About this role
The ATO / Risk Management Framework Lead plans and drives the path to an
Authorization to Operate (ATO) and then keeps the system authorized. ACF won't
let any production system, MIS, dashboard, portal, data repository, or external
facing platform that processes Federal information operate until ACF confirms
the authorization path, whether a full ATO, a provisional ATO, or a written ACF
OCIO determination that no ATO is required. ACF expects the ATO process to take
about six months, on a schedule the ACF OCIO approves no later than 30 days
after award. The lead builds the authorization package, coordinates assessment
and testing, resolves findings, runs continuous monitoring, and owns the
privacy and security activities Task 9 requires, including incident reporting
and the flow down of requirements to anyone CDIT brings onto the work. The lead
works most closely with the Cloud / Solution Architect, who designs the
environment the package describes.
Responsibilities
· Within
30 days after award, lead the draft Privacy Threshold Analysis and Privacy
Impact Assessment support package and the Data Security Plan for the COR and
the ACF OCIO reviewers, describing data flows, system boundaries, user roles,
encryption, access controls, audit logging, retention, destruction, incident
response, subcontractor access, and privacy protections (RFQ Task 9.4).
· Work
with the COR and ACF to determine the type and sensitivity of the CUI involved
and whether an ATO is required, and recommend the most efficient authorization
path among the ACF Tech ATO types, including inheritance from a FedRAMP
authorized environment and the ACF Authority to Use (ACF Tech Appendix D).
· Propose
the ATO schedule for ACF OCIO approval no later than 30 days after award and
manage the authorization effort to it (RFQ Task 10).
· Categorize
the system under FIPS 199 and FIPS 200 and select, tailor, and document the
NIST SP 800-53 control baseline for a Moderate system, applying NIST SP 800-18,
NIST SP 800-171, DISA STIG hardening guidance, OMB Memorandum M-05-22, and HHS
and ACF policy.
· Author
and maintain the authorization package deliverables listed below on the
schedule ACF Tech approves, including the annual System Security Plan update,
the annual assessment, the quarterly POA&M update, and the annual
contingency plan test.
· Coordinate
the security assessment with the assessor, support testing, track every
finding, and drive remediation or risk acceptance to closure.
· Document
the Zero Trust implementation approach and expected maturity level and manage
the quarterly Zero Trust scorecard submissions for the system (ACF Tech
Appendix B and Appendix C).
· Run
continuous monitoring under FISMA and NIST SP 800-137: monthly vulnerability
scans with an ACF Tech approved tool, patch management, log review, account
review, configuration management, and POA&M updates on the schedule ACF
OCIO approves. Report critical and high vulnerabilities to the COR and
remediate them within ACF approved timeframes (RFQ Task 10).
· Maintain
the authorization boundary and all security documentation throughout the period
of performance, and submit changes through ACF change control before
implementation.
· Own
incident reporting: any suspected or confirmed breach, cyber incident,
unauthorized disclosure, lost device, or exposure of information that isn't
public is reported immediately, within one hour at most, through CDIT and
Guidehouse to the Contracting Officer, the COR, and the ACF Incident Response
Team, with logs and evidence preserved and full cooperation with ACF and HHS
response (RFQ Task 9.5 and Section 4.0).
· Assess
whether any data the program collects, stores, transmits, or analyzes is
Protected Health Information and whether CDIT or any subcontractor is a HIPAA
business associate, and if so support the Business Associate Agreement and the
required safeguards (RFQ Task 9.6).
· Support
the Data Inventory and Data Minimization Plan before any data is collected,
confirming that no Social Security numbers or other high risk identifiers are
collected without written COR approval (RFQ Task 6.3).
· Complete
the electronic authentication risk assessment with the system owner and ISSO to
set the identity, authentication, and federated assurance levels (RFQ Section
4.0).
· Flow
the privacy, security, records, incident reporting, and training requirements
down to any subcontractor, consultant, or vendor CDIT uses, track the required
training certificates, and keep the records that show compliance (RFQ Tasks 9.2
and 9.3).
· Support
the Sustainability and Transition strategy with the security documentation,
data handling, and media sanitization under NIST SP 800-88 needed for a
complete and secure transfer at the end of the contract (RFQ Task 8).
Required qualifications
· Bachelor's
degree.
· At
least 7 years in federal information security, with hands on Risk Management
Framework work under NIST SP 800-37 and NIST SP 800-53.
· Has led
at least one federal system through assessment to a signed ATO, including
writing the System Security Plan, supporting the assessment, and managing the
POA&M.
· FedRAMP
knowledge, including control inheritance from an authorized cloud environment
and the customer responsibility matrix.
· Continuous
monitoring and vulnerability management with enterprise scanning tools,
including reading results and driving remediation.
· Working
knowledge of FISMA, the Privacy Act, HIPAA security requirements, and federal
incident reporting obligations.
· Clear
technical writing and the ability to coordinate assessors, developers, and
Government reviewers to a schedule.
· Public
Trust Tier 2 clearance, held or obtainable.
Desired qualifications (CDIT
additions, not conditions of the subcontract)
· CISSP,
CGRC (formerly CAP), CISM, or an equivalent security certification.
· Prior
ATO work at HHS or an HHS operating division, and familiarity with the HHS and
ACF security program and templates.
· Experience
with a governance, risk, and compliance tool used for federal authorization
packages.
· Experience
producing Zero Trust scorecards against the CISA Zero Trust Maturity Model.
· Privacy
credential such as CIPP/G, or experience preparing Privacy Threshold Analyses
and Privacy Impact Assessments.