More jobs:
HHS - A&A Subject Matter Expert; SME
Job in
Rockville, Montgomery County, Maryland, 20849, USA
Listed on 2026-02-14
Listing for:
cFocus Software Incorporated
Full Time
position Listed on 2026-02-14
Job specializations:
-
IT/Tech
Cybersecurity, IT Support, Information Security
Job Description & How to Apply Below
Overview
cFocus Software seeks an A&A Subject Matter Expert (SME) to join our program supporting the Department of Health and Human Services (HHS). This position is remote. This position requires the ability to obtain a Public Trust clearance.
Qualifications- Bachelor’s degree in Cybersecurity, Information Technology, or related field.
- Minimum 8–10 years of experience supporting federal RMF and A&A programs.
- Expert knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, and FISMA.
- Extensive experience reviewing and approving ATO and ongoing authorization packages.
- Hands-on experience with eGRC platforms (e.g., RSA Archer).
- Experience briefing senior executives and Authorizing Officials.
- Strong written, analytical, and verbal communication skills.
- Active CAP, CISSP, or CISM (preferred).
- Serve as the enterprise SME for Authorization & Accreditation (A&A) and ongoing authorization activities.
- Oversee and coordinate ATO packages across HRSA to ensure consistency, completeness, and compliance.
- Provide expert guidance on NIST SP 800-37 Rev. 2, FISMA, OMB A-130, and HHS authorization policies.
- Review and validate SSPs, SARs, POA&Ms, Continuous Monitoring Plans, and Risk-Based Decisions (RBDs).
- Ensure annual authorization packages and continuous monitoring deliverables meet HRSA timelines.
- Support Authorizing Officials (AOs) and senior leadership during authorization decision-making.
- Develop and maintain A&A guidance, SOPs, templates, and standard operating procedures.
- Coordinate with ISSOs, SCAs, GRC staff, and system owners to resolve authorization issues.
- Support enterprise-level ATO tracking, dashboards, and reporting metrics.
- Prepare executive briefings and reports on authorization posture, trends, and risks.
- Support audits, OIG reviews, and external data calls related to system authorizations.
- Identify opportunities to streamline authorization processes and improve quality through automation.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×