Security Authorization Lead (RMF and ATO) with Security Clearance

D9Tech Resources LLC

Arlington (VA)

Hybrid

USD 120,000 - 150,000

Full time

25 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

D9Tech Resources LLC is seeking a Security Compliance professional to author SSPs, manage POA&M, and drive ATO processes for DoD/cloud environments.

You will translate technical findings into actionable remediation with engineers, maintain eMASS or XACTA packages, and ensure continuous monitoring while coordinating with ISSOs and AO.

Candidates must hold active Secret clearance or higher, US citizenship, and experience with NIST RMF and DoD frameworks.

Qualifications

  • Active Secret clearance or higher and US citizenship required.
  • Experience owning an ATO lifecycle from documentation to authorization decision.
  • Hands-on authorship of System Security Plans and control implementation statements.
  • Proficiency with eMASS or XACTA tooling.
  • Strong knowledge of NIST SP 800-53 and RMF lifecycle.
  • POA&M management including milestone development and evidence collection.
  • Ability to communicate clearly with engineers, ISSOs, ISSMs, and AO.

Responsibilities

  • Author the package: write and maintain SSPs, control statements, and supporting artifacts.
  • Own the POA&M lifecycle: open, prioritize, track, and close POA&M with evidence.
  • Drive the ATO to signature: manage accreditation timeline and brief officials.
  • Work the tooling: maintain the package in eMASS or XACTA with current artifacts.
  • Translate scan output into action: review ACAS, STIG, and cloud findings, remediate with engineers.
  • Sustain continuous monitoring: run recurring control assessments and reporting cadence.
  • Advise early: participate in architecture discussions to design controls upfront.

Skills

Active Secret clearance or higher
U.S. citizenship
Full ATO ownership
SSP and control statements drafting
eMASS or XACTA proficiency
NIST SP 800-53 & RMF lifecycle
POA&M management
Clear communication with engineers/IS/

Tools

eMASS
XACTA

Job description

SECURITY COMPLIANCE | ACTIVE SECRET CLEARANCE REQUIRED, TS/SCI PREFERRED | U.S. CITIZENSHIP REQUIRED | REMOTE OR HYBRID (CONUS) ABOUT THE ROLE

An Authority to Operate is won or lost long before the package reaches the Authorizing Official. It is won in how the control narratives are written, how the evidence is gathered, and how honestly the residual risk is described. This seat owns that work end to end, from the first System Security Plan draft through sustained continuous monitoring after the signature.

You will need to be bilingual. Engineers will tell you what they built, and you will have to translate it into control language that an assessor accepts; assessors will hand back findings, and you will have to translate those into engineering work that actually closes the gap. Compliance professionals who can only do one half of that translation struggle in this role.

WHAT YOU WILL DO
  • Author the package. Write and maintain System Security Plans, control implementation statements, and the supporting artifacts an assessor will actually read.
  • Own the POA&M lifecycle. Open, prioritize, track, and close Plans of Action and Milestones, with realistic milestones and evidence that stands up to review.
  • Drive the ATO to signature. Manage the accreditation timeline, coordinate assessment activities, prepare risk acceptance narratives, and brief the ISSM and Authorizing Official.
  • Work the tooling. Maintain the package in eMASS or XACTA, keeping control status, artifacts, and assessment procedures linked and current.
  • Translate scan output into action. Review ACAS, STIG, and cloud configuration findings, then work with engineers to remediate rather than simply reporting the count.
  • Sustain continuous monitoring. Run the recurring control assessments, configuration change reviews, and reporting cadence that keep an ATO from decaying quietly.
  • Advise early. Get into architecture conversations before the build is finished, so controls are designed in rather than retrofitted.
REQUIRED QUALIFICATIONS
  • Active Secret clearance or higher.
  • U.S. citizenship.
  • Demonstrated ownership of at least one system through a full ATO, from documentation through authorization decision.
  • Hands-on authorship of System Security Plans and control implementation statements, not just review of documents written by others.
  • Working proficiency in eMASS or XACTA.
  • Command of NIST SP 800-53 and the Risk Management Framework lifecycle.
  • POA&M management experience, including milestone development, evidence collection, and closure.
  • Ability to communicate clearly with engineers, ISSOs, ISSMs, and Authorizing Officials.
PREFERRED QUALIFICATIONS
  • Cloud accreditation experience, particularly AWS or AWS GovCloud.
  • Familiarity with the DoD Cloud Computing Security Requirements Guide at IL4, IL5, or IL6, and with CNSSI 1253 categorization.
  • DISA STIG and ACAS experience.
  • CISSP, CISM, CAP, or CGRC certification.
  • Prior ISSO or ISSM appointment on a Federal or Department of Defense system.
  • Experience with compliance as code, where control evidence is generated by automation rather than assembled by hand.
WORKING ENVIRONMENT

The seat is remote or hybrid within the continental United States, with periodic on-site presence for assessment and accreditation activities depending on the supported program.

This role pairs with a Cloud Security Guardrails Engineer, who owns the technical enforcement layer. The split is deliberate: authorization depth and hands-on policy engineering are different skills, and asking one person to do both tends to shortchange whichever half they enjoy less.

About D9tech Resources

D9Tech Resources is a Service-Disabled Veteran-Owned Small Business and SBA 8(a) participant delivering cleared cloud, cybersecurity, network, data, and AI engineering to Federal and Department of Defense customers. Bench engineers are interviewed, verified, and kept ready, so that when a billet opens we place a known quantity instead of starting a search.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Information Assurance Specialist
Sr. Information Assurance Specialist

NR Labs LLC • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
Cloud Security Guardrails Engineer with Security Clearance
Cloud Security Guardrails Engineer with Security Clearance

D9Tech Resources LLC • Arlington (VA)

Hybrid
USD 140,000 - 210,000
ATO Lead — Remote Security Compliance (Secret)
ATO Lead — Remote Security Compliance (Secret)

D9Tech Resources LLC • Arlington (VA)

Hybrid
USD 120,000 - 150,000
Information System Security Officer (ISSO) – TS/SCI
Information System Security Officer (ISSO) – TS/SCI

Strategic Business Systems (SBS) • Herndon (VA)

On-site
USD 140,000 - 190,000
Medical, dental, vision coverage
401(k) retirement plan with company匹配
Paid time off and holidays
+2
Information Assurance Program Lead
Information Assurance Program Lead

118-WW TMG MFG OPS • Dallas (TX)

On-site
USD 120,000 - 180,000
Information Assurance Engineer
Information Assurance Engineer

Agile IT Synergy, LLC • Tampa (FL)

On-site
USD 90,000 - 130,000
Information Assurance Specialist III
Information Assurance Specialist III

onezerollc • Arlington (VA)

Hybrid
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+6
Information Assurance Specialist III
Information Assurance Specialist III

OneZero Solutions • Arlington (VA)

On-site
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+5
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering • Washington

On-site
USD 150,000 - 190,000
11 paid holidays
3 weeks PTO
Company-sponsored health plan
+2
Security Compliance SME
Security Compliance SME

Creative G C • Herndon (VA)

Hybrid
USD 90,000 - 130,000