Security and Authorization Specialist (Federal ATO / RMF)
RoarTech inc
*Company:* RoarTech Inc
*Employment Type:* Full-time/Part Time
*Location:* Remote (U.S.), with occasional on-site meetings in the Washington, DC metropolitan area
*Eligibility:* U.S. citizenship required; must be eligible to obtain and maintain a Federal Public Trust background investigation
*Reports To:* Program Manager RoarTech Inc. is looking for a security and authorization specialist to carry a data and workflow application through a Federal authorization decision and then keep it authorized. The application will be hosted inside an agency cloud platform that already holds an authorization to operate, so the work centers on control inheritance, application-specific control documentation, privacy analysis, scanning and remediation, and continuous monitoring, rather than on standing up a new system boundary from scratch. This is a hands-on position. You will write the documents, run and interpret the scans, track the findings, and sit in the meetings with the agency security staff. You will not be managing a team of assessors. If you enjoy getting a package through an authorizing official cleanly and on schedule, and you would rather own a system end to end than review other people's work, this will suit you. What you will do * Complete a security impact analysis with the hosting platform's security team to place the application inside the platform's existing authorization boundary, and document what that means for the control set.
* Write the application-specific control documentation under the NIST SP 800-53 Moderate baseline, identifying clearly which controls are inherited, which are hybrid, and which the application implements itself.
* Prepare the privacy threshold analysis and, where required, support the privacy impact assessment for a system that handles personally identifiable information.
* Run and interpret static, dynamic, and dependency scanning in the delivery pipeline; record findings on a plan of action and milestones with severity, owner, and remediation date; verify fixes before closing them.
* Prepare the contingency plan and support its testing.
* Verify Section 508 conformance for the application's dashboards and user interfaces and document the accessibility conformance report.
* Operate continuous monitoring after authorization: scheduled control assessments, POA&M maintenance, configuration change review, and the security content of the monthly report to the client.
* Maintain the incident response procedure for the delivery team and take part in the client's exercises.
* If the platform's security office decides the application needs its own authorization rather than inheritance, prepare the full assessment and authorization package under the agency's process.
* Work with engineering colleagues so that security evidence is produced by the pipeline rather than assembled by hand at audit time. What you bring * Five or more years of Federal information system security work, including at least three years preparing or maintaining assessment and authorization artifacts (system security plans, security assessment reports, POA&Ms) under the NIST Risk Management Framework, SP 800-37 and SP 800-53.
* Experience taking a system or an application all the way to a Federal authorization decision, working with an information system security officer, a security control assessor, and an authorizing official.
* Practical understanding of control inheritance in a FedRAMP-authorized or agency-authorized platform, including the real difference between inherited, hybrid, and system-specific controls.
* Experience preparing privacy threshold analyses and supporting privacy impact assessments.
* Hands-on experience with application and dependency security scanning in a delivery pipeline, and with driving findings on a POA&M through remediation.
* Writing that a Federal security office accepts without sending back. We will ask for a redacted authorization artifact you personally wrote.
* A bachelor's degree and five years of relevant experience, or an equivalent combination of experience and certifications.
* U.S. citizenship and eligibility for a Federal Public Trust background investigation. Nice to have * CISSP, CISM, CAP, CGRC, or a comparable security certification; cloud security credentials such as AWS Certified Security Specialty or Azure Security Engineer.
* Experience with a Federal civilian agency's own security and privacy requirements and authorization process.
* Experience assessing or authorizing systems that include artificial intelligence or machine learning components, where model logging, evaluation records, and drift monitoring serve as control evidence.
* Section 508 conformance testing and accessibility conformance reporting.
* Experience with ongoing authorization and continuous monitoring rather than one-time package work. Why this one is interesting The application you will authorize uses automation to do work that people currently do by hand, under human review at every step. That means the control story includes logging, evaluation evidence, and human decision gates, not just the usual baseline. If you have been looking for authorization work with something new in it, this is that. About RoarTech RoarTech Inc. is a small business headquartered in Fairfax, Virginia. Since 2014 we have supported Federal agencies with enterprise and cloud architecture, hybrid multi-cloud platforms, cybersecurity and authorization, data management, program and project management, and digital modernization services. Our past performance spans the Departments of State, Education, and Veterans Affairs, the U.S. Air Force, GSA, GAO, FCC, NOAA, and NIH. Through Enclavia.ai, our AI accelerator, we build governed, compliance-native AI platforms for regulated and Federal environments, with drift monitoring, audit logging, and human-in-the-loop controls designed in from the start. We are a small team that values judgment, craftsmanship, and direct accountability to the client. RoarTech Inc. | Pay: $70.00 - $75.00 per hour Expected hours: 40.0 per week Application Question(s):
* Are you a US CItizen?
* I understand this position is 1099 only.
* Can you occasionally commute to DC? Work Location: Remote
*Employment Type:* Full-time/Part Time
*Location:* Remote (U.S.), with occasional on-site meetings in the Washington, DC metropolitan area
*Eligibility:* U.S. citizenship required; must be eligible to obtain and maintain a Federal Public Trust background investigation
*Reports To:* Program Manager RoarTech Inc. is looking for a security and authorization specialist to carry a data and workflow application through a Federal authorization decision and then keep it authorized. The application will be hosted inside an agency cloud platform that already holds an authorization to operate, so the work centers on control inheritance, application-specific control documentation, privacy analysis, scanning and remediation, and continuous monitoring, rather than on standing up a new system boundary from scratch. This is a hands-on position. You will write the documents, run and interpret the scans, track the findings, and sit in the meetings with the agency security staff. You will not be managing a team of assessors. If you enjoy getting a package through an authorizing official cleanly and on schedule, and you would rather own a system end to end than review other people's work, this will suit you. What you will do * Complete a security impact analysis with the hosting platform's security team to place the application inside the platform's existing authorization boundary, and document what that means for the control set.
* Write the application-specific control documentation under the NIST SP 800-53 Moderate baseline, identifying clearly which controls are inherited, which are hybrid, and which the application implements itself.
* Prepare the privacy threshold analysis and, where required, support the privacy impact assessment for a system that handles personally identifiable information.
* Run and interpret static, dynamic, and dependency scanning in the delivery pipeline; record findings on a plan of action and milestones with severity, owner, and remediation date; verify fixes before closing them.
* Prepare the contingency plan and support its testing.
* Verify Section 508 conformance for the application's dashboards and user interfaces and document the accessibility conformance report.
* Operate continuous monitoring after authorization: scheduled control assessments, POA&M maintenance, configuration change review, and the security content of the monthly report to the client.
* Maintain the incident response procedure for the delivery team and take part in the client's exercises.
* If the platform's security office decides the application needs its own authorization rather than inheritance, prepare the full assessment and authorization package under the agency's process.
* Work with engineering colleagues so that security evidence is produced by the pipeline rather than assembled by hand at audit time. What you bring * Five or more years of Federal information system security work, including at least three years preparing or maintaining assessment and authorization artifacts (system security plans, security assessment reports, POA&Ms) under the NIST Risk Management Framework, SP 800-37 and SP 800-53.
* Experience taking a system or an application all the way to a Federal authorization decision, working with an information system security officer, a security control assessor, and an authorizing official.
* Practical understanding of control inheritance in a FedRAMP-authorized or agency-authorized platform, including the real difference between inherited, hybrid, and system-specific controls.
* Experience preparing privacy threshold analyses and supporting privacy impact assessments.
* Hands-on experience with application and dependency security scanning in a delivery pipeline, and with driving findings on a POA&M through remediation.
* Writing that a Federal security office accepts without sending back. We will ask for a redacted authorization artifact you personally wrote.
* A bachelor's degree and five years of relevant experience, or an equivalent combination of experience and certifications.
* U.S. citizenship and eligibility for a Federal Public Trust background investigation. Nice to have * CISSP, CISM, CAP, CGRC, or a comparable security certification; cloud security credentials such as AWS Certified Security Specialty or Azure Security Engineer.
* Experience with a Federal civilian agency's own security and privacy requirements and authorization process.
* Experience assessing or authorizing systems that include artificial intelligence or machine learning components, where model logging, evaluation records, and drift monitoring serve as control evidence.
* Section 508 conformance testing and accessibility conformance reporting.
* Experience with ongoing authorization and continuous monitoring rather than one-time package work. Why this one is interesting The application you will authorize uses automation to do work that people currently do by hand, under human review at every step. That means the control story includes logging, evaluation evidence, and human decision gates, not just the usual baseline. If you have been looking for authorization work with something new in it, this is that. About RoarTech RoarTech Inc. is a small business headquartered in Fairfax, Virginia. Since 2014 we have supported Federal agencies with enterprise and cloud architecture, hybrid multi-cloud platforms, cybersecurity and authorization, data management, program and project management, and digital modernization services. Our past performance spans the Departments of State, Education, and Veterans Affairs, the U.S. Air Force, GSA, GAO, FCC, NOAA, and NIH. Through Enclavia.ai, our AI accelerator, we build governed, compliance-native AI platforms for regulated and Federal environments, with drift monitoring, audit logging, and human-in-the-loop controls designed in from the start. We are a small team that values judgment, craftsmanship, and direct accountability to the client. RoarTech Inc. | Pay: $70.00 - $75.00 per hour Expected hours: 40.0 per week Application Question(s):
* Are you a US CItizen?
* I understand this position is 1099 only.
* Can you occasionally commute to DC? Work Location: Remote
Vacancy posted more than 2 months ago
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security and Authorization Specialist (Federal ATO / RMF). Be the first to apply!
