> Markdown version of [/jobs/ext/2897745-security-assessment-authorization-analyst](https://www.wearedevelopers.com/jobs/ext/2897745-security-assessment-authorization-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Assessment & Authorization Analyst - **Company:** DLH Corporation - **Location:** United States - **Experience:** Expert - **Salary:** $135,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, System Configuration, Security Content Automation Protocol, Google Cloud, Information Technology, Splunk - **Published:** September 14, 2026 - **Apply:** https://jobs.military.com/career/335810/security-assessment-authorization-sa-a-analyst-sr-job-1457-texas-tx-austin ## About the Role n, * Minimum of eight (8) years of experience in developing and maintaining ATO security packages\n * Experience developing clear, concise documentation describing system configuration, operations, and security controls\n * Prior experience working with security tools such as Tenable, Splunk, and GRC JCAM\n * Strong knowledge of Federal security guidelines, standards, and control frameworks (such as NIST SP 800-53)\n * Bachelor's degree in information technology, Cybersecurity, or a related field\n * Relevant certifications (e.g., CGRC (CAP), CISA, CompTIA Security+, CISSP) required\n * Strong knowledge of security standards and best practices.\n * Excellent problem-solving and analytical skills.\n * Strong cross-team collaboration and coordination with 3rdparties is required\n * Prior experience with Cloud Security (AWS, Azure, GCP) within a large government environment (FedRAMP certified) preferred\n * Must be able to obtain a Public Trust clearance\n ## Description DLH is seeking an experienced Security Assessment & Authorization Analyst to join our team. The Sr. Security Assessment & Authorization Analyst is responsible for developing and maintaining Authority to Operate (ATO) security packages and authorization documentation and working across the Risk Management Framework (RMF) lifecycle for assigned systems. You will have worked with customers to understand technologies, develop security documentation, assess vulnerabilities, document and implement security controls, manage POA&Ms, and help move solutions successfully through authorization. The ideal candidate will have experience developing ATO packages, bring a robust knowledge of RMF, and enjoy working across diverse teams to solve cybersecurity and compliance challenges. \n \n \nResponsibilities \n \n \n * Develop and maintain ATO security packages and authorization documentation\n * Assess security controls to ensure compliance with NIST 800-53 requirements\n * Significant experience with the RMF lifecycle and assisting customers in obtaining Authority to Operate security packages\n * Develop, manage, and update Security Plans of Action & Milestones (POA&Ms)\n * Analyze STIG and SCAP requirements to ensure document compliance\n * Track vulnerabilities through remediation, mitigation, and/or risk acceptance\n * Evaluate environmental and configuration changes to determine impacts to the security posture of assigned systems\n * Recommend mitigating controls and countermeasures\n ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)