Cybersecurity Assessment & Authorization (A&A) Subject Matter Ex

Marathon TS Inc
United States
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$26,000.0
Working hours
Regular working hours

Tech stack

Cloud Computing Cloud Computing Security Cyber Security Information Systems Identity and Access Management Information Security Management Software Vulnerability Management SARS Software Products Cloud Platform System Information Technology Operational Systems 3-tier Architectures

Job description

We are seeking an experienced Cybersecurity Assessment & Authorization (A&A) Subject Matter Expert (SME) to support a federal government cybersecurity program. This role is responsible for leading Assessment and Authorization (A&A) activities in accordance with the Department of Defense (DoD) Risk Management Framework (RMF), ensuring information systems meet cybersecurity compliance requirements and maintain Authorization to Operate (ATO) status. The ideal candidate possesses extensive experience applying the NIST Risk Management Framework (RMF) and NIST SP 800-53 security controls within large, complex enterprise environments. This individual will work closely with government stakeholders, system owners, engineers, cybersecurity teams, and Authorizing Officials to assess risk, validate security controls, and support the authorization lifecycle for enterprise information systems. This is a fully remote position supporting a federal government customer. Candidates must be U.S. citizens and meet the required security clearance and certification requirements., * Lead Assessment and Authorization (A&A) activities throughout the Risk Management Framework (RMF) lifecycle.

  • Support the authorization, reauthorization, and continuous monitoring of federal information systems.
  • Evaluate security controls in accordance with NIST SP 800-53 and applicable DoD cybersecurity policies.
  • Conduct comprehensive security control assessments and authorization reviews for enterprise-scale environments.
  • Analyze vulnerabilities, determine residual risk, and evaluate the potential impact to system authorization status.
  • Develop, review, and maintain RMF documentation, including:
  • System Security Plans (SSPs)
  • Security Assessment Reports (SARs)
  • Plans of Action & Milestones (POA&Ms)
  • Risk Assessment Reports
  • Authorization Packages
  • Collaborate with Information System Owners (ISOs), Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), engineers, and Authorizing Officials throughout the authorization process.
  • Provide cybersecurity guidance for cloud environments, operational technology (OT), enterprise enclaves, applications, and outsourced IT services.
  • Monitor compliance with DoD cybersecurity directives, NIST standards, and organizational security policies.
  • Support continuous monitoring activities and ongoing authorization efforts.
  • Present findings, risk assessments, and authorization status updates to senior government leadership.
  • Recommend remediation strategies to resolve security control deficiencies and reduce organizational risk.
  • Serve as a trusted cybersecurity advisor on Assessment & Authorization best practices.

Requirements

  • Minimum five (5) years of experience supporting Cybersecurity Assessment & Authorization (A&A) activities.
  • Demonstrated experience implementing the DoD Risk Management Framework (RMF).
  • Experience applying NIST SP 800-53 security controls and conducting cybersecurity assessments.
  • Experience supporting Authorization to Operate (ATO) packages for federal information systems.
  • Experience assessing security controls within large, complex enterprise environments.
  • Strong understanding of cybersecurity risk management principles and authorization processes.
  • Experience identifying security vulnerabilities and evaluating residual risk.
  • Ability to communicate technical cybersecurity concepts to both technical and executive audiences.
  • Excellent analytical, documentation, and problem-solving skills.

Preferred Qualifications

  • Experience supporting the Defense Logistics Agency (DLA) or other Department of Defense organizations.
  • Experience supporting enterprise environments consisting of:
  • Cloud-hosted services
  • Operational Technology (OT)
  • Enterprise enclaves
  • Mission applications
  • Hybrid infrastructures
  • Experience with Continuous Monitoring (ConMon) programs.
  • Familiarity with DoD Enterprise Mission Assurance Support Service (eMASS).
  • Experience preparing executive briefings and cybersecurity risk presentations.

Security Clearance Requirements

  • Active Secret Security Clearance (required)
  • Must possess a Moderate Risk, Non-Critical Sensitive (Tier 3 / NACLC / ANACI) investigation at the time of proposal submission.

Certification Requirements Candidates must possess a current DoD 8570/8140 Baseline Certification meeting:

  • Information Assurance Management (IAM) Level III

Examples include (or equivalent approved certifications):

  • CISSP
  • CISM
  • GSLC
  • CCISO

Desired Skills

  • DoD Risk Management Framework (RMF)
  • NIST SP 800-53
  • NIST Cybersecurity Framework
  • eMASS
  • Security Control Assessments
  • Authorization to Operate (ATO)
  • Continuous Monitoring (ConMon)
  • Vulnerability Management
  • Cyber Risk Analysis
  • Security Documentation
  • Enterprise Cybersecurity
  • Cloud Security
  • Operational Technology (OT) Security
  • Executive Communications

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · WWC 2024

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig · LIVE

Videos

See all

Related articles

See all