Security Assessment & Authorization (SA&A) Analyst (Job 1458)

DLHBethesda, MD
$115,000 - $126,000

About The Position

DLH is seeking a Security Assessment & Authorization Analyst to join their team. This role is responsible for developing and maintaining Authority to Operate (ATO) security packages and authorization documentation, and working across the Risk Management Framework (RMF) lifecycle for assigned systems. The analyst will collaborate with customers to understand technologies, develop security documentation, assess vulnerabilities, document and implement security controls, manage Plans of Action & Milestones (POA&Ms), and facilitate the authorization process for solutions. The ideal candidate will have experience developing ATO packages, performing multiple steps within the RMF framework, and enjoy solving cybersecurity and compliance challenges with diverse teams.

Requirements

  • Minimum of five (5) years of experience in developing and maintaining ATO security packages and helping customers with the RMF and ATO lifecycle
  • Experience developing clear, concise documentation describing system configuration, operations, and security controls
  • Prior experience working with security tools such as Tenable, Splunk, and GRC JCAM
  • Working knowledge of Federal security guidelines, standards, and control frameworks (such as NIST SP 800-53)
  • Bachelor’s degree in information technology, Cybersecurity, or a related field
  • Relevant certifications (e.g., CGRC (CAP), CISA, CompTIA Security+, CISSP) required.
  • Strong knowledge of security standards and best practices.
  • Excellent problem-solving, analytical skills.
  • Strong cross-team collaboration and coordination across diverse audiences and stakeholders
  • Must be able to obtain a Public Trust clearance

Nice To Haves

  • Prior experience with Cloud Security (AWS, Azure, GCP) within a large government environment (FedRAMP certified) preferred

Responsibilities

  • Support the development and maintenance of ATO security packages and authorization documentation
  • Assess security controls to ensure compliance with NIST 800-53 requirements
  • Prior experience with the RMF lifecycle and supporting customers in obtaining Authority to Operate security packages
  • Develop, manage, and update Plans of Action & Milestones (POA&Ms)
  • Analyze STIG and SCAP requirements to ensure document compliance
  • Track vulnerabilities through remediation, mitigation, and/or risk acceptance
  • Evaluate environmental and configuration changes to determine impacts to the security posture of assigned systems
  • Recommend mitigating controls and countermeasures

Benefits

  • Personal Time Off (PTO)
  • medical
  • dental
  • vision
  • supplemental life with AD&D
  • disability coverage
  • flexible spending accounts
  • 401(k) Retirement Plan
  • matching component
  • training
  • e-learning suite
  • professional and technical certification preparation
  • education assistance at accredited institutions
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service