<p style="text-align:justify;"><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><strong><span style="padding:0px;line-height:18px;"><span style="padding:0px;">The following states/districts are excluded from this job ad: AK, CA, CO, </span></span><span style="padding:0px;"><span style="padding:0px;line-height:18px;"><span style="padding:0px;">CT, DC, HI, LA, </span></span></span></strong><span style="padding:0px;line-height:18px;"><strong><span style="padding:0px;">MA, MN, MO, NE, NV, NH, NJ, NM, NY, ND, OR, PR, RI, VT, </span></strong><span style="padding:0px;"><strong>WA, WY</strong></span></span></span></p>
<p style="text-align:justify;"><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><span style="padding:0px;line-height:18px;"><span style="padding:0px;"><strong>Future Need - Actively Interviewing</strong></span></span></span></p>
<p><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><strong>Location: </strong>Remote in any United States jurisdiction not excluded from this job advertisement. </span></p>
<p style="text-align:justify;"><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">As the RMF, Security & ATO Manager, you will lead Risk Management Framework, cybersecurity, and Authority to Operate activities for a complex multi-tenant cloud environments ensuring continuous compliance, zero ATO lapses, and a proactive security posture across a healthcare platform and all hosted tenant applications.</span></p>
<p style="text-align:justify;"><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><strong>Position Description: </strong>The Risk Management Framework (RMF), Security & Authority to Operate (ATO) Manager serves as the lead for cybersecurity compliance, RMF implementation, and authorization activities supporting a mission-critical VA healthcare platform.</span></p>
<p><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><strong>Minimum/General Experience: </strong>10 years of experience in federal cybersecurity, information assurance, RMF compliance, and ATO processes </span></p>
<p><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><strong>Minimum Education: </strong>Bachelor's Degree in cybersecurity, information assurance, computer science, or related field</span></p>
<p><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><strong>Essential Skills/Qualifications:</strong></span></p>
<ul>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Expert ability to ensure all security and authorization activities are executed in accordance with approved cybersecurity policies, RMF processes, and Government security requirements</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Expert experience managing RMF and ATO processes for complex enterprise or mission-critical systems</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Expert knowledge of the NIST RMF steps (e.g., Categorize, Select, Implement, Assess, Authorize, Monitor)</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Expert experience managing federal ATO/ATC packages, continuous monitoring programs, and POA&M lifecycle management</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Expert understanding of VA Office of Information Technology (OI&T) security governance, directives, and VA Handbook 6500 series</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Excellent knowledge of Federal cybersecurity frameworks, security compliance processes, and continuous monitoring practices</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Excellent experience conducting and coordinating security audits</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Excellent ability to produce and maintain all required RMF security documentation</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Excellent knowledge of multi-tenant ATO inheritance frameworks, authorization boundaries, and security control allocation between platform and tenant layers</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Above average experience with vulnerability scanning tools (e.g., Nessus), Static Application Security Testing (SAST) integration, and vulnerability remediation tracking</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Above average knowledge of healthcare and privacy control implementation in a cloud-hosted environment</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Knowledge of VA Technical Reference Model (TRM) submission processes, connection management, and credential/account access audit requirements</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Experience using SNOWCAM</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Experience supporting Federal Government programs and systems operating in cloud or hybrid environments</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Excellent verbal and communication skills</span></li>
</ul>
<p><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><strong>General Physical Requirements needed to perform the essential functions of this job may vary based on the location of the assignment</strong>.</span></p>
<ul>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Assignment Location - Remote</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Sedentary Work - Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Typing, communicating, repetitive motions.</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Close visual acuity to prepare and analyze data, view computer monitors and read. May need to view presentation screens and other visual aids in a virtual setting.</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Inside environmental conditions with protection from outside elements.</span></li>
</ul>
<p><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><strong>Security</strong>: Active Federal Civilian Public Trust clearance</span></p>
<ul>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">U.S. Citizenship or Permanent Resident that has lived in the United States for at least 3 years</span></li>
</ul>
<p><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><strong>Federal Civilian Public Trust </strong>Consists of a review of up to but not limited to:</span></p>
<ul>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Covers 10 year period and in some instances lifetime events</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">OPM Security Investigations Index (SII)</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">DOD Defense Central Investigations Index (DCII)</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">National Agency Check (NAC) records</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">FBI name check</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">FBI fingerprint check</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Credit report check</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Written inquiries to previous employers and references listed on the application for employment</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Potential interviews with the subject, spouse, neighbors, supervisor, coworkers</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Law enforcement check</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Court records check</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Education check - Attendance and Degrees</span></li>
</ul>
<p style="text-align:justify;"><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><strong>Tasks/Activities include, but are not limited to:</strong></span></p>
<ul>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Maintains regular communication with the Contracting Officer's Representative (COR) and Government cybersecurity leadership regarding system authorization status, security posture, and risk mitigation activities</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Manages all six steps of the NIST RMF process for the VA healthcare platform and all hosted applications</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Ensures zero lapses in ATO status</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Initiates, manages, and sustains all ATO/ATC packages including periodic assessment oversight, activities, and staffing of all ATO audits</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Leads and coordinates all security audits and assessments including internal and external assessment teams</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Attends all audit meetings, provides documentation, and reviews all findings for accuracy</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Develops and maintains the platform authorization strategy defining ATO inheritance frameworks, tenant onboarding standards, and platform security guardrails</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Creates and maintains all POA&Ms ensuring proper NIST security family alignment, mapping, milestone accuracy, and timely closure of findings</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Produces and delivers monthly RMF, security, and ATO status reports</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Conducts and maintains incident response and disaster recovery tabletop exercises annually or as mandated</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Reports exercise results to leadership and implements all corrective actions</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Manages credential and account audits</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Submits and maintains internal and external connection requests</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Manages full lifecycle connection requests (e.g., submission, approval, removal)</span></li>
<li><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Ensures full compliance with all applicable VA security and privacy directives</span></li>
</ul>
<p><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;"><strong>Compensation & Benefits: </strong>The annual projected pay range for this position is $131,725 - $171,026 with consideration being given to various factors including but not limited to qualifications, experience, job responsibilities, and geographic location. </span></p>
<p><span style="font-family:'times new roman', times, serif;color:#000000;font-size:12pt;">Oxley Enterprises, Inc. offers a full array of benefits including:</span></p>
<ul>
<li><span style="font-family:'times new roman', times, serif;color:#000000;font-size:12pt;">Medical, dental, vision and prescription drug coverage for you and your family.</span></li>
<li><span style="font-family:'times new roman', times, serif;color:#000000;font-size:12pt;">Life Insurance, short-term disability and long-term disability paid for by the Company.</span></li>
<li><span style="font-family:'times new roman', times, serif;color:#000000;font-size:12pt;">Supplemental coverages including Accident, Critical Illness, and Hospital.</span></li>
<li><span style="font-family:'times new roman', times, serif;color:#000000;font-size:12pt;">Additional Life insurance coverage for you and your dependents. </span></li>
<li><span style="font-family:'times new roman', times, serif;color:#000000;font-size:12pt;">401k plan with various options to select based on your retirement goals.</span></li>
</ul>
<p><span style="font-family:'times new roman', times, serif;font-size:12pt;color:#000000;">Oxley Enterprises®, Inc. is a certified service-disabled veteran-owned (SDVOSB), veteran-owned (VOSB), and woman-owned small business (WOSB) that has 26 years of experience building and delivering quality IT systems and programs. Oxley is ranked in the INC 5000 7 times (2016, 2017, 2018, 2021, 2023, 2024, 2025). Oxley is a 2019 - 2025 Department of Labor HIRE Vets Medallion Award Winner. Oxley is Virginia Values Veterans certified.</span></p>
<p><span style="font-size:12pt;font-family:'times new roman', times, serif;color:#000000;">All qualified applicants will receive consideration for employment without regard to any status protected by applicable federal, state, or local law.</span></p>
<p style="background:#FFFFFF;"><span style="font-size:12pt;font-family:'times new roman', times, serif;color:#000000;">If you require a reasonable accommodation to apply for a position at Oxley Enterprises, Inc., please send an email to our Human Resources Department at: <a href="mailto:careers@oxleyenterprises.com">careers@oxleyenterprises.com</a> with the following information:</span></p>
<p style="background:#FFFFFF;"><span style="font-size:12pt;font-family:'times new roman', times, serif;color:#000000;">Subject Line: Accommodation Request</span></p>
<p style="background:#FFFFFF;"><span style="font-size:12pt;font-family:'times new roman', times, serif;color:#000000;">Provide a description of your accommodation request</span></p>
<p style="background:#FFFFFF;"><span style="font-size:12pt;font-family:'times new roman', times, serif;color:#000000;">Include your contact information: Full name, Email address, Best number to reach you (optional)</span></p>
<p style="background:#FFFFFF;"><span style="font-size:12pt;font-family:'times new roman', times, serif;color:#000000;">We participate in the E-Verify program. <a href="http://www.dhs.gov/E-Verify">http://www.dhs.gov/E-Verify</a></span></p>