Subject Matter Expert - RMF & ATO Lead

AI overview

Lead the execution of the NIST Risk Management Framework across system lifecycles, providing strategic oversight and ensuring compliance with federal cybersecurity standards.

Harnessing Technology to Improve Financial Stewardship for the Welfare, Defense, and Security of Our Nation

Blake Willson Group (BWG) unites deep domain experts with technologists who leverage industry-leading financial management solutions to address the most critical mission objectives. Headquartered in the National Capital Region, the firm delivers measurable outcomes through technology-forward strategies and advanced solutions that drive mission success.

Blake Willson Group has a distinguished track record of exceptional performance, achieving operational efficiencies that allow our clients to do more with less. BWG has earned the confidence of its clients by consistently exceeding expectations through its unwavering commitment to best value solutions, implemented with speed.

Job Location: 

This role is 100% remote.

Clearance:

Must be currently authorized to work in the United States on a full-time basis and have the ability to obtain a Public Trust Security Clearance. 

Job Description:

In this position as a RMF & ATO Lead, you will lead execution of the NIST Risk Management Framework (RMF) process across the full system lifecycle in support of DOJ and Bureau of Prisons (BOP) security requirements. You will provide strategic oversight, technical leadership, and quality assurance for Authorization to Operate (ATO) efforts, ensuring compliance with NIST, DOJ, and federal cybersecurity standards. In this position, you will also:

  • Lead execution of the NIST RMF process (SP 800-37) across all lifecycle phases, supporting timely and compliant ATO decisions.
  • Oversee development, quality review, and maintenance of authorization package artifacts, including SSPs, SARs, POA&Ms, Risk Assessments, and supporting documentation.
  • Guide system teams through Rapid ATO timelines while ensuring compliance with DOJ security policies and NIST SP 800-53 controls.
  • Lead security control selection, tailoring, validation, and documentation across cloud-based and on-premises environments using verifiable technical evidence.
  • Direct security assessments, including SAP development, assessment result review, and risk analysis to inform authorization decisions.
  • Oversee POA&M development, remediation tracking, and Continuous Monitoring (ConMon) strategies to support ongoing authorization.
  • Ensure all RMF documentation and supporting artifacts (Incident Response Plans, Contingency Plans, Configuration Management Plans, ISAs/MOUs, and privacy documentation) are complete and accurately maintained in JCAM.
  • Serve as the primary cybersecurity liaison and technical lead, mentoring ATO staff and facilitating risk-based decision making with system owners, assessors, and leadership.

Required Skills:

  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related field.
  • 7 years of experience performing systems security assessments, preparing security documentation, and supporting security authorization for live networks, systems, and enterprise environments.
  • 5 years of experience assessing and enhancing IT security policies and procedures to meet Federal and applicable international regulatory requirements.
  • 5 years of IT security experience with deep knowledge of security regulations and assessments, including development of multiple A&A and ATO packages across diverse system environments, including classified systems.
  • Active possession of one of the following certifications: CISA, CRISC, CISSP, or CAP.

Desired Skills:

  • Strong working knowledge of NIST Special Publications, including NIST SP 800-53 for security control selection and NIST SP 800-37 RMF.
  • Experience using JCAM for RMF and authorization package management is preferred.
  • Experience supporting DOJ, BOP, or other federal law enforcement agencies with RMF, ATO, or Continuous Monitoring activities.
  • Hands-on experience with cloud service providers (AWS, Azure, or GCP) and applying NIST SP 800-53 controls within FedRAMP-aligned environments.

At Blake Willson Group, we believe in transparency and fairness in compensation practices. For this position, we offer a competitive salary range of $110,000 to $130,000 in the United States. Your individual salary within this range will be determined by various factors, including but not limited to your education, experience, skills, and geographic location. We also provide a comprehensive Total Rewards package, which includes major medical benefits such as dental and vision coverage, a 401(k)-contribution plan, holiday and personal time off, professional development training & certification benefits, health & wellness subsidies, paid time off for community service, and more. We value your contributions and are committed to recognizing and rewarding your performance and the value you bring to our business.

The statements above describe the general nature and level of work anticipated for this role. They are not intended to be an exhaustive list of all duties, responsibilities, or skills required. Blake Willson Group reserves the right to modify, assign, or add job-related responsibilities as business needs require. Where feasible, reasonable accommodations may be provided for individuals to perform essential job functions.
Blake Willson Group is an Equal Employment Opportunity (EEO) employer and is committed to maintaining a professional, respectful, and harassment-free workplace. All employment decisions are based on business needs, qualifications, and merit. We comply with all applicable federal, state, and local employment laws and do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, genetic information, or any other legally protected status. Blake Willson Group prohibits unlawful discrimination, harassment, and retaliation.
Blake Willson Group complies with federal equal employment opportunity requirements. The “Know Your Rights: Workplace Discrimination Is Illegal” poster is available to applicants and employees. View the official poster here: Know Your Rights: Workplace discrimination is illegal
If you require a reasonable accommodation during the application process, please contact us at 202-381-0603, Ext. 3.
Blake Willson Group participates in E-Verify to confirm employment eligibility and will provide the federal government with your Form I-9 information to verify authorization to work in the United States. 

Harnessing Technology to Improve Financial StewardshipBlake Willson Group (BWG) is a fast-growing firm delivering comprehensive professional services and technology solutions to Civilian, Defense, and Intelligence Community customers. Headquartered in Arlington, Virginia, Blake Willson Group has grown rapidly since its inception, securing consecutive years on the Inc. 5000 list, a prestigious honor designated for America’s most successful companies. We are internationally recognized for quality management practices and nationally recognized as a Continuing Professional Education (CPE) training provider. Built on our foundational values of Service to Others, Leadership, Diversity, Dependability, Integrity, and Grit, BWG commits to Empowering Our People and Improving Our Nation. Members of the Blake Willson Group team are passionate and enthusiastic, working towards a common goal of exceptional client support.

View all jobs
Salary
$110,000 – $130,000 per year
Report this job
Apply for this job