Evolver Federal is seeking a Senior Cybersecurity Risk Management Analyst to support its Federal client in Springfield, VA in managing a portfolio of systems participating in Ongoing Authorization/ Continuous ATO. This role will ensure compliance with established guidance/processes for Ongoing Authorization (OA) including but not limited to: developing and reviewing security documentation in support of the OA process and compiling related security packages for submission, validating control sets for testing, and conducing internal compliance reviews of assigned systems processes, as well as develop various compliance reports relating to all areas of risk and compliance. The successful candidate will have previous experience managing a Federal Government Ongoing Authorization Program or previous experience as an ISSO with assigned systems participating in Ongoing Authorization/ Continuous ATO Program. The candidate will also have experience with FISMA metrics and in reviewing and analyzing data output from scanning tools for the purposes of identifying risks and trends at the enterprise level in support of continuous monitoring and drive remediation efforts. Responsibilities: Provide security SME-level input to working groups to improve FISMA metrics and continuous monitoring processes. Advise on architectural requirements for system/network security, Active Directory, application integration, and system hierarchy. Analyze data from continuous monitoring, configuration, vulnerability, asset, and software management tool output to identify security trends and risks. Support risk mitigation through performance analysis and anomaly detection. Guide System Team stakeholders on OA processes and ensure compliance with OA Methodology. Perform document reviews for all security documentation in support of initial authorization, reauthorization, and ongoing Security Authorization packages, as well as compile and prepare authorization packages. Conduct monthly reviews and annual assessments of OA systems. Validate system control assessment test plans and ensure control testing is in alignment with OA assessment frequency requirements. Organize and lead monthly Organizational Risk Management Board (ORMB) meetings, including preparing and distributing meeting minutes. Develop, maintain, and make recommendations for enhancing Cybersecurity Policies. Develop, update, and maintain Standard Operating Procedures (SOPs) and make recommendations for new processes and/or SOPs needed to mature and improve Government Programs. Apply knowledge of NIST 800-53 security controls and recommend appropriate allocation to support OA/ Continuous ATO. Communicate clearly with system owners, developers, and executive leadership on various cybersecurity, risk and compliance topics, including providing recommendations on system and network security architecture, Active Directory integration, and application security. Coordinate, schedule, develop agendas, and facilitate meetings for large governance groups and working groups comprised of all levels of government and contractor stakeholders. Perform other duties as assigned by the Government. Ability to work efficiently and effectively in a dynamic and fast-paced environment.