> Markdown version of [/jobs/ext/170090-lead-ato-sme-federal-cybersecurity-program](https://www.wearedevelopers.com/jobs/ext/170090-lead-ato-sme-federal-cybersecurity-program). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead ATO SME - Federal Cybersecurity Program - **Company:** MDC Corporation - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $80,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Agile Methodology, Federal Information Processing Standards (FIPS), Enterprise Software Applications, Devsecops - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5070a7f77bed8dbf ## About the Role Do you have experience in Waterfall?, Do you have a Bachelor's degree?, · 10+ years IT project management experience in Waterfall and Agile environments. · 10+ years performing A&A/ATO, system security assessments, security documentation, or security upgrades for enterprise systems. · Strong working knowledge of NIST SP 800-37, NIST SP 800-53, FIPS 199/200, FISMA, and federal ATO processes. · Bachelor degree and at least two of: CISSP, CAP/CGRC, CISA, CRISC, CISM, or CGEIT. Preferred Qualifications · JCAM, CSAM, eMASS, Xacta, or comparable federal A&A tool experience. · Experience supporting classified systems or federal law enforcement/public safety environments., * How many years of hands-on A&A/ATO/RMF experience do you have, and which federal A&A tools have you used? * Do you hold at least two of the following certifications: CISSP, CAP/CGRC, CISA, CRISC, CISM, or CGEIT? Please list them. Security clearance: * Top Secret (Required) Work Location: Hybrid remote in Washington, DC 20534 ## Description We are seeking a dynamic and experienced Lead ATO SME to spearhead the Federal Cybersecurity Program's Authority to Operate (ATO) processes. You will ead a federal authorization factory supporting rapid ATO, continuous monitoring, and executive-level cyber risk reporting. This role directs RMF execution, coordinates with system owners and authorizing stakeholders, and ensures authorization packages are accurate, complete, and audit-ready. Key Responsibilities · Lead RMF/ATO activities across Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor phases. · Guide development and quality review of SSPP/SSP, SAR, POA&M, RTM, risk analysis, and authorization packages. · Coordinate with ISSO, SCA, cloud, DevSecOps, PMO, and SOC teams to maintain system authorization posture. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [ShapeShift: Reinventing Agile for a B2B SaaS Scale-Up](https://www.wearedevelopers.com/videos/1655-shapeshift-reinventing-agile-for-a-b2b-saas-scale-up) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 212: WebMCP or MCP, What is DevRel, AI's 10% Productivity Boost, and a 49MB Web Page…](https://www.wearedevelopers.com/magazine/717-dev-digest-212-webmcp-or-mcp-what-is-devrel-ai-s-10-productivity-boost-and-a-49mb-web-page)