ATO Administrator II

AMERICAN SYSTEMS
McLean, VA, United States
21 days ago

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$110,000.0
Working hours
Regular working hours

Tech stack

Information Systems System Configuration Software Vulnerability Management Information Security Management System SC Clearance Patch Management

Job description

As the ATO Administrator you will provide oversight to the execution of Risk Management Framework (RMF) processes via eMASS administration and daily cybersecurity operations while ensuring compliance with DoD directives throughout the MCU environment.

  • Author detailed security assessment reports, System Security Plans (SSPs), and Risk Assessment Reports (RARs) for multiple Authority to Operate (ATO) packages in eMASS
  • Utilize the eMASS platform to manage the authorization lifecycle
  • Upload and maintain RMF artifacts (Body of Evidence), develop SOPs, and create security-related diagrams.
  • Ensure that ATO packages are maintained and deadlines are met for package submission and or renewal.
  • Collaborate with system owners, ISSMs, and technical teams for accurate documentation and compliance.
  • May involve basic system configuration, patch management, and troubleshooting technical issues.
  • Lead training initiatives on RMF processes, security tool administration, and incident response protocols for team development.

Requirements

  • As a requirement of this position, all candidates must be a U.S. Citizen. In accordance with 8 U.S.C. 1324b(a)(2)(C) , we will not consider candidates for this position who do not meet the aforementioned conditions.
  • Must hold active DOD Interim Secret or Secret Clearance .
  • Minimum of 6 years’ experience in federal cybersecurity environments, with at least four years in managing complex DoD information systems and RMF processes.
  • Must have an IAT Level III security certification such as CISSP, CASP+ CE or CISM
  • Strong proficiency with Risk Management Framework (RMF) processes including System Security Plan (SSP) development, Control Correlation Bridge (CCB) implementation, and Continuity of Operations Planning (COOP) documentation.
  • Excellent communication, problem-solving, and organizational skills are crucial.
  • Proven leadership capabilities with experience managing technical teams or projects
  • Comprehensive knowledge of NIST 800-53 security control families, ACAS, DoD STIGs implementation, continuous monitoring, and federal compliance frameworks including FedRAMP, FISMA, and DoD Instruction DoDI 8500.01 and 01 requirements .
  • Demonstrated experience with assessment tools like vulnerability management systems, eMASS (Enterprise Mission Assurance Support Service), and automated compliance reporting platforms used in DoD Risk Management Framework implementations.

Benefits & conditions

AMERICAN SYSTEMS is committed to pay transparency for our applicants and employee-owners. The salary range for this position is USD $110,000.00/Yr. - USD $140,000/Yr. Actual compensation will be determined based on several factors permitted by law. AMERICAN SYSTEMS provides for the welfare of its employees and their dependents through a comprehensive benefits program by offering healthcare benefits, paid leave, retirement plans, insurance programs, and education and training assistance.

About the company

Epsilon, Inc. has joined AMERICAN SYSTEMS! As one organization, we offer expanded resources, streamlined operations, and increased opportunities for growth and development.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

2:01 min

The necessity of developer intelligence amidst automated attack generation

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC 2024

5:51 min

Transitioning to continuous security operations and automated system hardening

Thomas Fuchs +3 · LIVE

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · WWC 2025

1:48 min

Use cases for managing micro frontend dependency versions

Lucas Braeschke Lucas Braeschke +1 · WWC 2025

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

Videos

See all

Related articles

See all