Delegated Authorizing Official Representative (DAO-R)
About the Role
The program provides Systems Engineering and Technical Assistance (SETA) core and non-core support in Cyber Security and Management to improve the Information Assurance (IA) posture of a National customer. Core capabilities include IA Management, Federal Information Security Management Act (FISMA) coordination and reporting, Risk Management Framework (RMF) application, IA compliance measurements and metrics, Assessment and Authorization (A&A), Vulnerability Management, and Cyber Defense support.
Responsibilities
- Ensure adherence to ICD-503 and customer-specific directives/policies through the lifecycle (RMF 1-6) of customer-sponsored assets.
- Provide risk recommendations to the customer after reviewing sponsored asset overall risk posture as part of the Authority to Operate (ATO) RMF process.
- Manage and track customer-sponsored assets’ Plan of Action and Milestones (POAMs) by working with various security stakeholders (ISSO/ISSE/ISSM/SCA) post-authorization.
- Screen new asset requests to ensure sponsorship and information system owner identification.
- Facilitate System Review Team to ensure new/existing customer-sponsored assets have the correct project regulation, data types/C-I-A impact assignments, and overlay assignments (with customer signoff).
- Assign asset security controls and levy asset-specific liens on controls for which the program did not meet during accreditor reviews.
- Ensure customer-sponsored assets maintain their security postures in accordance with customer-identified Continuous Monitoring (RMF step 6) directives and policies.
- Provide continuous ad-hoc authorization-related daily support to both the customer and programs.
Requirements
- 10 to 12 years of experience with a BS/BA, 8 to 10 years with an MS/MA, or 5 to 7 years with a PhD.
- Must possess and maintain a TS/SCI with Poly clearance.
- Able to support customer’s core hours in a SCIF environment (0900-1500; Mon – Fri).
- Level III DoD 8570 certification in IAT or IAM or ability to attain certification within 6 months of start.
- Experience implementing RMF Process and NIST 800-53 technical controls, as well as developing and maintaining associated certification and accreditation documentation.
- Able to work in a team environment.
- Familiarity with Cloud platforms (Azure, AWS, Oracle Cloud (OCI), Google Cloud).
- Familiarity with Cloud Security groups.
- Ability to analyze and assess vulnerability management tools.
- Familiarity with analyzing and generating reports using Splunk.
Qualifications (Desired)
- Bachelor of Science Degree in Science, Technology, Engineering, or Mathematics (STEM) or an advanced IA certification.
- Self-starter requiring limited direction and supervision.
- Experience briefing senior customer personnel.
- Ability to organize and prioritize numerous customer requests in a fast-paced, deadline-driven environment.
- Familiarity with Amazon Web Services (AWS).
- Familiarity with customer's IA processes.
- Experience with ServiceNow.
Pay
Projected compensation range: $133,901.35 – $232,828.46. Final salary/hourly rate may vary based on factors such as relevant work experience, skills, competencies, geographic location, education, certifications, and Federal Government Contract Labor categories.
Benefits
- Health Insurance
- Life Insurance
- Paid Time Off
- Holiday Pay
- Short-Term and Long-Term Disability
- Retirement and Savings plans
- Learning and Development opportunities
- Wellness programs
- Other optional benefit elections
Schedule
Core hours: 0900-1500, Monday – Friday (in a SCIF environment).