Senior Security Analyst – ATO / RMF (Active TS/SCI Clearance)

Strategic Business Systems

Chantilly (VA)

On-site

USD 140,000 - 195,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Telework and flexible schedule where
401(k) retirement plan with company 4%
Paid Time Off and holidays
Professional development support for A

Job summary

Strategic Business Systems is seeking a Senior Security Analyst to support ATO/RMF efforts for government and DoD customers. This onsite role in Chantilly, VA requires active TS/SCI clearance and Security+ or higher IAT Level II/III certification.

You will develop security documentation, assess controls, manage POA&Ms, and guide customers through authorization and continuous monitoring. The position emphasizes hands‑on security work, cloud and on‑premises environments, vulnerability management,

Qualifications

  • Hands‑on experience with RMF/ATO processes.
  • Experience creating security documentation for government projects.
  • Ability to translate technical findings into clear remediation guidance.

Responsibilities

  • Lead customers through RMF/ATO lifecycle and security documentation.
  • Develop and maintain ATO packages and authorization artifacts.
  • Explain security controls to technical and leadership audiences.
  • Collaborate with customers and partners to implement security measures.

Skills

Technical writing
Customer meetings
Security documentation
Security best practices

Education

Bachelor's degree preferred

Tools

Tenable Nessus
Checkmarx
Fortify

Job description

Strategic Business Systems

Senior Security Analyst – ATO / RMF (Active TS/SCI Clearance)

Senior Security Analyst ATO / RMF AWS Professional Services

Location: Chantilly, VA
Work Type: 100% Onsite Secure Facility
Employment Type: Full-Time
Citizenship: U.S. Citizenship required
Clearance: Active TS/SCI required; CI Polygraph preferred but not required
Certification: Active Security+ or higher (IAT Level II/III) required

The Opportunity

Strategic Business Systems (SBS) is expanding our cybersecurity team and hiring Senior Security Analysts to support our growing Authority to Operate as a Service (ATOaaS) offering.

SBS developed ATOaaS in collaboration with leading technology companies and DoD/Intelligence Community customers to help accelerate the process of bringing innovative commercial technologies into secure government environments.

This is a hands‑on cybersecurity role supporting technology partners and government customers throughout the Authority to Operate (ATO) and Risk Management Framework (RMF) lifecycle. Youll work directly with customers to understand their technologies, develop security documentation, assess vulnerabilities, implement and document security controls, manage POA&Ms, and help move cloud‑based solutions successfully through authorization.

The goal is straightforward: help technology providers navigate the government security authorization process faster while maintaining the security and compliance required for mission environments.

If you have experience developing ATO packages, understand RMF, and enjoy working directly with customers to solve cybersecurity and compliance challenges, this is a strong fit.

What Youll Be Doing
  • Support customers through the complete ATO and RMF lifecycle
  • Develop and maintain ATO security packages and authorization documentation
  • Write clear technical documentation describing how systems are configured, secured, and operated
  • Work across the RMF lifecycle, including Categorize, Select, Implement, Assess, Authorize, and Monitor
  • Assess security controls against NIST 800-53 requirements
  • Analyze STIG and SCAP requirements and document compliance
  • Review vulnerability scans and identify security weaknesses within customer environments
  • Interpret results from tools such as Tenable Nessus, Checkmarx, and Fortify
  • Develop, manage, and update Plans of Action & Milestones (POA&Ms)
  • Track vulnerabilities through remediation, mitigation, or risk acceptance
  • Identify and help customers remediate open‑day vulnerabilities
  • Evaluate configuration changes and their impact on the security posture of enterprise cloud solutions
  • Recommend mitigating controls and security countermeasures
  • Support continuous monitoring following authorization
  • Maintain security documentation as customer environments and requirements evolve
  • Explain security‑control inheritance models and associated resources
  • Prepare documentation for system audits and vulnerability assessments
  • Communicate cybersecurity risk and remediation recommendations to technical teams and senior leadership
Customer & Technical Delivery
  • Lead technical discussions with customers and technology partners
  • Understand customer systems, architectures, and business requirements
  • Translate technical environments into appropriate security controls and authorization requirements
  • Advise customers on security best practices and required remediation
  • Identify technical and cybersecurity risks and recommend mitigation strategies
  • Participate in project planning and identify risks, dependencies, and deliverables
  • Develop project artifacts and support Work Breakdown Structures (WBS)
  • Communicate project status, risks, and technical requirements to project leadership
  • Provide guidance and technical leadership to customers and less‑experienced security staff
What Were Looking For
ATO / RMF Experience
  • Hands‑on experience supporting and/or managing ATO packages for cloud‑based products
  • Experience supporting solutions used by U.S. government agencies and/or military organizations
  • Strong experience with ATO writing, security documentation, and package development
  • Hands‑on knowledge of the Risk Management Framework (RMF)
  • Understanding of all RMF lifecycle steps
  • Experience assessing security controls against NIST 800-53
  • Experience developing and managing POA&Ms
  • Ability to understand and explain security‑control inheritance
Vulnerability & Compliance Management
  • Experience identifying and mitigating open‑day vulnerabilities
  • Experience reviewing and interpreting vulnerability scans
  • Knowledge of STIGs and SCAP
  • Experience with vulnerability and application-security tools such as Tenable Nessus, Checkmarx, Fortify, or similar platforms
  • Ability to recommend appropriate countermeasures and mitigating controls
  • Experience supporting continuous monitoring and compliance reporting
Cloud Security
  • Experience assessing the security posture of cloud‑based environments and products
  • Understanding of cloud security controls, configurations, and compliance requirements
  • Ability to evaluate configuration changes and determine their potential security impact
  • Familiarity with firewalls, network security, and intrusion detection systems (IDS) in cloud environments is preferred
Customer-Facing Skills
  • Strong technical writing and documentation skills
  • Ability to explain cybersecurity risks and requirements to both technical and non‑technical stakeholders
  • Comfortable leading customer meetings and technical discussions
  • Ability to translate cybersecurity findings into actionable remediation recommendations
  • Self‑motivated and comfortable working within a small, agile technical team
Security & Certifications
  • Active TS/SCI clearance required
  • CI Polygraph preferred but not required
  • Active Security+ or higher IAT Level II/III certification required
  • CISSP or similar information security certification preferred
  • Cloud security or platform certifications are a plus
  • Bachelors degree preferred
Why SBS

SBS is a trusted technology and cybersecurity partner supporting federal agencies, the Department of Defense, Intelligence Community, and leading commercial technology companies.

Our ATOaaS offering is designed to solve a significant challenge for technology providers: navigating the complex security and authorization requirements necessary to bring commercial technologies into government environments.

Youll be part of a team that:

  • Works directly with innovative technology companies and government customers
  • Helps accelerate the delivery of new technologies into DoD and Intelligence Community environments
  • Works across cloud security, ATO, RMF, vulnerability management, and continuous monitoring
  • Provides hands‑on guidance throughout the authorization lifecycle
  • Has direct impact on getting new technology into the hands of government and military users

COMPENSATION & BENEFITS

SBS offers a comprehensive total‑rewards package, including a market competitive salary along with:

  • Comprehensive medical, dental, and vision coverage; HSA‑eligible plan options available

  • 401(k) retirement plan with company match (vesting schedule per Plan Document)

  • Paid Time Off, federal holidays, and floating holiday for personal observance

  • Annual professional development support for AWS certifications, training, and conferences

  • Employee referral program where applicable and documented by program policy

  • Life, AD&D, and short‑/ long‑term disability insurance

  • Telework and flexible‑schedule support where mission and contract permit

  • Mission‑focused federal contractor supporting national‑security customers

Target Salary Range: $140,000-195,000. This range reflects the anticipated compensation for this role. Actual salary will be based on a combination of factors, including the positions scope and level of responsibility, the candidates relevant experience, education, technical expertise, skills and qualifications, geographic location, and applicable business or contractual requirements.

Equal Employment Opportunity
SBS is an equal opportunity employer; all qualified applicants will receive consideration for employment without regard to age, gender, gender identity, sex, sexual orientation, color, race, creed, national origin, religion, marital status, parental status, citizenship status, ancestry, physical or mental disability, genetic information, veteran status, military status, or any other classification protected by federal, state, or local laws.

Accommodations
If you need an accommodation while seeking employment with SBS, please email hr@sbsplanet.com . Accommodations are made on a case‑by‑case basis.

No Unsolicited Agency Referrals
SBS does not accept unsolicited resumes from staffing agencies. Any resumes submitted without a prior agreement will be considered the property of SBS.

Equal employment opportunity, including veterans and individuals with disabilities.

PI286619079

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Officer (ISSO) – TS/SCI
Information System Security Officer (ISSO) – TS/SCI

Strategic Business Systems (SBS) • Arlington (VA)

On-site
USD 140,000 - 190,000
Telework options
401(k) with match
Paid time off & holidays
+2
Information System Security Officer (ISSO) – TS/SCI
Information System Security Officer (ISSO) – TS/SCI

Strategic Business Systems (SBS) • Jessup (MD)

On-site
USD 120,000 - 190,000
Medical, dental, vision coverage
401(k) with company match
Paid time off & holidays
+1
Information System Security Officer (ISSO) TS/SCI
Information System Security Officer (ISSO) TS/SCI

Strategic Business Systems • Jessup (MD)

On-site
USD 130,000 - 160,000
Telework and flexible schedules
Comprehensive benefits package
401(k) retirement plan with company 1:
+5
Information System Security Officer (ISSO) – TS/SCI
Information System Security Officer (ISSO) – TS/SCI

Strategic Business Systems (SBS) • Herndon (VA)

On-site
USD 140,000 - 190,000
Medical, dental, vision coverage
401(k) retirement plan with company匹配
Paid time off and holidays
+2
AWS DevOps Engineer (Intermediate)
AWS DevOps Engineer (Intermediate)

Strategic Business Systems, Inc (SBS) • Chantilly (VA)

On-site
USD 90,000 - 125,000
Medical, dental, vision
401(k) with company match
Paid time off
+2
AWS DevOps / Agentic SRE Engineer (Active TS/SCI Clearance)
AWS DevOps / Agentic SRE Engineer (Active TS/SCI Clearance)

Strategic Business Systems, Inc (SBS) • Chantilly (VA), Northern (KY)

Hybrid
USD 180,000 - 270,000
Telework where mission permits
Professional development support for A
Senior AWS Cloud Architect (Active TS/SCI )
Senior AWS Cloud Architect (Active TS/SCI )

Strategic Business Systems, Inc (SBS) • Chantilly (VA)

On-site
USD 150,000 - 210,000
Medical, dental, and vision coverage
401(k) with company match
Paid time off and holidays
+2
AWS Senior Software Developer (Active TS/SCI Preferred)
AWS Senior Software Developer (Active TS/SCI Preferred)

Strategic Business Systems (SBS) • Chantilly (VA)

Hybrid
USD 100,000 - 130,000
Comprehensive medical, dental, and vision coverage
401(k) retirement plan with company match
Annual professional development support for AWS certifications
AWS Senior Software Developer (Active TS/SCI Preferred)
AWS Senior Software Developer (Active TS/SCI Preferred)

Strategic Business Systems • Fort Meade (MD)

On-site
USD 100,000 - 130,000
Comprehensive medical, dental, and vision coverage
401(k) retirement plan with company match
Paid Time Off and floating holiday
+2
AWS DevOps / Agentic SRE Engineer (Active TS/SCI Clearance)
AWS DevOps / Agentic SRE Engineer (Active TS/SCI Clearance)

Strategic Business Systems • Chantilly (VA)

On-site
USD 180,000 - 270,000
Comprehensive medical, dental, and V/V
401(k) with company match
Paid Time Off and holidays
+1