Lead authorship of the System Security Plan (SSP) from first draft to approval, written in clear, testable language that supports an ATO decision
Perform security categorization under FIPS 199 and derive baseline requirements from FIPS 200 and NIST SP 800-53 Rev 5 with appropriate tailoring
Build a complete and coherent authorization package that explains the system boundary, users, data types and flows, risks, and how controls are met
Translate technical inputs into specific control narratives that can be verified by assessors and traced to actual configurations
Collect, verify, and index evidence for every control, linking statements to diagrams, configurations, tickets, and scan results
Record, organize, and quality-check all artifacts in CSAM with consistent naming, metadata, and cross-references ready for audit
Keep documentation current as the system changes by capturing deltas promptly and updating only the affected sections
Plan and run readiness reviews before assessments, close gaps, and prepare concise responses to findings
Manage POA&M items through closure with clear actions, owners, and target dates
Create and maintain templates and checklists that reduce review time and improve consistency across systems
Coordinate with the ISSO, assessors, the Authorizing Official, engineers, and vendors to keep schedules and deliverables on track
When cloud services are used, align with applicable FedRAMP baselines and document inherited controls clearly
Communicate risks and decisions in straightforward terms so leadership can approve with confidence and reviewers can verify quickly
Support proposal efforts as needed, including resume formatting, skills alignment summaries, participation in meetings, and contributing subject matter expertise
Handle Controlled Unclassified Information (CUI) and adhere to applicable safeguarding and compliance requirements
Requirements
3 years of experience supporting federal government compliance
Demonstrated experience producing federal FISMA RMF authorization documentation that resulted in an ATO or successful assessments
Strong track record authoring SSP and POA&M with precise control statements and accurate mapping to evidence
Working knowledge of NIST SP 800-37, NIST SP 800-53 Rev 5, NIST SP 800-53A, NIST SP 800-18, NIST SP 800-30, FIPS 199, and FIPS 200
Ability to elicit engineering details and turn them into assessor-ready narratives with clear boundaries and data flows
Hands-on experience managing authorization packages in CSAM with disciplined organization and traceability
Familiarity with common assessment evidence and scanner outputs and how they map to NIST 800-53 controls and POA&M entries
Clear, concise writing, strong attention to detail, version control discipline, and the ability to drive edits and approvals across teams
Willing to commute to Washington, D.C. 4 days a week
Eligible to obtain a Public Trust
Applicants must be U.S. citizens and currently authorized to work in the United States on a full-time basis (no sponsorship)
Data Analyst joining Ford's team to focus on security technologies and data integration. Responsible for improving data operations across global infrastructure and complex requests.
Digital Product Manager at Ford creating connected vehicle experiences through integrated hardware and software solutions. Collaborating with teams to enhance customer experience through new digital products.
Cybersecurity Engineer implementing Zero Trust Reference Architecture solutions at Mythics. Deploying and maintaining Forescout platform within secure environments.
Security Governance Manager at WEBTOON responsible for IT and Security governance framework. Collaborating with Legal, Product, and Engineering teams in Los Angeles headquarters.
Manager of Cybersecurity leading the company's cybersecurity initiatives at Commonwealth Fusion Systems. Responsible for security policies and team management to protect information assets from cyber threats.
Principal Cloud Operations Developer at AVEVA enhancing Cloud security and leading deployment process improvements. Collaborating with development teams to ensure operational security, stability and scalability.
Responsable cybersécurité gérant la sécurité informatique de l'entreprise. Évaluant la conformité des systèmes d'information et pilotant la feuille de route cybersécurité.
Information Security Officer ensuring legal and cybersecurity compliance across IoT product development at Daikin. Supporting development teams and managing security awareness training.
Security employee monitoring site safety at Newell Brands, ensuring compliance with safety protocols. Supports services in emergency response and monitors site safety continually.
Cybersecurity Intern assisting the Cyber GRC team and Project Manager at HF Sinclair. Gaining hands - on experience in Security Operations and Cyber Risk Management during the summer of 2026.