Assessment & Authorization (A&A) Lead
Intellect Solutions LLC
SUMMARY We are seeking an experienced Assessment and Authorization (A&A) Lead to oversee cybersecurity assessment, authorization, and continuous monitoring activities for federal information systems. The successful candidate will possess strong knowledge of the NIST Risk Management Framework (RMF), federal security requirements, and the complete Authorization to Operate (ATO) lifecycle. This position will lead and manage a team of approximately five to eight Security Control Assessors, Information System Security Officers (ISSOs), and other cybersecurity professionals. The A&A Lead will be responsible for ensuring that security authorization packages are accurate, complete, compliant, and delivered according to established schedules. Key Responsibilities Lead the end-to-end A&A and ATO process for federal information systems. Manage and mentor a team of five to eight Security Control Assessors and ISSOs. Develop and maintain integrated ATO schedules, milestones, priorities, and resource assignments. Coordinate security authorization activities with system owners, technical teams, ISSOs, assessors, authorizing officials, and other stakeholders. Apply the NIST Risk Management Framework throughout the system development and authorization lifecycle. Review and validate security authorization documentation, including: System Security Plans Security Assessment Plans Security Assessment Reports Plans of Action and Milestones Risk assessments Contingency plans Continuous monitoring plans Security control implementation evidence Oversee security control assessments and ensure findings are clearly documented, supported by evidence, and assigned appropriate risk ratings. Evaluate system vulnerabilities, control deficiencies, and residual risks to support authorization decisions. Monitor remediation activities and ensure POA&M items are properly documented, tracked, updated, and closed. Conduct quality assurance reviews of A&A packages before submission to the Authorizing Official. Identify risks, schedule delays, documentation gaps, and resource constraints and communicate them to program leadership. Establish standardized A&A procedures, templates, checklists, and quality-control processes. Facilitate status meetings, risk-review sessions, and authorization-readiness reviews. Support continuous monitoring, annual assessments, significant-change reviews, and authorization renewals. Prepare executive-level dashboards, metrics, and reports describing ATO status, risks, findings, and remediation progress. Provide guidance to system teams on federal cybersecurity policies, control implementation, and compliance expectations. Promote accountability, collaboration, and consistent performance across the A&A team. Required Qualifications Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related discipline. At least eight years of cybersecurity, information assurance, or information system security experience. At least five years of direct experience supporting federal A&A, ATO, or NIST RMF activities. Demonstrated experience managing or leading teams of Security Control Assessors, ISSOs, or cybersecurity analysts. Strong knowledge of: NIST Risk Management Framework
NIST SP 800-37
NIST SP 800-53
NIST SP 800-53A
NIST SP 800-30
FISMA requirements Federal continuous monitoring practices Experience reviewing complex security authorization packages and evaluating security control evidence. Strong understanding of security risk management, vulnerability management, POA&M management, and continuous monitoring. Ability to manage multiple systems and authorization activities simultaneously. Strong leadership, analytical, organizational, and problem-solving skills. Excellent written and verbal communication skills, including the ability to communicate technical risks to executive and nontechnical stakeholders. Ability to work effectively with government leadership, system owners, engineers, cybersecurity teams, and third-party assessors. Required Certification Candidates must hold at least one of the following active certifications: Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) Preferred Qualifications Experience supporting cybersecurity programs within NIH, HHS, or another federal civilian agency. Experience with federal governance, risk, and compliance platforms such as CSAM, JCAM, ServiceNow GRC, or similar tools. Experience managing a portfolio of systems with concurrent ATO deadlines. Familiarity with cloud security requirements, including FedRAMP and NIST controls for AWS, Microsoft Azure, or other cloud environments. Experience developing A&A standard operating procedures, playbooks, templates, and performance metrics. Additional certifications such as CAP/CGRC, CRISC, CCSP, PMP, or Security+. Experience supporting high-impact or mission-critical federal information systems. Leadership Expectations The A&A Lead must be a hands-on leader who can establish priorities, assign responsibilities, remove obstacles, coach team members, and maintain high-quality deliverables. The individual must be comfortable engaging directly with senior government stakeholders, presenting authorization risks, and recommending practical solutions that balance mission requirements with cybersecurity compliance. Success Measures Timely completion of ATO packages and authorization milestones. Quality and completeness of security documentation. Reduction in overdue assessments and POA&M items. Accuracy of risk assessments and executive reporting. Improved coordination among system owners, ISSOs, assessors, and technical teams. Consistent application of NIST RMF requirements across the system portfolio. Effective leadership, development, and retention of the A&A team. #J-18808-Ljbffr Intellect Solutions LLC$130k - $145k
...Salary: $130,000 - $145,000/year Work location : Hybrid, 2-3 days per week on-site in Bethesda, MD. Lead Security Assessment and Authorization (SA&A) activities for NIH CIT enterprise information systems, including on-premises, cloud-based, network, hosting...SuggestedContract workFlexible hours2 days per week3 days per week- A-TEK Inc. is seeking an experienced RMF/A&A Lead to support a federal client. The role oversees authorization readiness, package development, governance, risk management... ...maintaining SSPs and SARs, coordinating annual assessments, and ensuring artifacts are audit-ready. #J-18...Suggested
- Intellect Solutions LLC is seeking an experienced Assessment and Authorization (A&A) Lead to oversee cybersecurity assessment, authorization, and continuous monitoring for federal information systems in Rockville, MD. You will supervise a team of five to eight professionals...Suggested
$165k - $185k
.... A-TEK is seeking an experienced RMF/A&A Lead to support our federal customer. The RMF... ...&A Lead serves as the senior technical authority for RMF and A&A activities supporting... ...Coordinate three annual security control assessments and prepare evidence for the...Suggested- ...seeking an experienced security professional to lead Federal RMF and A&A activities within the Washington, DC metro or... ...focuses on developing and maintaining federal authorization packages, coordinating security assessments, and ensuring evidence-driven compliance...Suggested
- ...compliance platform designed to streamline assessment preparation, evidence management, and... ...and technically skilled CMMC Assessment Lead to oversee the planning, preparation,... ...customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring...For contractorsRemote work
- STG International is looking for a part-time Lead Psychologist in Rockville, MD, to support our Federal Occupational Health contract. This position requires navigating psychological assessments within federal regulations, offering a hybrid work model for candidates in...Contract workPart time
$127.79k - $212.99k
...currently seeking a Enterprise Hosting Lead to join our team in Rockville, Maryland... ...ITIL-aligned processes.Proven ability to assess end-to-end solution components, identify... ...Cybersecurity Framework and Security Assessment and Authorization activities.NTT DATA provides a...Temporary workWork at officeRemote workFlexible hours$131.3k - $237.35k
...Solutions division is seeking an expert-level Lead Identity and Access Management Engineer to serve as the senior technical authority for complex enterprise identity management... ...principles.Lead IAM-related audits, risk assessments, and remediation efforts; ensure...Full timeFor contractors- ...seeking an experienced Product Manager to lead the Graph Platform and AI-Graph... ...stakeholder ecosystems and limited direct authority Stakeholder & Change Management Track record... ...on time or at the right level of quality, assesses alternatives to resolve, builds a plan for...Full timeTemporary workFor contractorsWork experience placementFor subcontractorLocal areaImmediate start
$155.56k - $174.04k
...Overview The Cybersecurity Lead will provide the Defense Nuclear Facilities Safety Board (DNFSB) support and implement... ...system; and cost effectiveness Provide daily Assessment and Authorization (A&A) updates through the use of the internal cybersecurity portal...Temporary workFor contractorsWork at officeImmediate startFlexible hoursShift work- ...focused on meaningful outcomes for clients. This semi‑remote role requires residency in Maryland, 5-7 client caseload, in‑person assessments as needed, extensive onboarding, and ongoing professional development. Benefit package includes health insurance, 401(k) with match...Remote job
- The Lead IAM Engineer/Architect leads enterprise IAM initiatives from planning through... ...tools, including: Configuration Assessment, Log Aggregation, Integrity Verification... ...child who lives with the employee) and to authorize their broker-dealers to provide FINRA with...Full timeTemporary workFor contractorsWork experience placementFor subcontractorLocal areaImmediate start
$155.5k - $188.2k
...today, safer tomorrow. Emergent is a leading public health company that delivers protective... .... Lead cybersecurity maturity assessments and create/maintain cybersecurity KPI... ...timeliness of job duties Must be able to author policy documents, provide business risk...Full timeLocal areaRemote work- ...ISPG and ADO ISSOs, managing risk/exception processes, and leading audit readiness. The role aligns to CMS governance where... ..., control selection, implementation oversight, assessment readiness, authorization package hygiene, and continuous monitoring—consistent with...Contract workTemporary workFor contractorsFlexible hours
- A national security solutions firm based in Virginia is hiring an Authorization and Compliance Lead to oversee cybersecurity controls and ensure compliance with federal regulations. Candidates must have a relevant bachelor's degree or equivalent experience, along with TS...
- Capital One is seeking a Principal Associate, Assessments & Team Effectiveness, within Enterprise Learning. The role partners with learning consultants to analyze and design learning experiences for people leaders and teams across the organization. The candidate will manage...
$120k - $145k
...are seeking a Security / ATO Compliance Lead to be responsible for overseeing cybersecurity... ...alignment, continuous monitoring, and Authority-to-Operate (ATO) lifecycle support for a... ...; review vulnerability scan outputs and assessment findings. Track remediation status and...Permanent employmentContract workTemporary workFor contractorsFor subcontractorWork at officeRemote work$24 - $27.61 per hour
(Contract) Guest Experience Lead | Gaithersburg lululemon is an innovative performance... ...inclusive guest experience. Continuously assess the level of guest connection and technical... .... Job Requirements Must be legally authorized to work in the country in which the store...Minimum wageContract workPart timeLocal areaImmediate startShift workNight shiftWeekend workDay shiftAfternoon shiftEarly shift$24 - $27.61 per hour
...people. Job Summary The Guest Experience Lead is responsible for ensuring all guests (i... ...inclusive guest experience. Continuously assess the level of guest connection and technical... ...Requirements Eligibility Must be legally authorized to work in the country in which the store...Minimum wageContract workPart timeShift workNight shiftWeekend workDay shiftAfternoon shiftEarly shift$170k - $180k
...Position Overview A-TEK is seeking a Lead Technical Architect to provide technical... ...will serve as the senior technical authority for modernization activities while remaining... ...or work product is not permitted. We may assess application materials for job-related technical...3 days per week$45k - $75k
...contribute to the company’s success. As a Lead Teller within PNC's Retail Branch... ...customer solutions. Managing Risk - Assessing and effectively managing all of the risks... ...and/or the Financial Industry Regulatory Authority (FINRA), which prohibit the hiring of individuals...Full timeTemporary workPart timeWork experience placementWork at office- ...customer needs. Analyze quality systems and assess: Quality Management Systems according... ...North America is the US subsidiary of GMED, a leading Certification Organization, a distinguished Notified Body (CE0459) Authorized to act under European Regulation (EU) 2017/7...Full timeContract workTemporary workWork experience placementRemote workWork from homeWorldwideHome officeFlexible hours
- ...delivery across Testing, Deployment, and Infrastructure & Cost for the Card Authorizations Platform. You will drive platform-level OKRs, enable faster shipping, and improve reliability. You’ll lead high-priority initiatives, partner with engineers and stakeholders, and...
- A leading technology integrator is seeking an Information System Security Engineer to support critical information security operations in McLean, VA. The role involves overseeing the A&A process, developing security plans, and mitigating cyber threats while ensuring compliance...
- ArdentMC is seeking a Lead Compliance Specialist in Rockville, MD to lead cybersecurity compliance initiatives aligned with... ...and NIST standards. The role involves conducting Security Assessment and Authorization (SA&A) activities, developing security documentation, and ensuring...Flexible hours
- Lead Compliance Specialist (Hybrid, Rockville, MD) Ardent supports federal cybersecurity and privacy compliance efforts, focusing on Security Assessment and Authorization (SA&A) activities. The Lead Compliance Specialist will lead initiatives aligned with FISMA, NIST,...Local areaFlexible hours
$125k - $175k
...are seeking a Vulnerability Management Lead responsible for planning, executing, and... ...Management Lead serves as the primary technical authority for enterprise vulnerability management,... ...enterprise vulnerability scanning, assessment, prioritization, remediation tracking,...$113k - $188k
...NoneClearance Required:Ability to Obtain Public TrustWhat You Will Do:Leads cybersecurity strategy and implementation, including risk... ...with federal security standards and facilitates audits, assessments, and remediation activities.Oversees incident response planning...Full timeFlexible hours$138k - $150k
SHE Lead - Site OperationsLocation: Gaithersburg, Maryland, United StatesIntroduction to roleIf you are an experienced SHE professional... ...standards, construction hazard identification, risk assessment, safety management systems and contractor safety programs.Excellent...Full timeTemporary workFor contractorsWork at officeAfternoon shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Assessment & Authorization (A&A) Lead. Be the first to apply!



