| Location | DC |
SUMMARY: We are seeking an experienced Assessment and Authorization (A&A) Lead to oversee cybersecurity assessment, authorization, and continuous monitoring activities for federal information systems. The successful candidate will possess strong knowledge of the NIST Risk Management Framework (RMF), federal security requirements, and the complete Authorization to Operate (ATO) lifecycle.
This position will lead and manage a team of approximately five to eight Security Control Assessors, Information System Security Officers (ISSOs), and other cybersecurity professionals. The A&A Lead will be responsible for ensuring that security authorization packages are accurate, complete, compliant, and delivered according to established schedules.
Key Responsibilities
Lead the end-to-end A&A and ATO process for federal information systems.
Manage and mentor a team of five to eight Security Control Assessors and ISSOs.
Develop and maintain integrated ATO schedules, milestones, priorities, and resource assignments.
Coordinate security authorization activities with system owners, technical teams, ISSOs, assessors, authorizing officials, and other stakeholders.
Apply the NIST Risk Management Framework throughout the system development and authorization lifecycle.
Review and validate security authorization documentation, including:
System Security Plans
Security Assessment Plans
Security Assessment Reports
Plans of Action and Milestones
Risk assessments
Contingency plans
Continuous monitoring plans
Security control implementation evidence
Oversee security control assessments and ensure findings are clearly documented, supported by evidence, and assigned appropriate risk ratings.
Evaluate system vulnerabilities, control deficiencies, and residual risks to support authorization decisions.
Monitor remediation activities and ensure POA&M items are properly documented, tracked, updated, and closed.
Conduct quality assurance reviews of A&A packages before submission to the Authorizing Official.
Identify risks, schedule delays, documentation gaps, and resource constraints and communicate them to program leadership.
Establish standardized A&A procedures, templates, checklists, and quality-control processes.
Facilitate status meetings, risk-review sessions, and authorization-readiness reviews.
Support continuous monitoring, annual assessments, significant-change reviews, and authorization renewals.
Prepare executive-level dashboards, metrics, and reports describing ATO status, risks, findings, and remediation progress.
Provide guidance to system teams on federal cybersecurity policies, control implementation, and compliance expectations.
Promote accountability, collaboration, and consistent performance across the A&A team.
Required Qualifications
Bachelor's degree in cybersecurity, information technology, computer science, engineering, or a related discipline.
At least eight years of cybersecurity, information assurance, or information system security experience.
At least five years of direct experience supporting federal A&A, ATO, or NIST RMF activities.
Demonstrated experience managing or leading teams of Security Control Assessors, ISSOs, or cybersecurity analysts.
Strong knowledge of:
NIST Risk Management Framework
NIST SP 800-37
NIST SP 800-53
NIST SP 800-53A
NIST SP 800-30
FISMA requirements
Federal continuous monitoring practices
Experience reviewing complex security authorization packages and evaluating security control evidence.
Strong understanding of security risk management, vulnerability management, POA&M management, and continuous monitoring.
Ability to manage multiple systems and authorization activities simultaneously.
Strong leadership, analytical, organizational, and problem-solving skills.
Excellent written and verbal communication skills, including the ability to communicate technical risks to executive and nontechnical stakeholders.
Ability to work effectively with government leadership, system owners, engineers, cybersecurity teams, and third-party assessors.
Required Certification
Candidates must hold at least one of the following active certifications:
Preferred Qualifications
Leadership Expectations
The A&A Lead must be a hands-on leader who can establish priorities, assign responsibilities, remove obstacles, coach team members, and maintain high-quality deliverables. The individual must be comfortable engaging directly with senior government stakeholders, presenting authorization risks, and recommending practical solutions that balance mission requirements with cybersecurity compliance.
Success Measures
Success in this role will be measured through:
Effective leadership, development, and retention of the A&A team.