> Markdown version of [/jobs/ext/183842-contingent-lead-cybersecurity-compliance-manager-ato-sme](https://www.wearedevelopers.com/jobs/ext/183842-contingent-lead-cybersecurity-compliance-manager-ato-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # [Contingent] Lead Cybersecurity Compliance Manager (ATO SME) - **Company:** phia, LLC - **Location:** Fairfax, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Cyber Security, Information Systems, Requirements Traceability, Privacy Controls, Matrix Reports, Information Technology, Tenable Nessus, E-government - **Published:** May 15, 2026 - **Apply:** https://jobs.localjobnetwork.com/job/detail/87174369/Contingent-Lead-Cybersecurity-Compliance-Manager-ATO-SME ## About the Role * Prior experience supporting federal agency ATO programs * Experience with federal authorization management platforms used in federal environments (e.g., JCAM) * Experience with classified system (Secret, Top Secret) ATO packages * Experience developing Privacy Risk Certification Memos and coordinating with Senior Component Officials for Privacy (SCOP) * Familiarity with automated asset discovery and continuous scanning tools for system boundary definition * Experience supporting both on-premises and FedRAMP cloud authorization packages Required Education + Experience Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field Experience: 10+ years of IT Project Management experience in both Waterfall and Agile environments; 10+ years performing systems security assessments, preparing A&A documentation, and achieving security authorizations for federal information systems including classified systems; 10+ years of experience with federal IT security regulations and standards Certifications: Minimum two (2) of the following: CISA (ISACA), CRISC (ISACA), CISM (ISACA), CGEIT (ISACA), CISSP (ISC), CAP/CGRC (ISC) Clearance: Active TOP SECRET clearance required GENERAL PROGRAM REQUIREMENTS Citizenship: Must be a U.S. Citizen. No exception. Work Hours: Full-time; Monday-Friday core hours 0730-1600 EST Work Location: Hybrid - Washington, DC Metro Area; on-site presence required. Classified work must be performed at a government-designated facility on government-provided equipment. Travel: Occasional travel may be required in support of this program. ## Description DISCLAIMER: This position is in support of a current government proposal. Employment is contingent upon contract award to phia, LLC., phia is seeking an experienced Lead ATO Subject Matter Expert to serve as the primary technical lead for Risk Management Framework (RMF) and Authorization to Operate (ATO) activities in support of a federal client's information technology security program. You will lead the full RMF lifecycle across multiple federal information systems, drive security authorization packages to ATO, and coordinate ISSO, SCA, and system owner teams to protect mission-critical IT infrastructure across on-premises, cloud, hybrid, and air-gapped environments. What You'll Do * Lead all phases of the NIST SP 800-37 Rev. 2 RMF lifecycle: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor, across a range of federal information system types. * Develop, manage, and maintain ATO packages including System Security and Privacy Plans (SSPP), Security Assessment Reports (SAR), Plans of Action and Milestones (POA&M), Requirements Traceability Matrices (RTM), Residual Risk Reports, and Threat Matrix Reports. * Provide technical direction to ISSO and Security Control Assessor (SCA) teams; ensure proper role separation and independence requirements are maintained across assessment and authorization activities. * Conduct system-level risk assessments and brief senior government officials on security posture, residual risks, and recommended risk responses. * Lead the selection, tailoring, and allocation of NIST SP 800-53 Rev. 5 security and privacy controls in accordance with applicable federal cybersecurity standards; generate Requirements Traceability Matrices. * Develop and maintain Information Security Continuous Monitoring (ISCM) plans to supplement agency-level monitoring strategies at the system level. * Coordinate privacy documentation, including Initial Privacy Assessments (IPA), Privacy Impact Assessments (PIA), and Systems of Records Notices (SORN), for systems processing Personally Identifiable Information (PII). * Manage MOU and Interconnection Security Agreement (ISA) development for system interconnections; ensure interconnection documentation is included in final A&A packages. * Support annual FISMA and FISCAM audits: prepare documentation and respond to auditor requests. * Manage scope, schedule, and resource allocation for RMF engagements; provide regular program status reporting. Who You Are * RMF Expert: You have led federal information systems through the complete NIST SP 800-37 lifecycle to ATO. You know what it takes to get an authorization package across the finish line. * Documentation Specialist: You produce SSPP, SAR, POA&M, RTM, and authorization package documentation that is accurate, complete, and AO-ready without extensive rework. * Privacy-Conscious: You understand the Privacy Act of 1974, OMB A-130, and E-Government Act Section 208 requirements and know how to coordinate IPA/PIA processes with privacy officials. * Leader: You can direct cross-functional teams of ISSOs, SCAs, and system owners, keeping everyone aligned on authorization timelines and accountable for their deliverables. * Communicator: You translate complex security posture findings into clear risk briefings for senior government officials and executive stakeholders. ## Related Videos - [Introducing the W3C Web Sustainability Guidelines](https://www.wearedevelopers.com/videos/991-introducing-the-w3c-web-sustainability-guidelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [RPA in the Public Sector](https://www.wearedevelopers.com/videos/86-rpa-in-the-public-sector) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)