Security Assessment & Authorization (SA&A) Lead

Gunnison

Bethesda (MD)

Hybrid

USD 130,000 - 145,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

3 weeks of Personal Leave
11 paid Holidays
5 days Flexible Time Off
401(k) company match
Medical, Dental and Vision Insurance
Life and Disability Insurance
Public Transportation Subsidies
Certifications and Training Allowance

Job summary

Gunnison seeks an experienced SA&A lead to manage Authorization to Operate packages for NIH CIT enterprise systems, spanning on-prem, cloud, network, hosting, endpoints, and shared services. You will guide RMF processes, craft artifacts, and coordinate assessments across teams in a federal security context.

The role requires 3–5 years of security assessment experience, active CISSP/CAP or equivalent, and strong collaboration with system owners and leadership.

Qualifications

  • Bachelor's degree required and 3–5 years of security assessment/authorization experience.
  • Active CISSP and CAP certifications are preferred.
  • Experience creating and maintaining SSPs, SAPs, SARs, POA&Ms, risk registers, and other artifacts.

Responsibilities

  • Lead Security Assessment and Authorization (SA&A) activities for NIH CIT enterprise information systems and environments.
  • Plan, develop, coordinate, review, and maintain Authorization to Operate (ATO) packages per RMF, NIST SP 800-37/800-53, FISMA, and HHS/NIH requirements.
  • Develop and maintain SSPs, SAPs, SARs, risk assessments, contingency and incident response plans, and related documentation.
  • Write, review, and validate security-control implementation statements against NIST SP 800-53 controls.
  • Conduct security-control assessments, document findings, and recommend corrective actions.
  • Create and maintain POA&Ms with owners, milestones, risk ratings, and closure evidence.

Skills

Lead SA&A activities
RMF implementation
NIST SP 800-37
NIST SP 800-53 controls
Risk assessment
POA&Ms management
IR and CP testing
Incident response coordination

Education

Bachelor’s degree in cybersecurity, information assurance, information systems, or related field
CISSP (current and active)
CAP (current and active)
CISM
CISA
CCSP
PMP
CRISC
ISO/IEC 27001 Lead Implementer or Lead Auditor

Job description

  • This position is contingent upon a future opening with Gunnison.

Salary: $130,000 - $145,000/year

  • Lead Security Assessment and Authorization (SA&A) activities for NIH CIT enterprise information systems, including on-premises, cloud-based, network, hosting, endpoint, and shared-service environments.
  • Plan, develop, coordinate, review, and maintain Authorization to Operate (ATO) packages in accordance with the NIST Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, FISMA, and applicable HHS, NIH, and federal security requirements.
  • Lead development and maintenance of system authorization artifacts, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), risk assessments, contingency plans, incident response plans, and associated supporting documentation.
  • Write, review, assess, and validate security-control implementation statements against applicable NIST SP 800-53 controls and control enhancements.
  • Conduct security-control assessments, including evidence review, technical validation, stakeholder interviews, and assessment testing; document findings, assess risks, and recommend corrective actions.
  • Create, maintain, track, and update Plans of Action and Milestones (POA&Ms), ensuring findings have clear owners, remediation milestones, risk ratings, status updates, and closure evidence.
  • Prepare Risk Assessment Memoranda and other risk-based decision packages that clearly describe security risks, proposed mitigations, residual risk, and recommended courses of action for management review.
  • Develop and maintain system and program-level risk registers; identify and communicate high-risk conditions, trends, overdue remediation actions, dependencies, and emerging compliance concerns to program and Government leadership.
  • Coordinate and facilitate incident response (IR) and contingency planning (CP) tests, tabletop exercises, and after-action activities; document results, corrective actions, lessons learned, and required updates to security documentation.
  • Review ATO packages for completeness, accuracy, consistency, and readiness before submission to the CISO, CIO, Authorizing Official, or designated approval authority.
  • Conduct assessment entrance and exit meetings with system owners, system administrators, ISSOs, engineers, and other stakeholders; debrief teams on assessment findings, remediation expectations, and next steps.
  • Advise system owners and technical teams on RMF implementation, security-control compliance, risk acceptance, remediation planning, and authorization strategy.
  • Prepare clear, timely assessment reports, compliance dashboards, executive briefings, status reports, and decision memoranda for technical and leadership audiences.
  • Lead and mentor SA&A analysts and assessors; assign and review work, maintain quality standards, and coordinate simultaneous authorization and continuous-monitoring activities across multiple systems.
Description
  • Lead Security Assessment and Authorization (SA&A) activities for NIH CIT enterprise information systems, including on-premises, cloud-based, network, hosting, endpoint, and shared-service environments.
  • Plan, develop, coordinate, review, and maintain Authorization to Operate (ATO) packages in accordance with the NIST Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, FISMA, and applicable HHS, NIH, and federal security requirements.
  • Lead development and maintenance of system authorization artifacts, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), risk assessments, contingency plans, incident response plans, and associated supporting documentation.
  • Write, review, assess, and validate security-control implementation statements against applicable NIST SP 800-53 controls and control enhancements.
  • Conduct security-control assessments, including evidence review, technical validation, stakeholder interviews, and assessment testing; document findings, assess risks, and recommend corrective actions.
  • Create, maintain, track, and update Plans of Action and Milestones (POA&Ms), ensuring findings have clear owners, remediation milestones, risk ratings, status updates, and closure evidence.
  • Prepare Risk Assessment Memoranda and other risk-based decision packages that clearly describe security risks, proposed mitigations, residual risk, and recommended courses of action for management review.
  • Develop and maintain system and program-level risk registers; identify and communicate high-risk conditions, trends, overdue remediation actions, dependencies, and emerging compliance concerns to program and Government leadership.
  • Coordinate and facilitate incident response (IR) and contingency planning (CP) tests, tabletop exercises, and after-action activities; document results, corrective actions, lessons learned, and required updates to security documentation.
  • Review ATO packages for completeness, accuracy, consistency, and readiness before submission to the CISO, CIO, Authorizing Official, or designated approval authority.
  • Conduct assessment entrance and exit meetings with system owners, system administrators, ISSOs, engineers, and other stakeholders; debrief teams on assessment findings, remediation expectations, and next steps.
  • Advise system owners and technical teams on RMF implementation, security-control compliance, risk acceptance, remediation planning, and authorization strategy.
  • Prepare clear, timely assessment reports, compliance dashboards, executive briefings, status reports, and decision memoranda for technical and leadership audiences.
  • Lead and mentor SA&A analysts and assessors; assign and review work, maintain quality standards, and coordinate simultaneous authorization and continuous-monitoring activities across multiple systems.
Work location

Hybrid, 2-3 days per week on-site in Bethesda, MD.

  • Lead Security Assessment and Authorization (SA&A) activities for NIH CIT enterprise information systems, including on-premises, cloud-based, network, hosting, endpoint, and shared-service environments.
  • Plan, develop, coordinate, review, and maintain Authorization to Operate (ATO) packages in accordance with the NIST Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, FISMA, and applicable HHS, NIH, and federal security requirements.
  • Lead development and maintenance of system authorization artifacts, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), risk assessments, contingency plans, incident response plans, and associated supporting documentation.
  • Write, review, assess, and validate security-control implementation statements against applicable NIST SP 800-53 controls and control enhancements.
  • Conduct security-control assessments, including evidence review, technical validation, stakeholder interviews, and assessment testing; document findings, assess risks, and recommend corrective actions.
  • Create, maintain, track, and update Plans of Action and Milestones (POA&Ms), ensuring findings have clear owners, remediation milestones, risk ratings, status updates, and closure evidence.
  • Prepare Risk Assessment Memoranda and other risk-based decision packages that clearly describe security risks, proposed mitigations, residual risk, and recommended courses of action for management review.
  • Develop and maintain system and program-level risk registers; identify and communicate high-risk conditions, trends, overdue remediation actions, dependencies, and emerging compliance concerns to program and Government leadership.
  • Coordinate and facilitate incident response (IR) and contingency planning (CP) tests, tabletop exercises, and after-action activities; document results, corrective actions, lessons learned, and required updates to security documentation.
  • Review ATO packages for completeness, accuracy, consistency, and readiness before submission to the CISO, CIO, Authorizing Official, or designated approval authority.
  • Conduct assessment entrance and exit meetings with system owners, system administrators, ISSOs, engineers, and other stakeholders; debrief teams on assessment findings, remediation expectations, and next steps.
  • Advise system owners and technical teams on RMF implementation, security-control compliance, risk acceptance, remediation planning, and authorization strategy.
  • Prepare clear, timely assessment reports, compliance dashboards, executive briefings, status reports, and decision memoranda for technical and leadership audiences.
  • Lead and mentor SA&A analysts and assessors; assign and review work, maintain quality standards, and coordinate simultaneous authorization and continuous-monitoring activities across multiple systems.
Requirements

Minimum of three (3) to five (5) years of progressively responsible experience in security assessment and authorization, RMF, information-system security, cybersecurity compliance, or a related discipline.

Candidates Must Demonstrate Experience In
  • Developing, updating, and submitting ATO packages for enterprise systems, including cloud-hosted or hybrid environments.
  • Applying the NIST RMF lifecycle under NIST SP 800-37.
  • Assessing and documenting implementation of NIST SP 800-53 security controls and control enhancements.
  • Creating and maintaining SSPs, SARs, SAPs, POA&Ms, risk assessments, risk registers, and other authorization artifacts.
  • Planning and conducting security-control assessments, evidence reviews, stakeholder interviews, technical validations, and remediation verification.
  • Facilitating IR and CP tests or tabletop exercises and documenting outcomes and corrective actions.
  • Preparing risk-based decision packages, including risk assessment memoranda and risk acceptance/mitigation recommendations.
  • Reviewing authorization packages before senior leadership submission and briefing assessment findings to system owners and management.
  • Supporting continuous-monitoring, vulnerability-management, configuration-management, and compliance-reporting processes.
  • Bachelor’s degree from an accredited college or university in cybersecurity, information assurance, information systems, computer science, computer engineering, network engineering, systems engineering, or a closely related technical discipline.
  • Certified Information Systems Security Professional (CISSP), current and active
  • Certified Authorization Professional (CAP), current and active

Clearance Requirement: Ability to obtain and maintain a Public Trust.

Desired Qualifications
  • Master’s degree in cybersecurity, information assurance, information systems, computer science, engineering, public administration, business administration, or a related discipline.
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Certified Cloud Security Professional (CCSP)
  • CompTIA Security+, CySA+, CASP+, or equivalent
  • Project Management Professional (PMP)
  • ITIL Foundation
  • AWS Certified Security – Specialty
  • Microsoft Certified: Azure Security Engineer Associate
  • Google Professional Cloud Security Engineer
  • GIAC certifications relevant to governance, incident response, audit, cloud security, or risk management
  • Federal RMF, FISMA, NIST, cloud-security, or security-assessment training
  • Certified in Risk and Information Systems Control (CRISC)
  • ISO/IEC 27001 Lead Implementer or Lead Auditor

The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements.

Benefits

Gunnison Consulting Group's total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include:

  • 3 weeks of Personal Leave your first year
  • 11 paid Holidays each year
  • 5 days of Flexible Time Off each year for approved training or certifications (self-study is ineligible)
  • 401(k) company match at 50% up to 10% of your salary
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • Public Transportation Subsidies
  • Certifications and Training Allowance - Up to $5,000/year!
Why Join Gunnison?
  • Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation.
  • Quality is our top priority.
  • Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer.
  • There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow.
  • We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding.
  • We hire for careers at Gunnison, not to fill a position.

Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time.

In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects. By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could the company has thrived for over 25 years.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Assessment & Authorization (SA&A) Lead
Security Assessment & Authorization (SA&A) Lead

Gunnison Consulting Group • Bethesda (MD)

Hybrid
USD 130,000 - 145,000
3 weeks Personal Leave
11 paid Holidays
5 days Flexible Time Off
+5
Cybersecurity Incident and Application Analyst
Cybersecurity Incident and Application Analyst

Gunnison • Bethesda (MD)

Hybrid
USD 130,000 - 145,000
3 weeks Personal Leave
11 paid Holidays
Flexible Time Off for training
+3
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Gunnison Consulting Group • Bethesda (MD)

Hybrid
USD 145,000 - 160,000
Medical, Dental and Vision Insurance
401(k) company match
Paid Holidays
+1
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Gunnison • Bethesda (MD)

Hybrid
USD 140,000 - 190,000
3 weeks of Personal Leave
11 paid Holidays
Flexible Time Off
+5
Cybersecurity Operations Lead
Cybersecurity Operations Lead

Gunnison • Alexandria (VA)

Hybrid
USD 170,000 - 190,000
Bonus and profit-sharing
Personal Leave
Holidays
+5
Cybersecurity Program Manager
Cybersecurity Program Manager

Gunnison • Bethesda (MD)

Hybrid
USD 150,000 - 165,000
3 weeks Personal Leave
11 paid Holidays
Flexible Time Off
+5
System Database Developer - SecDevOps
System Database Developer - SecDevOps

Gunnison Consulting Group • Bethesda (MD)

Hybrid
USD 130,000 - 145,000
3 weeks Personal Leave
11 paid Holidays
Flexible Time Off
+5
Cyber Incident Management Lead
Cyber Incident Management Lead

Gunnison Consulting Group • Alexandria (VA)

On-site
USD 160,000 - 180,000
3 weeks of Personal Leave your first y
11 paid Holidays each year
5 days of Flexible Time Off
+5
Privacy Lead
Privacy Lead

Gunnison • Bethesda (MD)

Hybrid
USD 130,000 - 145,000
3 weeks Personal Leave
11 Holidays
5 Flexible Time Off
+5
System Database Developer - SecDevOps
System Database Developer - SecDevOps

Gunnison • Bethesda (MD)

Hybrid
USD 130,000 - 145,000
3 weeks Personal Leave
11 paid Holidays
5 days Flexible Time Off
+5