Title: Security Compliance SME
As a Security Compliance SME, you are responsible for attaining an Authority to Connect and an Authority to Operate in a
DISA Impact Level 5 security enclave. Duties include eMASS entrees and management of the eMASS profile. You will also
manage the ACAS platform and run daily vulnerability scans. You will assist in the development of the System Security Plan,
System Assessment Plan, Security Assessment Plan, Plan of Action & Milestones, Contingency Plan, Incident Response Plan,
Configuration Management Plan, and System and Communications Protection artifacts.
Required Skills
• 5+ yrs leading A&A for a FedRAMP or FISMA Moderate system through authorization and continuous monitoring.
• Demonstrated ownership of a FedRAMP significant change request, including direct 3PAO coordination (SAP scoping,
evidence packages, test support, SAR adjudication).
• Expert authorship of SSP control implementation statements against the NIST SP 800-53 Rev 5 Moderate baseline.
• Security impact analysis, change type determination, and risk-based recommendations to an AO.
• POA&M management, deviation requests, and monthly ConMon reporting.
• Working knowledge of UiPath sufficient to describe bot behavior, credentials, and data flows in control terms.
• Technical writing for AOs and assessors.