Lead ATO SME - Federal Cybersecurity Program

MDC Corporation
Washington, DC, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$80,000.0
Working hours
Regular working hours
Job source

Tech stack

Xacta Agile Methodology Federal Information Processing Standards (FIPS) Enterprise Software Applications Devsecops

Job description

We are seeking a dynamic and experienced Lead ATO SME to spearhead the Federal Cybersecurity Program’s Authority to Operate (ATO) processes.

You will ead a federal authorization factory supporting rapid ATO, continuous monitoring, and executive-level cyber risk reporting. This role directs RMF execution, coordinates with system owners and authorizing stakeholders, and ensures authorization packages are accurate, complete, and audit-ready.

Key Responsibilities

Ā· Lead RMF/ATO activities across Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor phases.

Ā· Guide development and quality review of SSPP/SSP, SAR, POA&M, RTM, risk analysis, and authorization packages.

Ā· Coordinate with ISSO, SCA, cloud, DevSecOps, PMO, and SOC teams to maintain system authorization posture.

Requirements

Do you have experience in Waterfall?, Do you have a Bachelor’s degree?, Ā· 10+ years IT project management experience in Waterfall and Agile environments.

Ā· 10+ years performing A&A/ATO, system security assessments, security documentation, or security upgrades for enterprise systems.

Ā· Strong working knowledge of NIST SP 800-37, NIST SP 800-53, FIPS 199/200, FISMA, and federal ATO processes.

Ā· Bachelor degree and at least two of: CISSP, CAP/CGRC, CISA, CRISC, CISM, or CGEIT.

Preferred Qualifications

Ā· JCAM, CSAM, eMASS, Xacta, or comparable federal A&A tool experience.

Ā· Experience supporting classified systems or federal law enforcement/public safety environments., * How many years of hands-on A&A/ATO/RMF experience do you have, and which federal A&A tools have you used?

  • Do you hold at least two of the following certifications: CISSP, CAP/CGRC, CISA, CRISC, CISM, or CGEIT? Please list them.

Security clearance:

  • Top Secret (Required)

Work Location: Hybrid remote in Washington, DC 20534

Benefits & conditions

Pulled from the full job description

  • Professional development assistance
  • Tuition reimbursement
  • Parental leave
  • 401(k)
  • Health insurance
  • Retirement plan
  • 401(k) matching, * 401(k)
  • 401(k) matching
  • Dental insurance
  • Employee assistance program
  • Flexible schedule
  • Health insurance
  • Life insurance
  • Paid time off
  • Parental leave
  • Professional development assistance
  • Retirement plan
  • Tuition reimbursement
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:58 min

Applying agile software methodologies to corporate operational challenges

Kyle Daigle Ā· Coffee With Developers

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig Ā· LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil Ā· LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady Ā· WWC Europe 2026

7:52 min

Q&A on agile implementation and challenging norms

Ivan Milanov Ivan Milanov Ā· Europe 2026 Virtual

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia Ā· LIVE

Videos

See all

Related articles

See all