FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in leading security authorization processes, including RMF and ATO for cloud environments, while effectively managing compliance across Agile teams. Proficient in developing security documentation and maintaining security control frameworks in alignment with federal standards.
Highest-signal resume keywords
RMF To ATO AuthorizationNIST 800-53 Rev. 5 ImplementationSecurity Assessment Report DevelopmentCISSP, CGRC, CISM CertificationFedRAMP Cloud Control Inheritance
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security Authorization Package DevelopmentVulnerability ManagementContinuous Monitoring Lifecycle ManagementSecurity Control Inheritance DefinitionAgile Compliance CoordinationTechnical Writing for Security DocumentationAuthorization Boundary DefinitionCompliance AutomationSoftware Supply Chain SecurityContainerized Workloads Security
Soft Skills
Interpersonal CommunicationLeadership in Security ReviewsCollaboration Across Teams
Tools & Technologies
OSCALEMASSXactaAgile Release TrainsAI-Assisted Development Tools
Certifications & Qualifications
CISSPCGRCCISM
Industry Keywords
FedRAMPGovernment Security ReviewCustomer Responsibility MatrixPublic TrustFAA Security Authorization
Tech Stack
Tools & technologiesCloudCyber SecurityKubernetes
About the role
Key responsibilities & impact- Lead the government network connection and RMF/ATO authorization process for L-CAP workloads on government-provided cloud infrastructure
- Conduct and coordinate security assessments, architecture reviews, control evidence, and assessor activities
- Own and maintain the security authorization package, including architecture briefings, data flow/security boundary diagrams, ports/protocols/services matrices, SBOMs, vulnerability/CVE dispositions, and POA&Ms
- Define and defend security control inheritance across cloud provider, government platform, and Leidos application layers
- Maintain the Customer Responsibility Matrix
- Serve as the primary interface with government security reviewers, ISSOs, assessors, and Authorizing Official staff
- Manage the POA&M and continuous monitoring lifecycle, including findings, risk characterization, remediation milestones, closure evidence, and security status reporting
- Maintain the authorization boundary as architecture evolves and assess security impacts of proposed changes
- Translate requirements into actionable engineering backlog items
- Coordinate cross-ART compliance across four Agile Release Trains to ensure consistent control implementation and evidence quality
- Support FedRAMP and agency-specific authorization requirements across cloud environments
- Coordinate personnel security and facility access eligibility with program security and Talent Acquisition
- Champion an AI-first engineering culture through AI-assisted development, automation, and emerging practices that improve productivity, code quality, testing, and delivery
Requirements
What you’ll need- Bachelor’s degree in Cybersecurity, Computer Science, IT, or related field with 6+ years of relevant cybersecurity, compliance, or security authorization experience, or a Master’s degree with 4+ years
- Additional experience, education and training may be considered in lieu of degree
- Experience leading a federal information system through RMF to ATO or equivalent authorization
- Experience with NIST 800-53 Rev. 5 control implementation and assessment
- Experience developing and defending authorization packages, including SSPs, POA&Ms, Security Assessment Reports, and authorization boundary diagrams
- Experience with FedRAMP cloud control inheritance, Customer Responsibility Matrices, vulnerability management, CVE disposition, and remediation tracking
- Experience working directly with government security reviewers, ISSOs, and/or Authorizing Official staff
- Ability to translate security requirements into actionable engineering backlog items and coordinate compliance across multiple Agile engineering teams
- Strong technical writing skills with experience producing government-facing security documentation
- Ability to obtain and maintain a Public Trust and successfully complete required government background investigations
- U.S. citizenship required, including eligibility for FAA facility and information system access
- Continuous U.S. residency for at least 3 of the previous 5 years
- CISSP, CGRC (formerly CAP), CISM, or equivalent certification strongly preferred
- FAA or aviation-sector security authorization experience preferred
- Experience with continuous ATO (cATO) or ongoing authorization models preferred
- Experience defining authorization boundaries for Kubernetes and containerized workloads preferred
- Familiarity with FedRAMP High and GovCloud inheritance models preferred
- Security authorization experience for safety-critical or real-time operational systems preferred
- Experience with compliance automation and evidence tooling, including OSCAL, eMASS, Xacta, or equivalent preferred
- Knowledge of software supply chain security, including SBOM, artifact signing, and provenance preferred
- Experience with SAFe or large-scale Agile compliance integration preferred
Benefits
Comp & perks- Hybrid work arrangement: 3 days onsite and 2 days working from home for employees within commuting distance
- 100% remote work may be considered for employees outside commuting distance
- Opportunity to work with AI-assisted development, automation, and emerging engineering practices
- Work on mission-critical software supporting national infrastructure
