Lead Ato Sme

ExcentiumWashington D.C., DC
1dHybrid

About The Position

We have an opportunity for a LEAD ATO SME (Cybersecurity Engineer III) supporting one of our Federal customers in Washington D.C. MINIMUM CLEARANCE LEVEL: TOP SECRET (Active) + Suitability CITIZENSHIP: US Citizenship LOCATION: HYBRID — On-site at BOP Central Office (Washington, DC) for classified work; Remote for unclassified. Employment Type: Full-Time Position Description: Serve as primary interface with BOP CISO and senior government leadership Lead and manage all ATO/Re-ATO activities across 50+ BOP information systems Oversee Security Control Assessment (SCA) scheduling, execution, and reporting Direct ISSO team activities and ensure consistent application of RMF methodology Brief Authorizing Officials on system risk posture and authorization recommendations Manage continuous monitoring program and ensure zero lapsed authorizations Coordinate with system owners, developers, and operations teams on security requirements Review and approve all authorization packages (SSPs, SARs, POA&Ms) before submission Education: Bachelor's degree in IT, Cybersecurity, Computer Science, or related field Qualifications: Minimum 10 years in federal cybersecurity, RMF, or information assurance Expert knowledge of NIST Risk Management Framework (RMF) and all seven lifecycle steps Deep understanding of NIST SP 800-37, 800-53 Rev 5, 800-53A, and FIPS 199/200 Experience with DOJ security policies and procedures (preferred) Proficiency with GRC tools (eMASS, JCAM, or similar) Experience managing enterprise-scale authorization programs (50+ systems) Strong written and verbal communication skills for executive briefings Ability to translate technical risks into business impact for leadership decisions Experience operating in classified environments and handling classified information Excellent documentation and communication skills Certification Requirement: Two (2) of the following: CISSP, CAP, CISM, CISA, Security+, or equivalent About Excentium Excentium is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing cybersecurity and IT services to federal agencies. We hold FedRAMP 3PAO accreditation, CMMC Level 2 certification, and maintain facility clearances supporting our mission-critical work across government. We take pride in building a workforce with strong Veterans focus. Excentium offers a competitive salary and comprehensive benefits package, including medical, dental, life, disability, 401k, and paid time off. Excentium , Inc. is an equal opportunity employer.

Requirements

  • MINIMUM CLEARANCE LEVEL: TOP SECRET (Active) + Suitability
  • CITIZENSHIP: US Citizenship
  • Minimum 10 years in federal cybersecurity, RMF, or information assurance
  • Expert knowledge of NIST Risk Management Framework (RMF) and all seven lifecycle steps
  • Deep understanding of NIST SP 800-37, 800-53 Rev 5, 800-53A, and FIPS 199/200
  • Proficiency with GRC tools (eMASS, JCAM, or similar)
  • Experience managing enterprise-scale authorization programs (50+ systems)
  • Strong written and verbal communication skills for executive briefings
  • Ability to translate technical risks into business impact for leadership decisions
  • Experience operating in classified environments and handling classified information
  • Excellent documentation and communication skills
  • Two (2) of the following: CISSP, CAP, CISM, CISA, Security+, or equivalent

Nice To Haves

  • Experience with DOJ security policies and procedures (preferred)

Responsibilities

  • Serve as primary interface with BOP CISO and senior government leadership
  • Lead and manage all ATO/Re-ATO activities across 50+ BOP information systems
  • Oversee Security Control Assessment (SCA) scheduling, execution, and reporting
  • Direct ISSO team activities and ensure consistent application of RMF methodology
  • Brief Authorizing Officials on system risk posture and authorization recommendations
  • Manage continuous monitoring program and ensure zero lapsed authorizations
  • Coordinate with system owners, developers, and operations teams on security requirements
  • Review and approve all authorization packages (SSPs, SARs, POA&Ms) before submission

Benefits

  • medical
  • dental
  • life
  • disability
  • 401k
  • paid time off
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service