Security Assessment & Authorization (SA&A) Lead

General Dynamics Information TechnologyRockville, MD
$142,792 - $184,000Onsite

About The Position

Advance your career while impacting security of our hosting environment as a Security Assessment & Authorization (SA&A) Lead at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government. MEANINGFUL WORK AND PERSONAL IMPACT As the Security Assessment & Authorization (SA&A) Lead, the work you’ll do at GDIT will be impactful to the mission of the customer. The SA&A Lead is responsible for leading NCI’s enterprise Assessment & Authorization (A&A) program, ensuring that all information systems comply with NIST RMF, FISMA, HHS, and NIH cybersecurity requirements. This senior SME provides technical leadership for system assessments, continuous monitoring, documentation quality, remediation support, and authorization readiness. This role aligns with A&A leadership positions seen in major federal cybersecurity practices. Bring your program management expertise along with a drive for innovation to GDIT.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field similar in size
  • 5+ years leading FISMA-based A&A programs plus experience with eGRC tools (e.g., JCAM, Archer, CSAM)
  • Possess one or more active certifications, for example, CISSP, CISA, CISM, CRISC
  • ITIL Foundations certification (or ability to obtain within 3 months).
  • The ability to obtain a Public Trust
  • Deep understanding of NIST SP 800 37, 800 53, 800 30, 800 171, FedRAMP, and HHS/NIH-specific policies
  • Strong experience managing assessment teams and reviewing security documentation
  • Experience supporting assessment programs for NIH, HHS, or similar scientific/health agencies.
  • Experience advising on control inheritance models, enclave ATOs, and enterprise automation.
  • Experience supporting cloud A&A, including AWS, GCP, and SaaS providers.
  • Expert knowledge of NIST RMF and security control assessment
  • Attention to detail and documentation excellence
  • Analytical thinking and risk-based decision support
  • Ability to translate technical risks into actionable remediation plans
  • Strong stakeholder coordination and communication skills

Responsibilities

  • Lead execution of RMF phases for all assigned systems, including categorization, control selection/tailoring, assessment, authorization, and continuous monitoring.
  • Manage teams responsible for developing and reviewing SSPs, SARs, SAPs, POA&Ms, PTAs, PIAs, eAuth documentation, contingency plans, and related artifacts.
  • Conduct assessment readiness reviews and ensure authorization packages meet quality standards.
  • Provide expert guidance to system owners, ISSOs, engineers, and federal leadership regarding RMF expectations and authorization strategies.
  • Coordinate IV&V of third party assessments and review contractor-provided documentation for completeness.
  • Support enterprise-wide initiatives such as boundary optimization, control inheritance, RMF automation, and FedRAMP leveraging activities.
  • Drive process improvements to reduce authorization timelines, improve documentation quality, and enhance cross-team coordination.
  • Support annual control assessments, continuous monitoring activities, and remediation validation.

Benefits

  • Full benefits
  • wellness programs
  • 401K matching
  • competitive salary
  • paid time off
  • variety of medical plan options
  • dental plan options
  • a vision plan
  • 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match.
  • full flex work weeks where possible
  • a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave.
  • short and long-term disability benefits
  • life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service