Blake Willson Group, LLC Logo

Blake Willson Group, LLC

Subject Matter Expert - RMF & ATO Lead

Posted 6 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in US
110K-130K Annually
Senior level
Remote
Hiring Remotely in US
110K-130K Annually
Senior level
The RMF & ATO Lead will oversee NIST RMF processes, manage security assessments, ensure compliance, and mentor ATO staff for cybersecurity operations.
The summary above was generated by AI

Harnessing Technology to Improve Financial Stewardship for the Welfare, Defense, and Security of Our Nation

Blake Willson Group (BWG) unites deep domain experts with technologists who leverage industry-leading financial management solutions to address the most critical mission objectives. Headquartered in the National Capital Region, the firm delivers measurable outcomes through technology-forward strategies and advanced solutions that drive mission success.

Blake Willson Group has a distinguished track record of exceptional performance, achieving operational efficiencies that allow our clients to do more with less. BWG has earned the confidence of its clients by consistently exceeding expectations through its unwavering commitment to best value solutions, implemented with speed.

Job Location: 

This role is 100% remote.

Clearance:

Must be currently authorized to work in the United States on a full-time basis and have the ability to obtain a Public Trust Security Clearance. 

Job Description:

In this position as a RMF & ATO Lead, you will lead execution of the NIST Risk Management Framework (RMF) process across the full system lifecycle in support of DOJ and Bureau of Prisons (BOP) security requirements. You will provide strategic oversight, technical leadership, and quality assurance for Authorization to Operate (ATO) efforts, ensuring compliance with NIST, DOJ, and federal cybersecurity standards. In this position, you will also:

  • Lead execution of the NIST RMF process (SP 800-37) across all lifecycle phases, supporting timely and compliant ATO decisions.
  • Oversee development, quality review, and maintenance of authorization package artifacts, including SSPs, SARs, POA&Ms, Risk Assessments, and supporting documentation.
  • Guide system teams through Rapid ATO timelines while ensuring compliance with DOJ security policies and NIST SP 800-53 controls.
  • Lead security control selection, tailoring, validation, and documentation across cloud-based and on-premises environments using verifiable technical evidence.
  • Direct security assessments, including SAP development, assessment result review, and risk analysis to inform authorization decisions.
  • Oversee POA&M development, remediation tracking, and Continuous Monitoring (ConMon) strategies to support ongoing authorization.
  • Ensure all RMF documentation and supporting artifacts (Incident Response Plans, Contingency Plans, Configuration Management Plans, ISAs/MOUs, and privacy documentation) are complete and accurately maintained in JCAM.
  • Serve as the primary cybersecurity liaison and technical lead, mentoring ATO staff and facilitating risk-based decision making with system owners, assessors, and leadership.

Required Skills:

  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related field.
  • 7 years of experience performing systems security assessments, preparing security documentation, and supporting security authorization for live networks, systems, and enterprise environments.
  • 5 years of experience assessing and enhancing IT security policies and procedures to meet Federal and applicable international regulatory requirements.
  • 5 years of IT security experience with deep knowledge of security regulations and assessments, including development of multiple A&A and ATO packages across diverse system environments, including classified systems.
  • Active possession of one of the following certifications: CISA, CRISC, CISSP, or CAP.

Desired Skills:

  • Strong working knowledge of NIST Special Publications, including NIST SP 800-53 for security control selection and NIST SP 800-37 RMF.
  • Experience using JCAM for RMF and authorization package management is preferred.
  • Experience supporting DOJ, BOP, or other federal law enforcement agencies with RMF, ATO, or Continuous Monitoring activities.
  • Hands-on experience with cloud service providers (AWS, Azure, or GCP) and applying NIST SP 800-53 controls within FedRAMP-aligned environments.

At Blake Willson Group, we believe in transparency and fairness in compensation practices. For this position, we offer a competitive salary range of $110,000 to $130,000 in the United States. Your individual salary within this range will be determined by various factors, including but not limited to your education, experience, skills, and geographic location. We also provide a comprehensive Total Rewards package, which includes major medical benefits such as dental and vision coverage, a 401(k)-contribution plan, holiday and personal time off, professional development training & certification benefits, health & wellness subsidies, paid time off for community service, and more. We value your contributions and are committed to recognizing and rewarding your performance and the value you bring to our business.

The statements above describe the general nature and level of work anticipated for this role. They are not intended to be an exhaustive list of all duties, responsibilities, or skills required. Blake Willson Group reserves the right to modify, assign, or add job-related responsibilities as business needs require. Where feasible, reasonable accommodations may be provided for individuals to perform essential job functions.Blake Willson Group is an Equal Employment Opportunity (EEO) employer and is committed to maintaining a professional, respectful, and harassment-free workplace. All employment decisions are based on business needs, qualifications, and merit. We comply with all applicable federal, state, and local employment laws and do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, genetic information, or any other legally protected status. Blake Willson Group prohibits unlawful discrimination, harassment, and retaliation.Blake Willson Group complies with federal equal employment opportunity requirements. The “Know Your Rights: Workplace Discrimination Is Illegal” poster is available to applicants and employees. View the official poster here: Know Your Rights: Workplace discrimination is illegalIf you require a reasonable accommodation during the application process, please contact us at 202-381-0603, Ext. 3.Blake Willson Group participates in E-Verify to confirm employment eligibility and will provide the federal government with your Form I-9 information to verify authorization to work in the United States. 

Top Skills

AWS
Azure
GCP
Jcam
Nist
Risk Management Framework

Similar Jobs

An Hour Ago
Remote
United States of America
113K-148K Annually
Senior level
113K-148K Annually
Senior level
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
Responsible for operational transfer pricing lifecycle, ensuring compliance and documentation. Collaborate with Finance and other departments for policy design and improvements with a focus on automation and data analysis.
Top Skills: Ai ToolsApple MacosGoogle SuiteOracleOracle ErpOracle FusionSlack
An Hour Ago
Remote
United States
102K-188K Annually
Mid level
102K-188K Annually
Mid level
Aerospace • Artificial Intelligence • Computer Vision • Software • Analytics • Defense • Big Data Analytics
The Geospatial Solutions Architect will design and implement geospatial data visualization solutions, develop operational dashboards, and oversee the integration of geospatial AI/ML models for a DoD customer.
Top Skills: Cloud-Based ApplicationsEsri ArcgisGeospatial Ai/MlGis ToolsQgis
An Hour Ago
In-Office or Remote
2 Locations
102K-188K Annually
Mid level
102K-188K Annually
Mid level
Aerospace • Artificial Intelligence • Computer Vision • Software • Analytics • Defense • Big Data Analytics
The IAM Engineer will design, implement, and manage IAM solutions to enhance secure authentication and access control across environments, integrating various tools and ensuring compliance with established security standards.
Top Skills: Authentication Protocols (SamlAWSAzure Active DirectoryCacCloud EnvironmentsIam SolutionsIdentity Governance ToolsMicrosoft Entra IdMulti-Factor AuthenticationOauthOktaOpenid Connect)Ping IdentityPkiZero Trust Architecture

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account