Security Authorization Specialist

🔥 1 hour ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Second Front Systems

Second Front Systems

51 - 200 employees

☁️ SaaS

🏛️ Government

SaaS • Defense • Government

Second Front Systems is a public-benefit, venture-backed company that provides mission-critical software solutions primarily to democracies around the world. Their product suite, which includes the 2F Suite, 2F Workshop, 2F Game Warden, and 2F Frontier, simplifies and accelerates the software development and delivery process. The company is trusted by leading software providers and government agencies for its secure DevSecOps solutions, enabling secure software deployment on classified and unclassified networks. Their offerings include tools for secure development, software accreditation, government cloud hosting, and edge deployment, particularly focused on supporting government and defense sectors. Second Front Systems collaborates with partners to make emerging technologies more accessible, accelerating the accreditation and compliance processes and offering solutions that can operate in remote or disconnected environments, such as drones and vehicles.

📋 Description

• Lead Authorization Work streams: Independently drive the end-to-end authorization lifecycle for Game Warden across FedRAMP and US agency ATO packages • Artifact Ownership: Author, refine, and maintain high-quality System Security Plans (SSPs), control implementation narratives, Plans of Action & Milestones (POA&Ms), and supporting authorization artifacts • Proactive Continuous Monitoring: Manage day-to-day continuous monitoring activities, including monthly POA&M updates, vulnerability and patch reporting, significant change reviews, and annual control assessments • Technical Point of Contact: Serve as the primary front-line technical point of contact for 3PAOs, agency reviewers, and sponsor authorization officials during assessments, readiness reviews, and audits • Engineering Partnership: Partner closely with Product, Engineering, Security Operations, and Cybersecurity Assessment teams to map complex cloud-native controls to FedRAMP and NIST 800-53 requirements • Translate Policy to Tech: Act as a bridge between compliance and engineering • Leverage GRC Automation: Utilize and help optimize GRC and evidence automation tooling to streamline control mapping and evidence collection • Process Evolution: Contribute to the continuous improvement of 2F’s authorization processes.

🎯 Requirements

• 7+ years of experience in security compliance, cybersecurity authorization, or GRC work • Strong, practical working knowledge of NIST 800-53 (Rev 4/5), NIST 800-37 (RMF), and FedRAMP-specific guidance and templates • Solid understanding of modern cloud environments and how cloud-native patterns (AWS services, containers, Kubernetes, CI/CD pipelines) map to technical controls • Proven success supporting 3PAO assessments, annual reviews, or agency ATO efforts from the vendor or integrator side • Exceptional written communication skills; a proven ability to produce assessor-ready technical documentation and clear control narratives • Active U.S. Top Secret (TS) security clearance required; eligibility for access to Sensitive Compartmented Information (SCI) required • Active professional security certification such as CISSP, CISM, or Security+.

🏖️ Benefits

• Competitive Salary • 100% Healthcare, vision and dental coverage • 401(k) + 3% company contribution • Equity incentive plan • Tech + office supplies stipend • Annual professional development stipend • Flexible paid time off + federal holidays off • Parental leave • Work from anywhere • Referral Bonus

Apply Now

Similar Jobs

🔥 2 hours ago

EnableComp

501 - 1000

⚕️ Healthcare Insurance

☁️ SaaS

💸 Finance

AI Security Architect leading security efforts for AI and Machine Learning initiatives in the healthcare sector. Collaborating with teams to embed security in AI strategies and operations.

Azure

SDLC

🔥 3 hours ago

BHG Financial

1001 - 5000

💸 Finance

Senior Information Security GRC Specialist leading the Business Continuity and Disaster Recovery program at BHG Financial, committed to enhancing organizational resilience and risk management.

Cyber Security

🔥 3 hours ago

Barbaricum

201 - 500

🔐 Security

🏛️ Government

🏢 Enterprise

Cloud Security Engineer developing cloud security controls for USSOUTHCOM’s Enhanced Domain Awareness ecosystem. Ensuring compliance with NIST standards and enhancing cybersecurity infrastructure.

AWS

Azure

Cloud

Cyber Security

🔥 3 hours ago

The Hello Team

1001 - 5000

🤝 B2B

🎯 Recruiter

Senior Cybersecurity & Compliance Consultant leading assessments and guiding clients on compliance frameworks in healthcare. Collaborating with client teams to strengthen cybersecurity programs.

Cyber Security

🔥 4 hours ago

CDW

10,000+ employees

🏢 Enterprise

☁️ SaaS

🔒 Cybersecurity

Principal Solutions Executive focused on enhancing CDW Security's market presence in cybersecurity within the education sector in the Northeast. Engaging clients and managing full sales lifecycles.