Lead and/or support the development of RMF and A&A documentation including SSPs, control implementation matrices, SARs, POA&Ms, and risk acceptance materials. Support authorization of on premise and cloud services leveraging FedRAMP packages, considering agency specific control requirements, and support 3PAO readiness assessments and SAR development for cloud platforms. Interpret and operationalize FISMA, NIST RMF, FedRAMP, and OSCAL standards to guide application enhancements, evidence automation, and RMF workflow modernization across a GRC platform. Ensuring consistency and compliance across multi‑tenant GRC environments, helping Components and customer agencies implement security controls, maintain accurate documentation, and sustain reliable continuous monitoring. Collaborating across Agile teams to embed RMF discipline, support backlog refinement, and validate that modernization activities remain compliant with Federal requirements. Coordinate A&A activities and requirements with System Owners, ISSOs, IAMs, and third-party assessors, reducing manual burden for ISSOs and system owners by shaping automated workflows, improving evidence pathways, and strengthening data integrity used for scoring, dashboards, and compliance reporting. Providing compliance and RMF subject matter guidance throughout sprint cycles, planning, testing activities, and release readiness processes, ensuring enhancements align with RMF control requirements and governance expectations. Supporting continuous authorization (cATO) goals through integration of automated control validation, vulnerability data ingestion, security tooling alignment, and machine‑readable artifacts (OSCAL).
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior