Just postedUrgently hiring Use left and right arrow keys to navigate
Based on similar jobs in your market
Estimated Pay info$17 per hour
Hours Full-time
Location Kansas City, Missouri

About this job

  

Aspis strives to make enterprise cybersecurity solutions and professional services accessible to organizations of all sizes, from small and medium-sized businesses to large enterprises, nonprofits, and municipal, state, and federal government agencies. Aspis is a HUBZone-certified small business. Our values are Integrity, Community, and Diversity.  


Aspis is hiring a Compliance / ATO Specialist to own security compliance and authorization work on a large Federal civilian cloud platform operations and maintenance program. The environment is hybrid: a FedRAMP-authorized AWS commercial cloud footprint alongside Azure, on-premises data centers, and legacy and mainframe-connected applications supporting hundreds of business applications. You will keep authorization packages current, run the continuous monitoring and POA&M cadence, maintain the compliance evidence repository, and carry the compliance story through FISMA reporting, A-123 testing, independent assessments, and penetration test cycles. It is the role that protects authorization continuity for the program, working closely with cybersecurity engineers, cloud engineers, system owners, and government stakeholders.


This is a full-time W-2 position supporting a federal government client as part of a contract delivery team. This is not designed to be a full-time remote position. Relocation assistance may be considered. The Kansas City, Missouri metropolitan area is strongly preferred and candidates who reside in and can work from the Kansas City metro will receive preference; however, residency there is not required, and we will consider candidates elsewhere in the United States who are able to travel to the client sites as needed. Due to the support a federal client, working abroad (outside of the United States) is explicitly prohibited. Travel to Kansas City for remote workers will not be reimbursed. Consistent with Aspis' return to office and telework policy, employees are required to report to an Aspis office on a regular basis but may be allowed to work from home and are required to visit client job sites as applicable. The company reserves the right to change its employment policies at any time without notice.


To be considered for this position, your resume must clearly document knowledge, skills, experience, and abilities similar to the responsibilities, qualifications, and requirements below.


A Cybersecurity Analyst may perform any combination of the functions below based on assignment and experience level.


Responsibilities

  • Prepare and maintain assessment and authorization packages under the Risk Management Framework, including System Security Plans, control implementation statements, and risk documentation.
  • Run the continuous monitoring cadence: control assessment scheduling, evidence collection, and posture reporting.
  • Maintain a living POA&M inventory, conduct aging reviews, and escalate items at risk of breaching remediation service levels before they slip.
  • Support FISMA reporting, OMB A-123 general computer controls testing, independent assessments, penetration tests, and contingency and disaster recovery exercises.
  • Maintain the standards compliance matrix and the deviation and waiver log, and keep the compliance evidence repository audit-ready.
  • Perform security impact analyses for proposed changes, migrations, and new services, and verify FedRAMP authorization status for proposed tooling.
  • Track vulnerability remediation status against contract thresholds and coordinate closure with engineering teams and system owners.
  • Improve and automate compliance and posture reporting to reduce manual evidence collection.
  • Communicate compliance findings and risk positions clearly to technical and non-technical stakeholders, and support knowledge transfer to government staff.
  • Other duties as assigned.


  Qualifications

  • Demonstrated hands-on RMF work in a cloud or hybrid environment.
  • Working knowledge of NIST SP 800-53 Rev 5, NIST SP 800-37, FISMA, and FedRAMP, and familiarity with Federal audit cycles.
  • Experience authoring or maintaining SSPs, control implementation statements, POA&Ms, and risk documentation.
  • Working familiarity with AWS and Azure security services sufficient to validate controls and collect evidence.
  • Clear, professional written and verbal communication, including the ability to produce security documentation that holds up under audit.
  • Strong analytical skills, attention to detail, and comfort tracking many open items to closure.
  • Ability to manage multiple assignments and deadlines with limited day-to-day oversight.
  • Discretion in handling sensitive client, system, and company information.
  • Ability to obtain and maintain a Federal Public Trust background investigation.

Skills:

  • RMF and authorization documentation, continuous monitoring, POA&M management, audit and assessment support, and cloud compliance evidence collection.
  • GRC software (e.g., eMASS, Xacta, CSAM, Archer, etc.)
  • Microsoft Office Suite (e.g., Word, PowerPoint, Excel, etc.)
  • Strong verbal and written communication skills.


Background Check: 

  • Successful completion of reference check.
  • Successful completion of a commercial background check.
  • Authorized to work in the United States without sponsorship.
  • Successful completion of an OF-306 (as a contractor).
  • Successful completion of a Federal Public Trust background check required.


Degree Required: Associate's degree or higher preferred; equivalent experience and/or certifications considered in lieu of a degree.


Experience Required: 3-8 years of relevant cybersecurity experience.


Industry Certifications: CompTIA Security+ (or equivalent) required; CGRC (formerly CAP), CISA, CISM, CCSP, or CISSP preferred.


We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veteran status, or any other characteristic protected by law. We will consider for employment qualified applicants with criminal histories consistent with applicable law.

  





PI2b0edf9d0fe0-31181-41357907


Nearby locations

Posting ID: 1289183981 Posted: 2026-08-19 Job Title: Loss Prevention Officer