Security Compliance (ATO) Specialist
About the role
Concept Plus is seeking a Security Compliance (ATO) Specialist to ensure the client OCI/ExaCC and Cloudflare solutions meet FedRAMP High, NIST 800-53 r5, and HIPAA requirements, and supports continuous Authorization to Operate (cATO) processes across the program.
What you'll do
- Map solution designs and configurations to FedRAMP High and NIST 800-53 r5 controls.
- Support continuous ATO activities: control assessment, POA&M management, and evidence collection.
- Advise architecture and engineering teams on compliant-by-design patterns and guardrails.
- Review IaC and cloud configurations for security control coverage.
- Support HIPAA and client security requirements and Section 508 compliance of deliverables.
Required Qualifications
- US Citizen
- Deep knowledge of FedRAMP High and NIST 800-53 r5.
- Experience with ATO / continuous ATO processes in federal environments.
- Cloud security assessment experience (OCI, AWS, or Azure).
- Familiarity with HIPAA and healthcare data protection.
- Ability to translate controls into actionable engineering guidance.
- 7+ years information security/compliance with 3+ years supporting federal ATO.
- Must satisfy client security requirements and obtain/maintain applicable client background investigation and clearance.
Preferred Qualifications
- Prior CMS ATO experience.
- Experience with GRC tooling and cloud-native security services (Cloud Guard).
- CISSP, CCSP, or CAP certification.
Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.