Back to jobs

Security | ATO Compliance Lead

Gaithersburg, MD

The Opportunity

At i360technologies, we specialize in business consulting and technology services for federal agencies. We are seeking a Security / ATO Compliance Lead to be responsible for overseeing cybersecurity compliance alignment, continuous monitoring, and Authority-to-Operate (ATO) lifecycle support for a large-scale federal financial modernization initiative.

This role ensures alignment with FedRAMP Moderate, FISMA, and NIST SP 800-53 Moderate security controls and supports Risk Management Framework (RMF) implementation activities, operating in a Moderate-impact federal cloud environment supporting multi-agency financial systems modernization.

What You Will Do

  • Lead review and validation of NIST SP 800-53 Moderate control implementation; ensure alignment with Risk Management Framework (NIST SP 800-37).
  • Maintain and update System Security Plan (SSP) documentation.
  • Support FedRAMP Moderate compliance requirements; ensure alignment with client security policies; support FISMA compliance activities.
  • Maintain and manage Plan of Action & Milestones (POA&M); track vulnerability remediation activities.
  • Coordinate corrective action planning; support risk identification and mitigation strategies.
  • Develop and support continuous monitoring strategy; review vulnerability scan outputs and assessment findings.
  • Track remediation status and reporting requirements; support periodic security control assessments.
  • Support preparation and maintenance of ATO documentation packages; assist with evidence collection and documentation updates.
  • Coordinate with agency ISSOs, security officials, and 3PAO assessors; support audit readiness and compliance reviews.

Required Qualifications

  • Minimum seven (7) years of federal cybersecurity compliance experience.
  • Demonstrated experience supporting FedRAMP Moderate systems.
  • Strong working knowledge of NIST SP 800-53 Moderate, NIST SP 800-37 (RMF), and FISMA compliance requirements.
  • Experience managing POA&M documentation.
  • Experience supporting ATO packages, renewals, and ongoing compliance activities; experience coordinating with federal security stakeholders.

Preferred Experience

  • CISSP, CISM, or equivalent cybersecurity certification.
  • Experience supporting CFO Act agencies.
  • Experience in federal financial system environments.

What Success Looks Like

  • NIST SP 800-53 Moderate controls are validated and documented cleanly, supporting on-time ATO renewals.
  • POA&M items are tracked and remediated on schedule, with minimal overdue findings.
  • Continuous monitoring and 3PAO coordination run smoothly, keeping the system audit-ready at all times.

Security & Eligibility Requirements

  • S. Citizenship or Lawful Permanent Residency with a minimum of three (3) years of U.S. residency
  • Successful completion of a Moderate Risk background investigation and FBI fingerprinting
  • Eligibility to obtain and maintain an HSPD-12 Personal Identity Verification (PIV) credential
  • Execution of a Non-Disclosure Agreement (NDA)
  • Compliance with Bureau of the Fiscal Service Security Rules of Behavior
  • Completion of required cybersecurity and privacy awareness training
  • Work must be performed within the United States (remote access from foreign locations is not permitted)
  • Employment is contingent upon contract award and Government approval of candidate qualifications

Benefits

  • Referral Bonus
  • (401k) Matching
  • Holidays – Eleven
  • Technology Reimbursement
  • Short-Term & Long-Term Disability
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (0-3 years - 15 Days PTO | 3+ years 20 Days)
  • 80% Employer Paid Health Care Plan (Medical, Dental & Vision)

Benefit eligibility and coverage are subject to applicable plan terms and company policies.

Salary: The salary range for this position is $120,000 – $145,000 annually, commensurate with experience, certifications, and qualifications. Final offers may vary based on factors including relevant experience, education, certifications (e.g., CISSP, CISM), and contract award terms.

Equal Opportunity Employer Minority/Female/Veteran/Disability

All qualified applicants will receive consideration for employment regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or status within any other protected group.

Only direct applicants will be considered. Submissions from recruiting or staffing firms will not be accepted.

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in i360technologies, Inc.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...