We are seeking a highly motivated and experienced Cybersecurity Specialist or Authorization Program Lead to serve in a project management function over our Authorization to Operate (ATO) process for the Department of Defense (DOD) and government agency clients that we support. The ideal candidate will have a strong background in the full lifecycle of the Risk Management Framework (RMF) and a deep understanding of the DOD Agency ATO process. This role will involve working with various stakeholders to ensure that systems and applications meet security requirements and are authorized for operation.
Key Responsibilities:- RMF and ATO Management: Lead and support the full lifecycle of the Risk Management Framework (RMF) process, from system categorization to continuous monitoring. Manage and track all activities required to achieve an Agency Authorization to Operate (ATO) across multiple concurrent ATOs. Establish a repeatable and scalable process to be used for all DOD and Agency ATOs.
- Documentation and Artifacts: Develop, review, and maintain all required security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Actions and Milestones (POA&Ms), and Consequence of Operations (CONOPS) plans.
- Security Control Assessments: Conduct comprehensive security control assessments and evaluations to ensure compliance with DOD and government security policies, including NIST SP 800-53, DISA STIGs, and other relevant directives.
- Collaboration: Work closely with system owners, developers, ISSOs, and other stakeholders to identify, document, and mitigate security vulnerabilities and risks.
- Vulnerability and Risk Management: Develop and manage Plan of Actions and Milestones (POA&Ms) to track and remediate identified vulnerabilities. Provide expert guidance on risk mitigation strategies.
- Policy and Compliance: Interpret and apply federal and DOD cybersecurity policies and regulations, providing guidance to project teams to ensure compliance.
- Reporting and Briefings: Prepare and present status updates, reports, and security briefings to management and government clients.
- Continuous Monitoring: Support the continuous monitoring program by conducting regular security reviews, vulnerability scans, and audits to maintain the security posture of authorized systems.
Required Qualifications:- Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. Equivalent experience may be considered in lieu of a degree.
- Experience: 7+ years of experience in a cybersecurity role, specifically supporting DOD or other federal government Authorization to Operate (ATO) efforts.
- RMF Expertise: In-depth knowledge of the NIST Risk Management Framework (RMF) and its application in the DOD environment.
- Technical Knowledge: Familiarity with cybersecurity tools and technologies, including vulnerability scanners (e.g., ACAS/Nessus), GRC platforms (e.g., eMASS, Xacta), and security information and event management (SIEM) systems.
- Communication: Excellent written and verbal communication skills, with the ability to effectively communicate complex technical information to both technical and non-technical audiences.
- Attention to Detail: Strong organizational skills and meticulous attention to detail are crucial for managing complex documentation and compliance requirements.
Preferred Qualifications:- Experience with specific DOD systems and processes (e.g., eMASS, RMF Knowledge Service, etc.).
- Experience with AI tools to streamline the ATO process.
- Experience with cloud security and supporting ATOs for cloud-based systems (e.g., FedRAMP, DOD Cloud SRG).
- Knowledge of specific government agency policies (e.g., FISMA, FedRAMP).
- Experience with a scripting language (e.g., Python, PowerShell) for automation task
------------
KPMG Assignment Select is geared toward independent professionals interested in temporary or project-based work. Our team is comprised of highly trained third-party professional individuals who are in the right place, at the right time, with the right skillset.
KPMG is working through its partnership with MBO Partners and is currently seeking a remote contractor in the United States.
Act with integrity, professionalism, and personal responsibility to uphold the firm’s respectful and courteous work environment
Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
KPMG complies with all local/state regulations in regard to displaying pay rate ranges. The pay rate range(s) displayed is/are specifically for those contracted who will perform work in or reside in the location(s) listed below, if selected for the role. Pay is determined based on a variety of factors including market data, ranges, applicant's skills and prior relevant experience, certain degrees and certifications (e.g. JD, technology), and specific location, for example. Additionally, applicants may be required to apply and become employed by a service provider utilized by KPMG, and final pay rate(s) and/or eligibility for additional benefits may be determined by such provider.
KPMG and MBO Partners are equal opportunity employers/contractors. All qualified applicants are considered without regard to race, color, creed, religion, age, sex/gender, national origin, ancestry, citizenship status, marital status, sexual orientation, gender identity or expression, disability, physical or mental handicap unrelated to ability, pregnancy, veteran status, unfavorable discharge from military service, genetic information, or other legally protected status.
Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Pay Rate Range
Min Pay Rate
Max Pay Rate
Currency
Unit
180
200
USD
hourly