> Markdown version of [/jobs/ext/1772202-ato-administrator-ii](https://www.wearedevelopers.com/jobs/ext/1772202-ato-administrator-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ATO Administrator II - **Company:** AMERICAN SYSTEMS - **Location:** McLean, VA, United States - **Experience:** Experienced - **Salary:** $110,000.0 - **Contract:** Contract - **Skills:** Information Systems, System Configuration, Software Vulnerability Management, Information Security Management System, SC Clearance, Patch Management - **Published:** July 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9049111/ato-administrator-ii ## About the Role * As a requirement of this position, all candidates must be a U.S. Citizen. In accordance with 8 U.S.C. 1324b(a)(2)(C) , we will not consider candidates for this position who do not meet the aforementioned conditions. * Must hold active DOD Interim Secret or Secret Clearance . * Minimum of 6 years' experience in federal cybersecurity environments, with at least four years in managing complex DoD information systems and RMF processes. * Must have an IAT Level III security certification such as CISSP, CASP+ CE or CISM * Strong proficiency with Risk Management Framework (RMF) processes including System Security Plan (SSP) development, Control Correlation Bridge (CCB) implementation, and Continuity of Operations Planning (COOP) documentation. * Excellent communication, problem-solving, and organizational skills are crucial. * Proven leadership capabilities with experience managing technical teams or projects * Comprehensive knowledge of NIST 800-53 security control families, ACAS, DoD STIGs implementation, continuous monitoring, and federal compliance frameworks including FedRAMP, FISMA, and DoD Instruction DoDI 8500.01 and 01 requirements . * Demonstrated experience with assessment tools like vulnerability management systems, eMASS (Enterprise Mission Assurance Support Service), and automated compliance reporting platforms used in DoD Risk Management Framework implementations. ## Description As the ATO Administrator you will provide oversight to the execution of Risk Management Framework (RMF) processes via eMASS administration and daily cybersecurity operations while ensuring compliance with DoD directives throughout the MCU environment. * Author detailed security assessment reports, System Security Plans (SSPs), and Risk Assessment Reports (RARs) for multiple Authority to Operate (ATO) packages in eMASS * Utilize the eMASS platform to manage the authorization lifecycle * Upload and maintain RMF artifacts (Body of Evidence), develop SOPs, and create security-related diagrams. * Ensure that ATO packages are maintained and deadlines are met for package submission and or renewal. * Collaborate with system owners, ISSMs, and technical teams for accurate documentation and compliance. * May involve basic system configuration, patch management, and troubleshooting technical issues. * Lead training initiatives on RMF processes, security tool administration, and incident response protocols for team development. ## Related Videos - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Kubernetes dev is fun, but setup and ops isn't! See a fun PaaS alternative to push any code, ipynbs or even just data!](https://www.wearedevelopers.com/videos/732-kubernetes-dev-is-fun-but-setup-and-ops-isn-t-see-a-fun-paas-alternative-to-push-any-code-ipynbs-or-even-just-data) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)