user avatar

Compliance ATO Architect

steampunk

Posted today
Public Trust
Unspecified
Unspecified
McLean, VA (On-Site/Office)

Overview

The Compliance ATO Architect serves as a strategic technical and governance leader responsible for guiding systems through the full Authorization to Operate (ATO) process within federal environments. This role combines deep understanding of National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), security architecture, and cloud technologies to ensure systems are designed, implemented, and documented in accordance with federal security standards and agency-specific requirements. The Compliance ATO Architect partners closely with engineering, security, cloud, and compliance teams to translate controls into actionable architecture, develop required documentation, and ensure readiness for assessments and ongoing compliance activities.

Contributions

Responsibilities include:
  • Lead and manage the full ATO lifecycle for cloud and on-prem systems, ensuring compliance with NIST RMF, FedRAMP, and agency-specific requirements.
  • Design secure, compliant architectural patterns and guide engineering teams in implementing them.
  • Collaborate with development, platform, and infrastructure teams to ensure systems meet security control baselines.
  • Create, review, and update ATO documentation, ensuring completeness, accuracy, and audit readiness.
  • Conduct gap assessments, review security evidence, and coordinate remediation efforts.
  • Work with Information System Security Officers (ISSOs), system owners, security assessors, and Authorizing Officials to support risk determinations throughout the ATO process.
  • Implement continuous monitoring strategies and ensure ongoing compliance.
  • Advise leadership on risk posture, architectural tradeoffs, and compliance impacts across systems and services.


Qualifications

Required:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related field, OR equivalent experience.
  • Must be able to obtain and maintain a Public Trust clearance.
  • 8+ years of experience in cybersecurity, security architecture, or compliance supporting federal or regulated environments.
  • 5+ years of hands-on experience leading systems through the full Authorization to Operate (ATO) lifecycle in accordance with NIST RMF or FedRAMP.
  • Deep knowledge of NIST 800-53 security controls, FISMA requirements, and continuous monitoring practices.
  • Experience architecting secure solutions in cloud environments (AWS, Azure, GCP, and/or OCI), including identity management, network security, boundary protection, logging/monitoring, and encryption strategies.
  • Proven ability to translate compliance and security requirements into actionable technical architecture guidance for engineering, cloud, and development teams.
  • Experience creating and maintaining ATO documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Incident Response Plans, Contingency Plans, policies, and related artifacts.
  • Experience coordinating with ISSOs, Information System Security Engineers (ISSEs), Security Control Assessors (SCAs), PMs, and Authorizing Officials throughout the ATO lifecycle.
  • Understanding of Zero Trust principles and secure-by-design architectural approaches.
  • Strong ability to evaluate security evidence, conduct gap analyses, and drive remediation plans to closure.
  • Experience with compliance automation tools (e.g., Splunk, Prisma, ConMon tools, OpenSCAP, AWS Security Hub, Azure Security Center).
  • Excellent written and verbal communication skills, including the ability to clearly explain complex compliance requirements to technical and non-technical stakeholders.

Preferred:
  • Relevant certifications, such as:
    • Certified Information Systems Security Professional (CISSP)
    • Certified Cloud Security Professional (CCSP)
    • Certified Authorization Professional (CAP)
    • Certified Information Security Manager (CISM)
    • AWS, Azure, GCP, or OCI cloud security certifications
  • Experience leading ATOs for large-scale, mission-critical federal systems.
  • Experience performing or supporting security assessments (SCA).
  • Knowledge of DevSecOps practices and how to embed compliance into secure pipelines.
  • Knowledge of automation scripts or IaC tools (CloudFormation, Terraform, Ansible).


About steampunk

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company, we focus on investing in our employees to enable them to do the greatest work of their careers - and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visit http://www.steampunk.com .

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program.
group id: 10150207

Match Score

Powered by IntelliSearchâ„¢
image match score
Create an account or Login to see how closely you match to this job!

Similar Jobs


Clearance Level
Public Trust
Employer
steampunk