×
Register Here to Apply for Jobs or Post Jobs. X

Security Assessment & Authorization (SA&A) Lead

Job in Bethesda, Montgomery County, Maryland, 20811, USA
Listing for: Gunnison
Full Time position
Listed on 2026-08-23
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 130000 - 145000 USD Yearly USD 130000.00 145000.00 YEAR
Job Description & How to Apply Below
  • This position is contingent upon a future opening with Gunnison.

Salary: $130,000 - $145,000/year

  • Lead Security Assessment and Authorization (SA&A) activities for NIH CIT enterprise information systems, including on-premises, cloud-based, network, hosting, endpoint, and shared-service environments.
  • Plan, develop, coordinate, review, and maintain Authorization to Operate (ATO) packages in accordance with the NIST Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, FISMA, and applicable HHS, NIH, and federal security requirements.
  • Lead development and maintenance of system authorization artifacts, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), risk assessments, contingency plans, incident response plans, and associated supporting documentation.
  • Write, review, assess, and validate security-control implementation statements against applicable NIST SP 800-53 controls and control enhancements.
  • Conduct security-control assessments, including evidence review, technical validation, stakeholder interviews, and assessment testing; document findings, assess risks, and recommend corrective actions.
  • Create, maintain, track, and update Plans of Action and Milestones (POA&Ms), ensuring findings have clear owners, remediation milestones, risk ratings, status updates, and closure evidence.
  • Prepare Risk Assessment Memoranda and other risk-based decision packages that clearly describe security risks, proposed mitigations, residual risk, and recommended courses of action for management review.
  • Develop and maintain system and program-level risk registers; identify and communicate high-risk conditions, trends, overdue remediation actions, dependencies, and emerging compliance concerns to program and Government leadership.
  • Coordinate and facilitate incident response (IR) and contingency planning (CP) tests, tabletop exercises, and after-action activities; document results, corrective actions, lessons learned, and required updates to security documentation.
  • Review ATO packages for completeness, accuracy, consistency, and readiness before submission to the CISO, CIO, Authorizing Official, or designated approval authority.
  • Conduct assessment entrance and exit meetings with system owners, system administrators, ISSOs, engineers, and other stakeholders; debrief teams on assessment findings, remediation expectations, and next steps.
  • Advise system owners and technical teams on RMF implementation, security-control compliance, risk acceptance, remediation planning, and authorization strategy.
  • Prepare clear, timely assessment reports, compliance dashboards, executive briefings, status reports, and decision memoranda for technical and leadership audiences.
  • Lead and mentor SA&A analysts and assessors; assign and review work, maintain quality standards, and coordinate simultaneous authorization and continuous-monitoring activities across multiple systems.
Description
  • Lead Security Assessment and Authorization (SA&A) activities for NIH CIT enterprise information systems, including on-premises, cloud-based, network, hosting, endpoint, and shared-service environments.
  • Plan, develop, coordinate, review, and maintain Authorization to Operate (ATO) packages in accordance with the NIST Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, FISMA, and applicable HHS, NIH, and federal security requirements.
  • Lead development and maintenance of system authorization artifacts, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), risk assessments, contingency plans, incident response plans, and associated supporting documentation.
  • Write, review, assess, and validate security-control implementation statements against applicable NIST SP 800-53 controls and control enhancements.
  • Conduct security-control assessments, including evidence review, technical validation, stakeholder interviews, and assessment testing; document findings, assess risks, and recommend corrective actions.
  • Create, maintain, track, and update Plans of Action and Milestones (POA&Ms), ensuring findings have clear owners, remediation milestones, risk ratings, status updates, and closure evidence.
  • Prepare Risk Assessment Memoranda and other risk-based decision packages that clearly describe security risks, proposed mitigations, residual risk, and recommended courses of action for management review.
  • Develop and maintain system and program-level risk registers; identify and communicate high-risk conditions, trends, overdue remediation actions, dependencies, and emerging compliance concerns to program and Government leadership.
  • Coordinate and facilitate incident response (IR) and contingency planning (CP) tests, tabletop exercises, and after-action activities; document results, corrective actions, lessons learned, and required updates to security documentation.
  • Review ATO packages for completeness, accuracy, consistency, and readiness before submission to the CISO, CIO,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary