Implement and maintain compliance with the NIST Risk Management Framework (RMF) and FISMA High requirements for all cloud systems.
Ensure that all cloud systems align with NASA NPR 2810, NIST SP 800-53, and other applicable federal cybersecurity policies and directives.
Support the Authorization to Operate (ATO) process, maintaining continuous compliance and ensuring timely updates to security documentation.
Oversee and enforce adherence to the shared responsibility model between the agency, cloud service providers, and system owners.
Develop, maintain, and update system Security Authorization Packages, including the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and Continuous Monitoring (ConMon) documentation.
Conduct Security Impact Analyses (SIA) for configuration changes, new deployments, or integrations within the cloud environment.
Identify, assess, and document system vulnerabilities and risks, recommending mitigation strategies to maintain a compliant security posture.
Prepare systems for internal and external audits, ensuring documentation and evidence are audit-ready.
Coordinate with assessors and Authorizing Officials (AOs) during security control assessments (SCA) and ATO renewals.
Track findings and corrective actions to closure, maintaining transparency through regular status reporting.
Requirements
Bachelor’s degree in Computer Science, Information Assurance, Cybersecurity, Engineering, or related technical field; Master’s degree preferred.
8+ years of progressive experience in information system security, with at least 3 years focused on securing cloud-based systems and services.
Demonstrated experience working in a federal or FISMA Moderate/High environment, including implementing NIST RMF and FedRAMP controls.
Must be able to obtain Public Trust (U.S Citizenship Required).
Must hold at least one DoD 8570.01-M IAT Level III or IAM Level III certification (e.g., CISSP, CISM, CASP+, or equivalent).
Cloud security certifications such as CCSP, AWS Certified Security – Specialty, Microsoft Certified: Cybersecurity Architect Expert, or Google Professional Cloud Security Engineer are highly desirable.
FedRAMP or NIST RMF practitioner certifications or training preferred.
Benefits
Health and Wellness programs
Income Protection
Paid Leave
Retirement
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
NIST Risk Management FrameworkFISMA High requirementsSecurity Authorization PackagesSystem Security PlanSecurity Assessment ReportPlan of Action and MilestonesContinuous MonitoringSecurity Impact Analysessystem vulnerabilitiesrisk mitigation strategies