> Markdown version of [/jobs/ext/2170287-senior-security-analyst-ato-rmf-active-ts-sci-clearance](https://www.wearedevelopers.com/jobs/ext/2170287-senior-security-analyst-ato-rmf-active-ts-sci-clearance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Analyst - ATO / RMF (Active TS/SCI Clearance) - **Company:** Strategic Business Systems, Inc. - **Location:** Chantilly, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Cloud Computing Security, Cyber Security, Intrusion Detection Systems, Network Security, Package Development Process, Fortify (Software), Security Content Automation Protocol, Cloud Platform System, Firewalls (Computer Science), Tenable Nessus, Checkmarx, Vulnerability Analysis - **Published:** August 21, 2026 - **Apply:** https://www.jofdav.com/jobs/59329179-senior-security-analyst-ato-rmf-active-ts-sci-clearance ## About the Role * Hands-on experience supporting and/or managing ATO packages for cloud-based products * Experience supporting solutions used by U.S. government agencies and/or military organizations * Strong experience with ATO writing, security documentation, and package development * Hands-on knowledge of the Risk Management Framework (RMF) * Understanding of all RMF lifecycle steps * Experience assessing security controls against NIST 800-53 * Experience developing and managing POA&Ms * Ability to understand and explain security-control inheritance Vulnerability & Compliance Management * Experience identifying and mitigating open-day vulnerabilities * Experience reviewing and interpreting vulnerability scans * Knowledge of STIGs and SCAP * Experience with vulnerability and application-security tools such as Tenable Nessus, Checkmarx, Fortify, or similar platforms * Ability to recommend appropriate countermeasures and mitigating controls * Experience supporting continuous monitoring and compliance reporting, * Experience assessing the security posture of cloud-based environments and products * Understanding of cloud security controls, configurations, and compliance requirements * Ability to evaluate configuration changes and determine their potential security impact * Familiarity with firewalls, network security, and intrusion detection systems (IDS) in cloud environments is preferred Customer-Facing Skills * Strong technical writing and documentation skills * Ability to explain cybersecurity risks and requirements to both technical and non-technical stakeholders * Comfortable leading customer meetings and technical discussions * Ability to translate cybersecurity findings into actionable remediation recommendations * Self-motivated and comfortable working within a small, agile technical team, * Active TS/SCI clearance required * CI Polygraph preferred but not required * Active Security+ or higher IAT Level II/III certification required * CISSP or similar information security certification preferred * Cloud security or platform certifications are a plus * Bachelors degree preferred, Target Salary Range: $140,000-195,000. This range reflects the anticipated compensation for this role. Actual salary will be based on a combination of factors, including the positions scope and level of responsibility, the candidates relevant experience, education, technical expertise, skills and qualifications, geographic location, and applicable business or contractual requirements. ## Description Strategic Business Systems (SBS) is expanding our cybersecurity team and hiring Senior Security Analysts to support our growing Authority to Operate as a Service (ATOaaS) offering. SBS developed ATOaaS in collaboration with leading technology companies and DoD/Intelligence Community customers to help accelerate the process of bringing innovative commercial technologies into secure government environments. This is a hands-on cybersecurity role supporting technology partners and government customers throughout the Authority to Operate (ATO) and Risk Management Framework (RMF) lifecycle. Youll work directly with customers to understand their technologies, develop security documentation, assess vulnerabilities, implement and document security controls, manage POA&Ms, and help move cloud-based solutions successfully through authorization. The goal is straightforward: help technology providers navigate the government security authorization process faster while maintaining the security and compliance required for mission environments. If you have experience developing ATO packages, understand RMF, and enjoy working directly with customers to solve cybersecurity and compliance challenges, this is a strong fit. What Youll Be Doing * Support customers through the complete ATO and RMF lifecycle * Develop and maintain ATO security packages and authorization documentation * Write clear technical documentation describing how systems are configured, secured, and operated * Work across the RMF lifecycle, including Categorize, Select, Implement, Assess, Authorize, and Monitor * Assess security controls against NIST 800-53 requirements * Analyze STIG and SCAP requirements and document compliance * Review vulnerability scans and identify security weaknesses within customer environments * Interpret results from tools such as Tenable Nessus, Checkmarx, and Fortify * Develop, manage, and update Plans of Action & Milestones (POA&Ms) * Track vulnerabilities through remediation, mitigation, or risk acceptance * Identify and help customers remediate open-day vulnerabilities * Evaluate configuration changes and their impact on the security posture of enterprise cloud solutions * Recommend mitigating controls and security countermeasures * Support continuous monitoring following authorization * Maintain security documentation as customer environments and requirements evolve * Explain security-control inheritance models and associated resources * Prepare documentation for system audits and vulnerability assessments * Communicate cybersecurity risk and remediation recommendations to technical teams and senior leadership Customer & Technical Delivery This role involves more than developing security documentation. Youll work directly with SBS technology partners and government customers to help move their solutions through the authorization process. Youll be expected to: * Lead technical discussions with customers and technology partners * Understand customer systems, architectures, and business requirements * Translate technical environments into appropriate security controls and authorization requirements * Advise customers on security best practices and required remediation * Identify technical and cybersecurity risks and recommend mitigation strategies * Participate in project planning and identify risks, dependencies, and deliverables * Develop project artifacts and support Work Breakdown Structures (WBS) * Communicate project status, risks, and technical requirements to project leadership * Provide guidance and technical leadership to customers and less-experienced security staff ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)