Lead comprehensive Assessment and Authorization (A&A) activities for DHS Intelligence Enterprise information systems operating in Top Secret/Sensitive Compartmented Information (TS/SCI), Secret, and Unclassified environments.
Conduct security assessments for enterprise systems hosted in: On-premises data centers DHS DICE Commercial Cloud Enterprise (C2E) Intelligence Community (IC) Cloud AWS GovCloud Hybrid cloud environments Cross Domain Solution (CDS) environments CONUS and OCONUS C-LAN extension sites
On-premises data centers
DHS DICE
Commercial Cloud Enterprise (C2E)
Intelligence Community (IC) Cloud
AWS GovCloud
Hybrid cloud environments
Cross Domain Solution (CDS) environments
CONUS and OCONUS C-LAN extension sites
Lead project discovery sessions, kickoff meetings, and stakeholder engagements for new system authorizations, reauthorizations, and major system changes.
Assess the implementation and effectiveness of NIST security controls and document findings within the Security Assessment Report (SAR) and Governance, Risk, and Compliance (GRC) platform.
Identify security control deficiencies, vulnerabilities, and compliance gaps; provide technical recommendations to reduce organizational risk.
Validate the accuracy and completeness of Plans of Action and Milestones (POA&Ms), ensuring corrective actions align with identified assessment findings.
Monitor remediation activities and verify completion of corrective actions before recommending authorization decisions.
Develop and prepare complete Authorization and Assessment packages, including: Authorization to Operate (ATO) Authorization to Connect (ATC) Interim Authorization to Test (IATT) Security Assessment Reports (SARs) Risk Recommendation Memoranda Risk Management Matrices Security Assessment Plans (SAPs) Project kickoff memoranda System Owner acknowledgment letters
Authorization to Operate (ATO)
Authorization to Connect (ATC)
Interim Authorization to Test (IATT)
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Conduct technical reviews of System Security Plans (SSPs), Contingency Plans, Configuration Management Plans, and supporting RMF documentation.
Maintain and update Assessment and Authorization Standard Operating Procedures (SOPs) for all DHS I&A enclaves, ensuring annual review and compliance with evolving Federal and Intelligence Community requirements.
Participate in Office of Inspector General (OIG), Federal Information Security Modernization Act (FISMA), and Intelligence Community Oversight Program (ICOP) audits, inspections, and cybersecurity assessments.
Represent the program during DHS and Intelligence Community cybersecurity working groups and technical review boards.
Research emerging technologies, cybersecurity standards, and automation opportunities to improve A&A efficiency and support ongoing authorization initiatives.
Prepare executive briefings, risk summaries, technical presentations, and decision support materials for the DHS I&A CISO, Government leadership, and Authorizing Officials.
Mentor junior cybersecurity personnel and provide technical guidance on RMF implementation, security control assessments, and authorization processes.
Minimum Qualifications
Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance with SAP eligibility .
Minimum 10 years of experience in information security, cybersecurity risk management, or Assessment and Authorization (A&A), including demonstrated experience in: Assessment and Authorization (A&A) Federal Information Security Modernization Act (FISMA) compliance Intelligence Community cybersecurity policy Continuous Monitoring (ConMon) Cross Domain Solutions (CDS) Secure cloud and hybrid cloud environments
Assessment and Authorization (A&A)
Federal Information Security Modernization Act (FISMA) compliance
Intelligence Community cybersecurity policy
Continuous Monitoring (ConMon)
Cross Domain Solutions (CDS)
Secure cloud and hybrid cloud environments
Current Certified Information Security Manager (CISM) , Certified Authorization Professional (CAP) , or comparable Governance, Risk, and Compliance (GRC) certification.
Certified Information Systems Security Professional (CISSP) certification is highly desirable.