
Open role
ATO Manager / Sr. Cyber Security Engineer
Falcon IT and Staffing Solutions

Falcon IT and Staffing Solutions
Posted 2026-09-15
About the role
Role: ATO Manager / Senior Cybersecurity Engineer. Location: 100% Remote. Description: Seeking a highly skilled ATO Manager to lead our compliance and information assurance initiatives for the Department of Veterans Affairs (VA) Health Electronic Data Interchange (EDI) Xchange (HEDX) program. Leveraging extensive IT experience across a wide range of IT systems—including end-user health applications and enterprise-level EDI networks—you will serve as the principal cybersecurity authority driving HEDX through the federal Risk Management Framework (RMF). You will design, implement, and assess systems to ensure they meet agency cybersecurity policy and HIPAA regulations. As the primary liaison between technical teams and VA Authorizing Officials, you will utilize your deep expertise in CAM, cybersecurity tools, network topologies, intrusion detection, PKI, and secured networks to achieve and sustain the ATO for this critical healthcare data exchange. Job Responsibilities: VA Authorization Artifacts & GRC, CAM Management Lead the development, review, maintenance, and quality assurance of comprehensive VA security authorization packages within the Continuous Authorization and Monitoring (CAM) system. Develop and maintain required RMF and ATO artifacts, including the System Security Plan (SSP), Configuration Management Plan (CMP), Privacy Impact Assessment (PIA), Plans of Action and Milestones (POA&Ms), security control implementation narratives, assessment evidence, and supporting documentation. Ensure authorization artifacts remain accurate, complete, audit-ready, and perfectly aligned with the system architecture, network topologies, secured networks, implemented security controls, and current risk posture. VA Stakeholder & Agency Coordination Serve as a principal cybersecurity and authorization liaison between the HEDX program and VA security, privacy, technical, and program stakeholders. Collaborate with Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Control Assessors (SCAs), Authorizing Officials (AOs), the VA Office of Information Security (OIS), system owners, and engineering teams to coordinate RMF activities across a vast array of IT systems involving end-user as well as enterprise-level networks. Design and implement systems that meet agency cybersecurity policy and regulations, resolving compliance issues, addressing assessment findings, and facilitating successful authorization decisions. Continuous Monitoring (ConMon) & ATO Sustainment Establish and lead a comprehensive Continuous Monitoring (ConMon) program to maintain HEDX's security and compliance posture throughout the authorization lifecycle. Monitor security controls, vulnerabilities, assessment findings, configuration and system changes, POA&Ms, and remediation activities. Ensure critical defensive measures—including Intrusion Detection systems and PKI implementations—are continuously evaluated so cybersecurity risks are identified and addressed within established timelines. Proactively manage authorization dependencies and emerging risks to support ATO maintenance, renewal, and continued operational authorization. POA&M, Vulnerability & Remediation Management Own and manage the lifecycle of cybersecurity findings and POA&Ms, from initial risk assessment and assignment through remediation, evidence validation, and closure. Partner with application, infrastructure, network, cloud, engineering, and security teams to prioritize vulnerabilities and control deficiencies, leveraging enterprise cybersecurity tools to establish corrective actions. Ensure remediation is completed in accordance with applicable VA and federal cybersecurity requirements. Authorization Readiness, Risk Reporting & Governance Lead ATO readiness reviews, security assessments, and authorization preparation activities to ensure the HEDX environment remains prepared for VA security reviews and authorization decisions. Develop and communicate cybersecurity status reports, risk summaries, security metrics, outstanding findings, POA&M status, remediation progress, and authorization milestones to program leadership and VA stakeholders. Provide clear visibility into the system's overall security posture, residual risk, compliance status, and ATO readiness. Required Skills: Designing and implementing systems that strictly meet Veterans Affairs Cyber Security policies and regulations. Administration, assessment, or engineering of enterprise cybersecurity tools. Designing and securing complex network topologies and secured networks (e.g., VA Enterprise Cloud, Trusted Internet Connections (TIC)). Deploying and managing Intrusion Detection systems. Implementing and managing PKI (Public Key Infrastructure) for user authentication and secure data transmission. Experience working in a fast-paced, Agile software development environment. Must possess excellent problem-solving skills. Must be a U.S. Citizen or Permanent Resident. Must be able to obtain and maintain a Public Trust Security clearance. Desired Skills and Experience: Extensive direct experience with VA Continuous Authorization and Monitoring (CAM) and eMASS. Deep understanding of VA Directive 6500, VA Handbook 6500.3 (Certification and Accreditation), and HIPAA/HITECH security standards. Active cybersecurity certifications aligned with DoD 8140/8570 or VA equivalents (e.g., CISSP, CISM, CASP+, or CGRC). Education and Experience: Master's degree in computer science, Software Engineering, or a related field (or equivalent experience). 10+ years of experience in software development. 10 years of additional relevant experience may be substituted for education.
AI apply unlocks in the Sawell app
Prefer desktop? Sign in on web