RMF and Authorization Lead

A-TEK Inc.

Rockville (MD)

Hybrid

USD 165,000 - 185,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, dental, vision insurance
401(k) with employer match
Paid time off

Job summary

A-TEK Inc. is seeking an experienced RMF/A&A Lead to support a federal client. The role oversees authorization readiness, package development, governance, risk management, and cybersecurity documentation across RMF/A&A activities.

Hybrid work is required in the Washington, DC area or Research Triangle, NC. Responsibilities include maintaining SSPs and SARs, coordinating annual assessments, and ensuring artifacts are audit-ready.

Qualifications

  • Experience leading Federal RMF and A&A activities of similar scope.
  • Knowledge of NIST SP 800-37/800-53/800-53A and FISMA.
  • Experience developing and maintaining Federal authorization packages.
  • Experience with security assessments, POA&M, and risk-based decisions.
  • Strong technical writing and stakeholder coordination.
  • Ability to support hybrid work in DC metro or Research Triangle.

Responsibilities

  • Lead RMF activities across multiple authorization boundaries and system inventory.
  • Maintain SSPs, SARs, POA&Ms, executive summaries, ATO docs.
  • Coordinate annual security control assessments and gather evidence.
  • Ensure assessor independence and governance integrity.
  • Manage artifacts in the agency's GRC platform.
  • Lead POA&M management, risk analysis, and remediation tracking.
  • Support cloud, FedRAMP docs, and shared responsibility analysis.
  • Review changes and prepare security impact analyses.
  • Identify risks impacting authorization, assessments, or timelines.
  • Support transition activities and boundary reconciliations.

Skills

Federal RMF leadership
A&A program management
NIST controls knowledge
Technical writing
Cross-functional coordination
Hybrid work adaptability
Security certifications

Education

Bachelor's degree in a related field

Tools

JCAM or FedRAMP GRC platform

Job description

Empower, Innovate, Impact! At Team A-TEK, we EMPOWER people to drive INNOVATION that IMPACTS mission!

A-TEK operates at the intersection of mission and innovation by applying our deep domain expertise across the federal markets. Embracing our digital-first strategy, A-TEK provides enhanced capabilities in application development, digital transformation, enterprise IT, and scientific services. Our solutions are designed to modernize, automate, secure, protect, and enhance the operations of our federal clients, ensuring they stay ahead in a rapidly evolving digital landscape.

Our work is fueled by a passion to serve our clients’ needs and to protect the safety and welfare of Americans. That passion shapes how we nurture our most valuable asset – Our Employees. A-TEK actively cultivates the talent that drives our success and fosters a creative, challenging, and mission-driven work environment for current and future employees.

A-TEK is seeking an experienced RMF/A&A Lead to support our federal customer. The RMF/A&A Lead serves as the senior technical authority for RMF and A&A activities supporting an HHS-affiliated agency. This individual leads authorization readiness, authorization package development and maintenance, Governance, Risk, and Compliance activities, cybersecurity documentation, risk management, and system lifecycle support. The Lead coordinates with system owners, ISSOs, administrators, privacy officials, assessors, and agency cybersecurity personnel to maintain complete, current, and audit ready authorization packages. The ability to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle, NC area is required.

Responsibilities
  • Lead RMF activities across three primary authorization boundaries and the associated system inventory.
  • Maintain SSPs, SARs, POA&Ms, Executive Summaries, ATO documentation, and supporting evidence.
  • Coordinate three annual security control assessments and prepare evidence for the independent assessor.
  • Maintain assessor independence and avoid acting as the assessor of record unless the agency expressly authorizes an activity.
  • Direct system registration, inventory reconciliation, artifact maintenance, data quality review, and status validation in the agency’s designated GRC platform.
  • Lead POA&M management, residual risk analysis, risk reporting, and remediation tracking.
  • Support cloud and FedRAMP documentation, control inheritance analysis, and shared responsibility analysis.
  • Review major changes, prepare security impact analyses, and support onboarding and decommissioning.
  • Conduct technical and quality reviews before submitting cybersecurity artifacts.
  • Identify and elevate risks that could affect an authorization, assessment, or deliverable schedule.
  • Support transition activities and reconcile authorization boundaries, inventories, artifacts, and active work.
Required Experience and Qualifications
  • Demonstrated experience leading Federal RMF and A&A activities of comparable scope and complexity.
  • Knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA, and Federal continuous monitoring requirements.
  • Experience developing and maintaining Federal authorization packages.
  • Experience supporting independent security assessments, POA&M management, and risk-based decisions.
  • Strong technical writing, stakeholder coordination, and quality review skills.
  • Ability to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle area.
  • Education and experience that satisfy the proposed GSA labor category.
Preferred Experience and Qualifications
  • Experience supporting HHS or another Federal health agency.
  • Experience using JCAM or a comparable Federal GRC platform.
  • Experience supporting cloud security, FedRAMP, inherited controls, and shared responsibility analysis.
  • Experience coordinating multiple concurrent authorization, assessment, and continuous monitoring activities.
  • CISSP, CAP/CGRC, CISM, Security+, or an applicable cloud security certification.
Compensation

Salary Range:$165,000 – $185,000 annually (commensuratewith experience)
Benefits:Health, dental, and vision insurance; 401(k) with employer match; paid time off; professional development opportunities.

Why Join Us?

This is an opportunity to make a direct impact on healthcare data processes that support critical regulatory functions. You will collaborate with dedicated professionals, work on meaningful projects, and contribute to improvements in public health systems.

Candidates may use tools (including AI) for proofreading or formatting; however, using any tool to fabricate, exaggerate, or misrepresent qualifications, experience, or work product is not permitted. We may assess application materials for job-related technical depth, internal consistency, and demonstrated hands‑on experience, including through follow‑up questions, skills assessments, or reference checks. Verification of education may be requested before or during the hiring process.

For security and identity verification purposes, participants may be asked to temporarily disable virtual backgrounds during portions of the call.

Misrepresentation or falsification may result in removal from further consideration. Candidates who need a reasonable accommodation in the application or interview process may request one.

A-TEK, Inc. is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or status as a qualified individual with a disability, or Vietnam era or other protected Veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

RMF and Authorization Lead
RMF and Authorization Lead

atek s.r.o. • Maryland

Hybrid
USD 165,000 - 185,000
Health, dental, and vision insurance
401(k) with employer match
Paid time off
+1
RMF and Authorization Lead New Hybrid, Bethesda/Rockville, MD, United States
RMF and Authorization Lead New Hybrid, Bethesda/Rockville, MD, United States

A-TEK Inc. • Bethesda (MD)

Hybrid
USD 165,000 - 185,000
RMF and Authorization Lead
RMF and Authorization Lead

atek • Bethesda (MD), Rockville (MD)

Hybrid
USD 165,000 - 185,000
Health insurance
401(k) with employer match
Paid time off
+1
Security Assessment and Continuous Monitoring Analyst
Security Assessment and Continuous Monitoring Analyst

atek s.r.o. • Maryland

Hybrid
USD 110,000 - 120,000
Health, dental, and vision insurance
401(k) with employer match
Paid time off
+1
Security Assessment and Continuous Monitoring Analyst
Security Assessment and Continuous Monitoring Analyst

A-TEK Inc. • Bethesda (MD), Rockville (MD)

Hybrid
USD 110,000 - 120,000
Health, dental, and vision insurance
401(k) with employer match
Paid time off
+1
Senior Program Manager CSOC
Senior Program Manager CSOC

atek s.r.o. • Rockville (MD)

On-site
USD 170,000 - 190,000
Health, dental, and vision insurance
401(k) with employer match
Paid time off
+1
Senior Cybersecurity Analyst / RMF Lead
Senior Cybersecurity Analyst / RMF Lead

chameleonintegratedservices • South Dakota

On-site
USD 120,000 - 160,000
Health insurance
Vision plan
401K with match
+4
RMF/Assessment & Authorization (A&A) Analyst
RMF/Assessment & Authorization (A&A) Analyst

Socket.dev • Bethesda (MD)

On-site
USD 115,000 - 135,000
Certificate incentive program
PTO and floating holidays
Health and dental insurance options
+1
Risk Management Framework (RMF) Specialist
Risk Management Framework (RMF) Specialist

PeopleTec, Inc. • Huntsville (AL)

On-site
USD 120,000 - 150,000
Cybersecurity Analyst
Cybersecurity Analyst

Amentum • McLean (VA)

On-site
USD 130,000 - 160,000
Health Insurance
Dental Insurance
Vision Insurance
+2