second-front-systems - Security Authorization Specialist
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT
Requirements
• 5+ years of experience in security compliance, authorization, or GRC work, with hands-on FedRAMP experience. • Demonstrated success authoring and maintaining SSPs, POA&Ms, control narratives, and continuous monitoring artifacts for US federal authorization programs. • Strong working knowledge of NIST 800-53, NIST 800-37 (RMF), and FedRAMP-specific guidance and templates. • Practical understanding of modern cloud architectures and how common cloud-native patterns (AWS services, containers, Kubernetes, CI/CD) map to technical controls. • Experience supporting 3PAO assessments, annual reviews, or agency ATO efforts from a vendor or integrator side. • Excellent written communication; able to produce assessor-ready documentation and control language. • Active U.S. Top Secret (TS) security clearance required; eligibility for access to Sensitive Compartmented Information (SCI) required. • Active professional security certification such as CISSP, CISM, or Security+. • Experience with DoD IL4/IL5 authorizations, DISA SRG, or agency-specific ATO processes. • Familiarity with additional frameworks such as NIST 800-171, CMMC, ISO 27001, or NCSC cloud security principles. • Hands-on experience with GRC and evidence automation platforms (e.g., Drata, Xacta, or similar) including configuring integrations, tuning control mappings, and building reusable evidence workflows. • Exposure to infrastructure-as-code, observability, and cloud-native tooling in support of continuous control evidence (e.g., Terraform, AWS Config). • Prior experience working in cleared or classified environments and with government authorization stakeholders. • Have a strong interest in matters of national security • The expected base salary range for this role is $119,000 – $160,000. Final compensation will be based on factors such as experience, skills, level, and geographic location. This role may also be eligible for discretionary bonuses and equity grants as part of the total compensation package. • SUCCESS AT 2F LOOKS LIKE: • Viewing obstacles as opportunities for growth • Having a bias toward action and tangible, measurable results • Striving to be both compassionate and direct with your feedback • Being team-oriented and inclusive with your actions
Responsibilities
• Own the authorization workstreams for Game Warden across FedRAMP and US agency ATO packages, including initial authorizations, annual assessments, and significant change requests. • Author and maintain System Security Plans (SSPs), control implementation narratives, Plans of Action & Milestones (POA&Ms), and supporting authorization artifacts that accurately reflect our architecture, controls, and operating reality. Drive findings and control gaps to closure with measurable outcomes. • Drive continuous monitoring activities including monthly POA&M updates, vulnerability and patch reporting, significant change reviews, and annual control assessments. • Serve as a technical point of contact for 3PAOs, agency reviewers, and sponsor authorization officials during assessments, readiness reviews, and audits. • Partner closely with Product, Engineering, Security Operations, and Cybersecurity Assessment teams to map technical controls to FedRAMP and NIST 800-53 requirements, and to collect defensible evidence. • Translate complex regulatory requirements into clear, actionable guidance that engineering teams can implement, not just policy language. • Use and help improve our GRC and evidence automation tooling to streamline control mapping, evidence collection, and continuous monitoring, writing basic scripts or queries (e.g., Python, Bash, SQL, simple API calls) where they save the team time. • Contribute to the evolution of 2F’s authorization processes, tooling, and evidence workflows as we scale our portfolio across frameworks and environments.
Benefits
• As a public benefit corporation, we’re a team of purpose-driven trailblazers transforming the future of U.S. national security. We hire the best to do their best and, as such, we are committed to providing the perks and benefits you need to be successful—both in- and outside the workplace. • 100% Healthcare, vision and dental coverage • 401(k) + 3% company contribution • Equity incentive plan • Tech + office supplies stipend • Annual professional development stipend • Flexible paid time off + federal holidays off • Parental leave • Work from anywhere • Referral Bonus • Visit our careers page https://www.secondfront.com/company/careers to learn more.
No credit card. Takes 10 seconds.