Left arrow iconBack to search

ATO /Risk Management Framework Lead

CDIT
Posted 8 days ago, valid for 22 days
Location

Slidell, LA, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

The ATO / Risk Management Framework Lead plans and drives the path to anAuthorization to Operate (ATO) and then keeps the system authorized. ACF won'tlet any production system, MIS, dashboard, portal, data repository, or externalfacing platform that processes Federal information operate until ACF confirmsthe authorization path, whether a full ATO, a provisional ATO, or a written ACFOCIO determination that no ATO is required. ACF expects the ATO process to takeabout six months, on a schedule the ACF OCIO approves no later than 30 daysafter award. The lead builds the authorization package, coordinates assessmentand testing, resolves findings, runs continuous monitoring, and owns theprivacy and security activities Task 9 requires, including incident reportingand the flow down of requirements to anyone CDIT brings onto the work. The leadworks most closely with the Cloud / Solution Architect, who designs theenvironment the package describes.

Responsibilities

路聽聽聽聽聽聽 Within30 days after award, lead the draft Privacy Threshold Analysis and PrivacyImpact Assessment support package and the Data Security Plan for the COR andthe ACF OCIO reviewers, describing data flows, system boundaries, user roles,encryption, access controls, audit logging, retention, destruction, incidentresponse, subcontractor access, and privacy protections (RFQ Task 9.4).

路聽聽聽聽聽聽 Workwith the COR and ACF to determine the type and sensitivity of the CUI involvedand whether an ATO is required, and recommend the most efficient authorizationpath among the ACF Tech ATO types, including inheritance from a FedRAMPauthorized environment and the ACF Authority to Use (ACF Tech Appendix D).

路聽聽聽聽聽聽 Proposethe ATO schedule for ACF OCIO approval no later than 30 days after award andmanage the authorization effort to it (RFQ Task 10).

路聽聽聽聽聽聽 Categorizethe system under FIPS 199 and FIPS 200 and select, tailor, and document theNIST SP 800-53 control baseline for a Moderate system, applying NIST SP 800-18,NIST SP 800-171, DISA STIG hardening guidance, OMB Memorandum M-05-22, and HHSand ACF policy.

路聽聽聽聽聽聽 Authorand maintain the authorization package deliverables listed below on theschedule ACF Tech approves, including the annual System Security Plan update,the annual assessment, the quarterly POA&M update, and the annualcontingency plan test.

路聽聽聽聽聽聽 Coordinatethe security assessment with the assessor, support testing, track everyfinding, and drive remediation or risk acceptance to closure.

路聽聽聽聽聽聽 Documentthe Zero Trust implementation approach and expected maturity level and managethe quarterly Zero Trust scorecard submissions for the system (ACF TechAppendix B and Appendix C).

路聽聽聽聽聽聽 Runcontinuous monitoring under FISMA and NIST SP 800-137: monthly vulnerabilityscans with an ACF Tech approved tool, patch management, log review, accountreview, configuration management, and POA&M updates on the schedule ACFOCIO approves. Report critical and high vulnerabilities to the COR andremediate them within ACF approved timeframes (RFQ Task 10).

路聽聽聽聽聽聽 Maintainthe authorization boundary and all security documentation throughout the periodof performance, and submit changes through ACF change control beforeimplementation.

路聽聽聽聽聽聽 Ownincident reporting: any suspected or confirmed breach, cyber incident,unauthorized disclosure, lost device, or exposure of information that isn'tpublic is reported immediately, within one hour at most, through CDIT andGuidehouse to the Contracting Officer, the COR, and the ACF Incident ResponseTeam, with logs and evidence preserved and full cooperation with ACF and HHSresponse (RFQ Task 9.5 and Section 4.0).

路聽聽聽聽聽聽 Assesswhether any data the program collects, stores, transmits, or analyzes isProtected Health Information and whether CDIT or any subcontractor is a HIPAAbusiness associate, and if so support the Business Associate Agreement and therequired safeguards (RFQ Task 9.6).

路聽聽聽聽聽聽 Supportthe Data Inventory and Data Minimization Plan before any data is collected,confirming that no Social Security numbers or other high risk identifiers arecollected without written COR approval (RFQ Task 6.3).

路聽聽聽聽聽聽 Completethe electronic authentication risk assessment with the system owner and ISSO toset the identity, authentication, and federated assurance levels (RFQ Section4.0).

路聽聽聽聽聽聽 Flowthe privacy, security, records, incident reporting, and training requirementsdown to any subcontractor, consultant, or vendor CDIT uses, track the requiredtraining certificates, and keep the records that show compliance (RFQ Tasks 9.2and 9.3).

路聽聽聽聽聽聽 Supportthe Sustainability and Transition strategy with the security documentation,data handling, and media sanitization under NIST SP 800-88 needed for acomplete and secure transfer at the end of the contract (RFQ Task 8).

Required qualifications

路聽聽聽聽聽聽 Bachelor'sdegree.

路聽聽聽聽聽聽 Atleast 7 years in federal information security, with hands on Risk ManagementFramework work under NIST SP 800-37 and NIST SP 800-53.

路聽聽聽聽聽聽 Has ledat least one federal system through assessment to a signed ATO, includingwriting the System Security Plan, supporting the assessment, and managing thePOA&M.

路聽聽聽聽聽聽 FedRAMPknowledge, including control inheritance from an authorized cloud environmentand the customer responsibility matrix.

路聽聽聽聽聽聽 Continuousmonitoring and vulnerability management with enterprise scanning tools,including reading results and driving remediation.

路聽聽聽聽聽聽 Workingknowledge of FISMA, the Privacy Act, HIPAA security requirements, and federalincident reporting obligations.

路聽聽聽聽聽聽 Cleartechnical writing and the ability to coordinate assessors, developers, andGovernment reviewers to a schedule.

路聽聽聽聽聽聽 PublicTrust Tier 2 clearance, held or obtainable.

Desired qualifications (CDITadditions, not conditions of the subcontract)

路聽聽聽聽聽聽 CISSP,CGRC (formerly CAP), CISM, or an equivalent security certification.

路聽聽聽聽聽聽 PriorATO work at HHS or an HHS operating division, and familiarity with the HHS andACF security program and templates.

路聽聽聽聽聽聽 Experiencewith a governance, risk, and compliance tool used for federal authorizationpackages.

路聽聽聽聽聽聽 Experienceproducing Zero Trust scorecards against the CISA Zero Trust Maturity Model.

路聽聽聽聽聽聽 Privacycredential such as CIPP/G, or experience preparing Privacy Threshold Analysesand Privacy Impact Assessments.






Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.