Haystack
← Back to Jobs
Technology
IS

Cybersecurity Assesment and Authorizationn (A&A) SME

Isoftech IncUnited States🇺🇸United StatesPosted 31 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Role Overview

Functions as a central authority on the Assessment and Authorization (A&A) of complex information systems, guiding the cybersecurity policies and procedures that protect our client''''s vital infrastructure. In this capacity, you will be responsible for executing rigorous client''''s cybersecurity processes. Ensure that systems successfully navigate the authorization pipeline and maintain their security posture over time.

Key Responsibilities

Undertakes a broad spectrum of activities aimed at enforcing compliance and managing risk within complex IT and Operational Technology (OT) environments.

Core duties will include:

  • A&A Execution: Serving as the SME for systems undergoing the authorization process, ensuring all systems meet stringent client requirements for initial and continuous authorization.
  • NIST Control Application: Utilizing a deep understanding of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 security controls to assess and authorize large organizational IT infrastructures.
  • Infrastructure Evaluation: Assessing complex environments that include compilations of large and small enclaves, Cloud Hosted Services, Operational Technology, Automated Information System (AIS) applications, and outsourced IT processes.
  • Risk Determination: Evaluating the residual risk of identified vulnerabilities (such as non-compliant security controls) and determining the potential ramifications on a system’s current or future operational authorization.
  • Executive Briefings: Preparing and delivering briefings to senior management on the progress, status, or results of information systems navigating the Risk Management Framework (RMF) lifecycle 

Required Experience

  • Total Experience: A minimum of five (5) years of highly relevant Certification and Accreditation (C&A) experience.
  • Framework Mastery: Comprehensive, hands-on experience executing the Risk Management Framework (RMF) and utilizing NIST C&A methodologies.
  • Enterprise Scale: Proven experience in assessing security controls and conducting thorough authorization reviews for large, complex organizational structures.
  • DoD Expertise: Direct, demonstrable experience supporting client''''s cybersecurity programs and initiatives.

Similar jobs