Assessment & Authorization (A&A) Lead

Intellect Solutions LLC

Rockville, Northern (MD, KY)

Hybrid

USD 150,000 - 190,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Intellect Solutions LLC is seeking an experienced Assessment and Authorization (A&A) Lead to oversee cybersecurity assessment, authorization, and continuous monitoring for federal information systems in Rockville, MD. You will supervise a team of five to eight professionals and ensure accurate, complete, and compliant security packages delivered on schedule.

The role requires a strong command of NIST RMF, SP 800-series controls, and federal security requirements, with demonstrated leadership in

Qualifications

  • Experience leading teams of Security Control Assessors, ISSOs, or cybersecurity analysts.
  • Strong knowledge of NIST RMF and related SP 800-series controls and guidance.
  • Familiarity with federal governance, risk, and compliance workflows and documentation.

Responsibilities

  • Lead the end-to-end A&A and ATO process for federal information systems.
  • Mentor a team of five to eight Security Control Assessors and ISSOs.
  • Develop and maintain integrated ATO schedules, milestones, and resource assignments.
  • Coordinate security authorization activities with system owners, technical teams, and stakeholders.
  • Apply RMF across the system development and authorization lifecycle.
  • Review and validate security authorization documentation and evidence.
  • Monitor POA&M items and ensure timely remediation and closure.
  • Prepare executive dashboards and reports on ATO status and risk.

Skills

Leadership
NIST RMF
Risk Management
Federal ATO
Team Mentoring
Communication

Education

Bachelor's degree in cybersecurity or related

Tools

CSAM
JCAM
ServiceNow GRC

Job description

SUMMARY

We are seeking an experienced Assessment and Authorization (A&A) Lead to oversee cybersecurity assessment, authorization, and continuous monitoring activities for federal information systems. The successful candidate will possess strong knowledge of the NIST Risk Management Framework (RMF), federal security requirements, and the complete Authorization to Operate (ATO) lifecycle.

This position will lead and manage a team of approximately five to eight Security Control Assessors, Information System Security Officers (ISSOs), and other cybersecurity professionals. The A&A Lead will be responsible for ensuring that security authorization packages are accurate, complete, compliant, and delivered according to established schedules.

Key Responsibilities
  • Lead the end-to-end A&A and ATO process for federal information systems.
  • Manage and mentor a team of five to eight Security Control Assessors and ISSOs.
  • Develop and maintain integrated ATO schedules, milestones, priorities, and resource assignments.
  • Coordinate security authorization activities with system owners, technical teams, ISSOs, assessors, authorizing officials, and other stakeholders.
  • Apply the NIST Risk Management Framework throughout the system development and authorization lifecycle.
  • Review and validate security authorization documentation, including:
    • System Security Plans
    • Security Assessment Plans
    • Security Assessment Reports
    • Plans of Action and Milestones
    • Risk assessments
    • Contingency plans
    • Continuous monitoring plans
    • Security control implementation evidence
  • Oversee security control assessments and ensure findings are clearly documented, supported by evidence, and assigned appropriate risk ratings.
  • Evaluate system vulnerabilities, control deficiencies, and residual risks to support authorization decisions.
  • Monitor remediation activities and ensure POA&M items are properly documented, tracked, updated, and closed.
  • Conduct quality assurance reviews of A&A packages before submission to the Authorizing Official.
  • Identify risks, schedule delays, documentation gaps, and resource constraints and communicate them to program leadership.
  • Establish standardized A&A procedures, templates, checklists, and quality-control processes.
  • Facilitate status meetings, risk-review sessions, and authorization-readiness reviews.
  • Support continuous monitoring, annual assessments, significant-change reviews, and authorization renewals.
  • Prepare executive-level dashboards, metrics, and reports describing ATO status, risks, findings, and remediation progress.
  • Provide guidance to system teams on federal cybersecurity policies, control implementation, and compliance expectations.
  • Promote accountability, collaboration, and consistent performance across the A&A team.
Required Qualifications
  • Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related discipline.
  • At least eight years of cybersecurity, information assurance, or information system security experience.
  • At least five years of direct experience supporting federal A&A, ATO, or NIST RMF activities.
  • Demonstrated experience managing or leading teams of Security Control Assessors, ISSOs, or cybersecurity analysts.
  • Strong knowledge of:
    • NIST Risk Management Framework
    • NIST SP 800-37
    • NIST SP 800-53
    • NIST SP 800-53A
    • NIST SP 800-30
    • FISMA requirements
    • Federal continuous monitoring practices
  • Experience reviewing complex security authorization packages and evaluating security control evidence.
  • Strong understanding of security risk management, vulnerability management, POA&M management, and continuous monitoring.
  • Ability to manage multiple systems and authorization activities simultaneously.
  • Strong leadership, analytical, organizational, and problem-solving skills.
  • Excellent written and verbal communication skills, including the ability to communicate technical risks to executive and nontechnical stakeholders.
  • Ability to work effectively with government leadership, system owners, engineers, cybersecurity teams, and third-party assessors.
Required Certification

Candidates must hold at least one of the following active certifications:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
Preferred Qualifications
  • Experience supporting cybersecurity programs within NIH, HHS, or another federal civilian agency.
  • Experience with federal governance, risk, and compliance platforms such as CSAM, JCAM, ServiceNow GRC, or similar tools.
  • Experience managing a portfolio of systems with concurrent ATO deadlines.
  • Familiarity with cloud security requirements, including FedRAMP and NIST controls for AWS, Microsoft Azure, or other cloud environments.
  • Experience developing A&A standard operating procedures, playbooks, templates, and performance metrics.
  • Additional certifications such as CAP/CGRC, CRISC, CCSP, PMP, or Security+.
  • Experience supporting high-impact or mission-critical federal information systems.
Leadership Expectations

The A&A Lead must be a hands-on leader who can establish priorities, assign responsibilities, remove obstacles, coach team members, and maintain high-quality deliverables. The individual must be comfortable engaging directly with senior government stakeholders, presenting authorization risks, and recommending practical solutions that balance mission requirements with cybersecurity compliance.

Success Measures
  • Timely completion of ATO packages and authorization milestones.
  • Quality and completeness of security documentation.
  • Reduction in overdue assessments and POA&M items.
  • Accuracy of risk assessments and executive reporting.
  • Improved coordination among system owners, ISSOs, assessors, and technical teams.
  • Consistent application of NIST RMF requirements across the system portfolio.

Effective leadership, development, and retention of the A&A team.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

RMF and Authorization Lead
RMF and Authorization Lead

A-TEK Inc. • Rockville (MD)

Hybrid
USD 165,000 - 185,000
Health, dental, vision insurance
401(k) with employer match
Paid time off
Cybersecurity Assessment & Authorization SME
Cybersecurity Assessment & Authorization SME

Ariel Partners • Fairfax (VA)

On-site
USD 90,000 - 130,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Jobtailor • Washington

On-site
USD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Inadev • Reston (VA)

Hybrid
USD 120,000 - 180,000
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc • Washington, Northern (KY)

Hybrid
USD 140,000 - 220,000
Paid holidays
PTO
Group medical plan
+4
Federal A&A Lead - RMF & ATO Champion
Federal A&A Lead - RMF & ATO Champion

Intellect Solutions LLC • Rockville (MD), Northern (KY)

Hybrid
USD 150,000 - 190,000
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc. • Washington

On-site
USD 150,000 - 210,000
11 paid holidays
3 weeks PTO (min)
Medical plan
+4
Information Assurance Engineer
Information Assurance Engineer

Agile IT Synergy, LLC • Tampa (FL)

On-site
USD 90,000 - 130,000
Compliance & Audit Support (Mid)
Compliance & Audit Support (Mid)

Koniag Services, Inc. • Washington, Northern (KY)

On-site
USD 70,000 - 110,000
Health insurance
Dental insurance
Vision insurance
+2
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc. • Washington

On-site
USD 120,000 - 180,000
Paid holidays
3 weeks PTO
Group medical plan
+4