In this position as a Senior RMF & ATO Lead, you will provide leadership and oversight for the execution of the NIST Risk Management Framework (RMF) and Authority to Operate (ATO) processes across federal information systems. You will guide system teams through all RMF lifecycle phases while ensuring compliance with DOJ security policies, NIST standards, and federal cybersecurity requirements. In this position, you will also: Lead execution of the NIST RMF lifecycle in accordance with NIST SP 800-37, including Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor phases. Oversee the development, quality review, and approval readiness of authorization package artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and risk assessment documentation. Guide system owners and technical teams through Rapid ATO timelines while maintaining full compliance with DOJ policies and NIST SP 800-53 control requirements. Lead security control selection, tailoring, and allocation based on system categorization, architecture, and operational environment. Validate security control implementations and ensure documentation is supported by verifiable technical evidence across cloud and on-premise environments. Direct the development of Security Assessment Plans (SAPs) and review assessment results to support authorization decisions. Lead risk analysis, determination, and response activities, including advising leadership on risk acceptance, mitigation, or remediation strategies. Oversee POA&M development and ensure remediation activities are tracked to closure in accordance with federal timelines. Provide oversight of Continuous Monitoring (ConMon) strategies, ensuring ongoing authorization requirements are met and accurately reported. Ensure authorization packages are updated to reflect system changes, assessment results, and evolving risk conditions. Ensure all RMF and supporting documentation is complete, accurate, and entered into JCAM. Lead development and review of supporting cybersecurity artifacts, including Incident Response Plans, Contingency Plans, Configuration Management Plans, Interconnection Security Agreements (ISAs), Memorandums of Understanding (MOUs), and privacy documentation (IPA/PIA), as applicable. Serve as the primary cybersecurity liaison to system owners, ISSOs, engineers, assessors, and Authorizing Official (AO) representatives. Provide technical leadership, mentorship, and guidance to ATO analysts, security engineers, and architects. Support issue resolution efforts and facilitate risk-based decision making with senior leadership and stakeholders.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level