Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Assessment & Authorization (SA&A) Lead

$130k - $145k

Gunnison Consulting Group, Inc.

Job Description

Job Description

Description:

* This position is contingent upon a future opening with Gunnison.

Salary: $130,000 - $145,000/year

Work location : Hybrid, 2-3 days per week on-site in Bethesda, MD.

  • Lead Security Assessment and Authorization (SA&A) activities for NIH CIT enterprise information systems, including on-premises, cloud-based, network, hosting, endpoint, and shared-service environments.
  • Plan, develop, coordinate, review, and maintain Authorization to Operate (ATO) packages in accordance with the NIST Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, FISMA, and applicable HHS, NIH, and federal security requirements.
  • Lead development and maintenance of system authorization artifacts, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), risk assessments, contingency plans, incident response plans, and associated supporting documentation.
  • Write, review, assess, and validate security-control implementation statements against applicable NIST SP 800-53 controls and control enhancements.
  • Conduct security-control assessments, including evidence review, technical validation, stakeholder interviews, and assessment testing; document findings, assess risks, and recommend corrective actions.
  • Create, maintain, track, and update Plans of Action and Milestones (POA&Ms), ensuring findings have clear owners, remediation milestones, risk ratings, status updates, and closure evidence.
  • Prepare Risk Assessment Memoranda and other risk-based decision packages that clearly describe security risks, proposed mitigations, residual risk, and recommended courses of action for management review.
  • Develop and maintain system and program-level risk registers; identify and communicate high-risk conditions, trends, overdue remediation actions, dependencies, and emerging compliance concerns to program and Government leadership.
  • Coordinate and facilitate incident response (IR) and contingency planning (CP) tests, tabletop exercises, and after-action activities; document results, corrective actions, lessons learned, and required updates to security documentation.
  • Review ATO packages for completeness, accuracy, consistency, and readiness before submission to the CISO, CIO, Authorizing Official, or designated approval authority.
  • Conduct assessment entrance and exit meetings with system owners, system administrators, ISSOs, engineers, and other stakeholders; debrief teams on assessment findings, remediation expectations, and next steps.
  • Advise system owners and technical teams on RMF implementation, security-control compliance, risk acceptance, remediation planning, and authorization strategy.
  • Prepare clear, timely assessment reports, compliance dashboards, executive briefings, status reports, and decision memoranda for technical and leadership audiences.
  • Lead and mentor SA&A analysts and assessors; assign and review work, maintain quality standards, and coordinate simultaneous authorization and continuous-monitoring activities across multiple systems.
Requirements:

Minimum of three (3) to five (5) years of progressively responsible experience in security assessment and authorization, RMF, information-system security, cybersecurity compliance, or a related discipline.

Candidates must demonstrate experience in:

  • Developing, updating, and submitting ATO packages for enterprise systems, including cloud-hosted or hybrid environments.
  • Applying the NIST RMF lifecycle under NIST SP 800-37.
  • Assessing and documenting implementation of NIST SP 800-53 security controls and control enhancements.
  • Creating and maintaining SSPs, SARs, SAPs, POA&Ms, risk assessments, risk registers, and other authorization artifacts.
  • Planning and conducting security-control assessments, evidence reviews, stakeholder interviews, technical validations, and remediation verification.
  • Facilitating IR and CP tests or tabletop exercises and documenting outcomes and corrective actions.
  • Preparing risk-based decision packages, including risk assessment memoranda and risk acceptance/mitigation recommendations.
  • Reviewing authorization packages before senior leadership submission and briefing assessment findings to system owners and management.
  • Supporting continuous-monitoring, vulnerability-management, configuration-management, and compliance-reporting processes.
  • Bachelor’s degree from an accredited college or university in cybersecurity, information assurance, information systems, computer science, computer engineering, network engineering, systems engineering, or a closely related technical discipline.
  • Certified Information Systems Security Professional (CISSP), current and active
  • Certified Authorization Professional (CAP), current and active

Clearance Requirement: Ability to obtain and maintain a Public Trust.

Desired Qualifications:

  • Master’s degree in cybersecurity, information assurance, information systems, computer science, engineering, public administration, business administration, or a related discipline.
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Certified Cloud Security Professional (CCSP)
  • CompTIA Security+, CySA+, CASP+, or equivalent
  • Project Management Professional (PMP)
  • ITIL Foundation
  • AWS Certified Security – Specialty
  • Microsoft Certified: Azure Security Engineer Associate
  • Google Professional Cloud Security Engineer
  • GIAC certifications relevant to governance, incident response, audit, cloud security, or risk management
  • Federal RMF, FISMA, NIST, cloud-security, or security-assessment training
  • Certified in Risk and Information Systems Control (CRISC)
  • ISO/IEC 27001 Lead Implementer or Lead Auditor

The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements.
Gunnison Consulting Group's total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include:

  • 3 weeks of Personal Leave your first year
  • 11 paid Holidays each year
  • 5 days of Flexible Time Off each year for approved training or certifications (self-study is ineligible)
  • 401(k) company match at 50% up to 10% of your salary
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • Public Transportation Subsidies
  • Certifications and Training Allowance - Up to $5,000/year!

Why Join Gunnison?

  • Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation.
  • Quality is our top priority.
  • Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer.
  • There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow.
  • We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding.
  • We hire for careers at Gunnison, not to fill a position.

Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time.
In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects . By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could , the company has thrived for over 25 years.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Assessment & Authorization (SA&A) Lead in Bethesda, MD vacancy
  •  ...services and solutions in: National Security Programs Professional,...  ...Contingent Position Title: Security Assessment Lead Location:Washington, DC Clearance...  ...driving force for completing all Security Authorization (SA), OA, Preliminary Risk Assessment, and... 
    Suggested
    Full time
    For contractors

    gTANGIBLE Corporation

    Washington DC
    more than 2 months ago
  • $135k - $165k

    SkyePoint Decisions is a leading Cybersecurity Architecture and...  ...effectively - anytime, anywhere, securely. We combine technical...  ...Decisions is seeking a RMF / Assessment & Authentication (A&A) Team...  ...systems achieve and maintain Authorization to Operate (ATO) status in accordance... 
    Suggested
    Contract work

    SkyePoint Decisions, Inc.

    Bethesda, MD
    4 days ago
  • $135k - $165k

    RMF/Assessment & Authorization Team Lead Bethesda, Maryland, United States SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering...  ...most efficiently and effectively - anytime, anywhere, securely. We combine technical expertise, mission awareness, and... 
    Suggested
    Contract work
    For contractors
    For subcontractor
    Work at office

    SkyePoint Decisions

    Bethesda, MD
    4 days ago
  •  ...Security Assessment Lead OCH Technologies is seeking a Security Assessment Lead to act as the technical authority for all independent risk assessments, vulnerability assessments, and analyses of alternatives conducted under this contract. The candidate will lead assessment... 
    Suggested
    Contract work
    Temporary work
    For contractors
    Local area

    OCH Technologies LLC

    Washington DC
    2 days ago
  •  ...Security Assessment Lead Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Security Assessment Lead to support KITS and our government customer in Washington, DC. This position is for a Future New Business Opportunity. The customer may need... 
    Suggested
    Local area
    Flexible hours

    Koniag

    Washington DC
    12 hours ago
  •  ...growing government contractor providing leading-edge support to federal customers, with...  ...particular focus on Defense and National Security mission sets. We leverage more than 17 years...  ...Barbaricum is seeking an experienced Assessment Lead Subject Matter Expert to lead... 
    Contract work
    For contractors
    Work at office

    Barbaricum

    Washington DC
    2 days ago
  • A national security solutions firm based in Virginia is hiring an Authorization and Compliance Lead to oversee cybersecurity controls and ensure compliance with federal regulations. Candidates must have a relevant bachelor's degree or equivalent experience, along with... 

    Core One

    Mc Lean, VA
    4 days ago
  •  ...government’s most critical national security and defense priorities, helping protect...  ...mission begins. Ardent is seeking a Lead Compliance Specialist to join our...  ...compliance efforts, with a focus on Security Assessment and Authorization (SA&A) activities. This role will lead... 
    Local area
    Flexible hours

    Ardent MC

    Rockville, MD
    2 days ago
  •  ...seeking a driven, results-oriented FSO / Security Lead to own all aspects of personnel,...  ...with cognizant security and accrediting authorities.Develop and deliver security training...  ...and conduct incumbent capture security assessments at existing program sites to accelerate... 
    Full time

    LMI

    Washington DC
    4 days ago
  • $150k - $180k

     ...hiring for a Vulnerability Management Team Lead to provide support to a Federal...  ...leading critical support for the Information Security’s vulnerability management program (VM)...  ...vulnerabilities.Manage performance of risk‐based assessments of current and emerging information... 
    Contract work
    Work experience placement
    Currently hiring
    Work at office
    Remote work

    Govcio

    Bethesda, MD
    2 days ago
  • $127.79k - $212.99k

     ...seeking a Enterprise Hosting Lead to join our team in Rockville...  ...hosting environments are reliable, secure, and efficient, supporting...  ...processes.Proven ability to assess end-to-end solution...  ...and Security Assessment and Authorization activities.NTT DATA provides... 
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA

    Rockville, MD
    4 days ago
  • $91.3k - $184.9k

     ...clients across defense, national security, public safety, civilian, and...  ...Who you are: The Security Lead is responsible for overseeing complex risk assessments, security governance, and compliance...  .... Oversee FedRAMP and ATO (Authority to Operate) processes.... 
    Live in
    Work at office
    Local area

    Accenture

    Washington DC
    22 hours ago
  • $114.1k - $268.18k

     ...class training facility, and leading market tools, we help our...  ...seeking a Lead Specialist, Cloud Security to join our Managed Services...  ..., policies, and risk assessments across cloud platforms.Oversee...  ...as neededApplicants must be authorized to work in the U.S. without... 
    H1b
    Local area

    KPMG

    McLean, VA
    1 day ago
  •  ...change and growth.As a Senior Lead Cybersecurity Architect at...  ...stakeholders to help teams build secure, scalable solutions that keep...  ..., and controls, and lead assessments of new technologies using established...  ...for companies, capable of authorizing transactions across global... 
    For contractors

    JP Morgan Chase

    Washington DC
    3 days ago
  • $90.3k - $189.6k

    Job Title: Lead Senior Information System Security OfficerJob Category: Information TechnologyTime Type: Full...  ...Framework (RMF) activities for Authority to Operate (ATO) decisions and ensure...  ...and implementation, self-assessments, POA&M development, and continuous... 
    Contract work
    Work experience placement
    Work at office
    Flexible hours

    CACI International

    Washington DC
    1 day ago
  •  ...compliance teams on contract reviews and risk assessments.Analysis & Cost ControlMonitors market...  ...are uniquely related to our role as a securities regulator. FINRA employees are required...  ...who lives with the employee) and to authorize their broker-dealers to provide FINRA... 
    Full time
    Contract work
    Temporary work
    For contractors
    For subcontractor
    Local area
    Immediate start

    Financial Industry Regulatory Authority

    Rockville, MD
    5 days ago
  • The Lead Product Manager - Surveillance owns the vision and strategy...  ...the right level of quality, assesses alternatives to resolve,...  ...uniquely related to our role as a securities regulator. FINRA employees...  ...with the employee) and to authorize their broker-dealers to provide... 
    Full time
    Temporary work
    For contractors
    Work experience placement
    For subcontractor
    Local area
    Immediate start

    Financial Industry Regulatory Authority

    Rockville, MD
    2 days ago
  • $253k - $336k

     ...of the most urgent national security needs. By working hand-in-hand...  ...THE JOBAnduril is seeking a Lead Scientist to help shape and grow...  ...relying solely on direct authority.Must hold an active U.S. TS/SCI...  ...due diligence screening and assessing potential risks as part of your... 
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Washington DC
    4 days ago
  •  ...Security And Intelligence Career Field Position Lead a patrol team of three or more officers, including Department of Army Civilian Police (DACP), Military...  ...possible civil action due to improper exercises of authority or injudicious use of force in the apprehension or... 
    Shift work
    Rotating shift
    Weekend work
    Afternoon shift

    US Army

    Silver Spring, MD
    3 days ago
  • The Lead IAM Engineer/Architect leads enterprise IAM initiatives...  ...workflows and partners with security and compliance teams on governance...  ..., including: Configuration Assessment, Log Aggregation, Integrity...  ...with the employee) and to authorize their broker-dealers to provide... 
    Full time
    Temporary work
    For contractors
    Work experience placement
    For subcontractor
    Local area
    Immediate start

    Financial Industry Regulatory Authority

    Rockville, MD
    2 days ago
  •  ...Summary: As a key part of the Security Team, the Security Preconstruction Lead serves as a senior preconstruction...  .... Prime hiring managers are not authorized to review or accept resume...  ...applications, analyzing resumes, or assessing responses and identifying potential... 
    Temporary work
    Work at office
    Local area

    Prime Electric

    Washington DC
    2 days ago
  • $120k - $145k

     ...federal agencies. We are seeking a Security / ATO Compliance Lead to be responsible for overseeing cybersecurity...  ..., continuous monitoring, and Authority-to-Operate (ATO) lifecycle support...  ...review vulnerability scan outputs and assessment findings. Track remediation... 
    Permanent employment
    Contract work
    Temporary work
    Work at office
    Remote work

    i360technologies, Inc.

    Gaithersburg, MD
    2 days ago
  •  ...and solutions in: National Security Programs Professional,...  ...Title: Cybersecurity Policy Lead Location:Washington, DC...  ...in providing inputs for risk assessment memos Meet with Subject Matter...  ...certifications: Certified Authorization Professional (CAP),... 
    Full time
    For contractors
    Work at office

    gTANGIBLE Corporation

    Washington DC
    more than 2 months ago
  •  ...Imagineeer is seeking a Lead Data and Architecture professional...  ...serve as the senior technical authority responsible for designing, governing, and implementing secure, compliant, enterprise-scale data...  ...explainability, bias assessment, and operational validation... 
    Local area
    Work from home
    Flexible hours

    IMAGINEEER LLC

    Arlington, VA
    2 days ago
  •  ...Position Summary Owns Marketplace security compliance posture and the MARS-E...  ...managing risk/exception processes, and leading audit readiness. The role aligns to...  ...selection, implementation oversight, assessment readiness, authorization package hygiene, and continuous... 
    Contract work
    Temporary work
    For contractors
    Flexible hours

    PRECISE SOFTWARE SOLUTIONS INCORPORATED

    Rockville, MD
    2 days ago
  • $165k - $185k

     ...designed to modernize, automate, secure, protect, and enhance the...  ...seeking an experienced RMF/A&A Lead to support our federal...  ...serves as the senior technical authority for RMF and A&A activities supporting...  ...annual security control assessments and prepare evidence for the... 

    A-TEK Inc.

    Rockville, MD
    2 days ago
  •  ...platform designed to streamline assessment preparation, evidence...  ...technically skilled CMMC Assessment Lead to oversee the planning,...  ...CMMC assessments conducted by authorized C3PAOs. This role is critical...  ...), assessment logistics, and secure evidence transfer processes... 
    Full time
    For contractors
    Remote work

    Paragone Solutions, Inc.

    McLean, VA
    more than 2 months ago
  •  ...day. Job Description Team Leader – Cyber Security Overview GDIT is seeking a Security Team Lead as part of the larger National Institutes of Health...  ...management, compliance reviews, and risk assessments. Ensure team adherence to NIH, HHS, and federal... 
    Work from home
    Flexible hours

    General Dynamics Information Technology

    Bethesda, MD
    22 days ago
  •  ...Description Job Description Cybersecurity Lead - Joint Base Anacostia-Bolling,...  ...Cybersecurity Lead is the senior authority on all aspects of security architecture, compliance, and risk...  ...DevSecOps framework.Lead vulnerability assessment activities; track, prioritize, and... 
    Full time

    Synertex LLC

    Washington DC
    2 days ago
  •  ...and solutions in: National Security Programs Professional,...  ...Position Title: System Compliance Lead Location:Washington, DC...  ...using the appropriate processes, Authority to Operate (ATO) expirations,...  ...templates for Memos, Risk Assessments, Disposal Packages, etc. to standardize... 
    Full time
    For contractors

    gTANGIBLE Corporation

    Washington DC
    more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Assessment & Authorization (SA&A) Lead. Be the first to apply!