The RMF / ATO Automation Lead is a senior technical and compliance leader responsible for owning and executing the full Risk Management Framework (RMF) accreditation lifecycle for a mission‑critical enclave. This role leads the implementation of DoD and Intelligence Community security controls, drives ATO and continuous ATO (cATO) efforts, and modernizes compliance through automation and DevSecOps practices. The ideal candidate brings deep experience operating in IL5/IL6 environments and can bridge security, engineering, and compliance teams to achieve scalable, audit‑ready outcomes.
Key Responsibilities
- Lead the end‑to‑end RMF accreditation and ATO lifecycle for assigned enclaves, including initial ATO and continuous ATO (cATO).
- Implement and assess security controls in accordance with CNSSI 1253, NIST SP 800‑171, and NIST SP 800‑53 / 800‑59 as applicable.
- Author, maintain, and update RMF documentation including System Security Plans (SSPs), POA&Ms, security assessments, and supporting artifacts.
- Manage ATO submission packages and navigate eMASS approval chains, coordinating with ISSOs, ISSEs, AO representatives, and government stakeholders.
- Design and implement automation strategies to streamline compliance, control validation, evidence collection, and continuous monitoring.
- Support DevSecOps‑driven cATO processes, integrating security controls into CI/CD pipelines.
- Lead and support continuous monitoring activities, including vulnerability management, log analysis, and control effectiveness reporting.
- Architect and support Identity and Access Management (IAM) federation solutions within Oracle Cloud Infrastructure (OCI).
- Partner with engineering, cloud, and security teams to ensure RMF requirements are embedded into system architecture and operational processes.
- Provide expert guidance on operating in IL5/IL6 classified and regulated cloud environments.