> Markdown version of [/jobs/ext/1820874-authorization-accreditation-a-a-program-lead](https://www.wearedevelopers.com/jobs/ext/1820874-authorization-accreditation-a-a-program-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Authorization & Accreditation (A&A) Program Lead... - **Company:** ICF Incorporated, L.L.C. - **Location:** Alexandria, VA, United States - **Experience:** Expert - **Salary:** $130,687.0 - $222,169.0 - **Contract:** Permanent contract - **Skills:** Information Systems, Information Security Management, Software Vulnerability Management, SARS Software Products, Cloud Platform System - **Published:** July 23, 2026 - **Apply:** https://www.juju.com/job/00000000gkqjep ## About the Role + Bachelor's degree in a technical discipline (or related field). + Minimum 10 years of progressively responsible experience in cybersecurity risk management or RMF execution roles supporting DoD or Federal environments. + Experience in RMF policy, processes, and documentation development is required. + Must have experience leading A&A or ISSM/ISSO teams through system authorization or reauthorization cycles. + Active US Government issued Security Clearance. + Due to contract requirements, US Citizenship is required. + A current certification in at least one of the following areas in required: + CISM + CISSP, + Master's degree in cybersecurity, information systems, or a related technical field. + ITIL v4 or equivalent process management certification. + Experience supporting DHRA or DoD Component RMF implementations and governance processes. + Strong familiarity with eMASS, ACAS, STIG Viewer, and other DoD assessment tools. + Demonstrated ability to lead security authorization efforts across hybrid and cloud environments. + Excellent communication and stakeholder engagement skills; proven ability to interface with AOs, SCA personnel, and senior leadership. ## Description ICF is seeking an experienced Authorization & Accreditation (A&A) Program Lead to support a Defense Human Resources Activity (DHRA) cybersecurity program. In this role, you will manage and execute Risk Management Framework (RMF) activities across multiple DHRA information systems, ensuring compliance with DoD and NIST cybersecurity standards. The A&A Program Lead provides expert guidance on RMF policy and process implementation, oversees the quality of authorization packages, and serves as the primary RMF point of contact for DHRA system owners and stakeholders. Work will be performed on-site in Monterey, CA or Alexandria, VA. What You'll Do + Oversee and manage the RMF lifecycle for DHRA information systems in accordance with NIST SP 800-37, SP 800-53, CNSSI 1253, and DoDI 8510.01. + Serve as the primary point of contact for all A&A and RMF activities within the Cyber PRIMES program. + Lead, mentor, and coordinate the work of RMF analysts, assessors, and documentation specialists. + Develop and maintain key RMF artifacts including Security Assessment Plans (SAPs), System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms). + Ensure consistent, compliant implementation of RMF controls and processes across multiple DHRA systems and environments. + Review and validate control implementations, risk assessments, and authorization documentation for accuracy and completeness. + Interface with Authorizing Officials (AOs), Information System Security Managers (ISSMs), and Information System Security Officers (ISSOs) to coordinate authorization packages and schedules. + Support continuous monitoring activities, vulnerability management, and risk mitigation planning. + Track ATO timelines, renewal cycles, and compliance posture across the DHRA enterprise. + Advise program and technical leadership on RMF requirements, control inheritance, and security posture impacts of system changes. + Contribute to governance boards and working groups focused on cybersecurity policy, reporting, and tool optimization. ## Related Videos - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) - [Cloud Vendor Lock-In - Is it just a new version of the Database Abstraction Layers?](https://www.wearedevelopers.com/videos/1185-cloud-vendor-lock-in-is-it-just-a-new-version-of-the-database-abstraction-layers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Hosting a modern justice system](https://www.wearedevelopers.com/videos/332-hosting-a-modern-justice-system) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters)