retention, destruction, incident response, subcontractor access, and privacy protections (RFQ Task 9.4).
  • Work with the COR and ACF to determine the type and sensitivity of the CUI involved and whether an ATO is required, and recommend the most efficient authorization path among the ACF Tech ATO types, including inheritance from a FedRAMP authorized environment and the ACF Authority to Use (ACF Tech Appendix D).
  • Propose the ATO schedule for ACF OCIO approval no later than 30 days after award and manage the authorization effort to it (RFQ Task 10).
  • Categorize the system under FIPS 199 and FIPS 200 and select, tailor, and document the NIST SP 800-53 control baseline for a Moderate system, applying NIST SP 800-18, NIST SP 800-171, DISA STIG hardening guidance, OMB Memorandum M-05-22, and HHS and ACF policy.
  • Author and maintain the authorization package deliverables listed below on the schedule ACF Tech approves, including the annual System Security Plan update, the annual assessment, the quarterly POA&M update, and the annual contingency plan test.
  • Coordinate the security assessment with the assessor, support testing, track every finding, and drive remediation or risk acceptance to closure.
  • Document the Zero Trust implementation approach and expected maturity level and manage the quarterly Zero Trust scorecard submissions for the system (ACF Tech Appendix B and Appendix C).
  • Run continuous monitoring under FISMA and NIST SP 800-137: monthly vulnerability scans with an ACF Tech approved tool, patch management, log review, account review, configuration management, and POA&M updates on the schedule ACF OCIO approves. Report critical and high vulnerabilities to the COR and remediate them within ACF approved timeframes (RFQ Task 10).
  • Maintain the authorization boundary and all security documentation throughout the period of performance, and submit changes through ACF change control before implementation.
  • Own incident reporting: any suspected or confirmed breach, cyber incident, unauthorized disclosure, lost device, or exposure of information that isn't public is reported immediately, within one hour at most, through CDIT and Guidehouse to the Contracting Officer, the COR, and the ACF Incident Response Team, with logs and evidence preserved and full cooperation with ACF and HHS response (RFQ Task 9.5 and Section 4.0).
  • Assess whether any data the program collects, stores, transmits, or analyzes is Protected Health Information and whether CDIT or any subcontractor is a HIPAA business associate, and if so support the Business Associate Agreement and the required safeguards (RFQ Task 9.6).
  • Support the Data Inventory and Data Minimization Plan before any data is collected, confirming that no Social Security numbers or other high risk identifiers are collected without written COR approval (RFQ Task 6.3).
  • Complete the electronic authentication risk assessment with the system owner and ISSO to set the identity, authentication, and federated assurance levels (RFQ Section 4.0).
  • Flow the privacy, security, records, incident reporting, and training requirements down to any subcontractor, consultant, or vendor CDIT uses, track the required training certificates, and keep the records that show compliance (RFQ Tasks 9.2 and 9.3).
  • Support the Sustainability and Transition strategy with the security documentation, data handling, and media sanitization under NIST SP 800-88 needed for a complete and secure transfer at the end of the contract (RFQ Task 8).
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service