Security Authorization Specialist
Job Description
SECURITY AUTHORIZATION SPECIALIST ABOUT THE ROLE Second Front Systems (2F) is seeking an ambitious, highly autonomous, and detail-driven Security Authorization Specialist to join our mission-driven team. We are a dynamic, fast-growing entrepreneurial company at the intersection of cutting-edge technology and national security, committed to delivering transformative solutions that empower our nation’s defenders. This is an opportunity to play a leadership role in the security, trust posture, and operational execution of a company that is redefining how software is delivered and secured in the defense sector. At 2F, we thrive on innovation and purpose, combining a startup’s agility with a clear mission to support national security. As a Security Authorization Specialist, you will be the primary engine driving the authorization work behind the deployment and scaling of our revolutionary Game Warden platform—an industry-leading tool that is accelerating the secure adoption of mission-critical SaaS solutions for the U.S. government. If you’re ready to own complex compliance work streams, guide technical teams, and make a measurable impact on national security, we want to hear from you. The Security Authorization Specialist will fully own the technical implementation and documentation work streams that keep Game Warden authorized across FedRAMP and related US agency ATO programs. You will lead the authoring of control narratives, build and maintain rigorous authorization evidence, and drive continuous monitoring so our authorizations remain unassailable. Note: This role requires U.S. citizenship due to government contract requirements. Additionally, candidates must reside in one of our approved hiring hubs: DC/MD/VA | Raleigh/Durham/Chapel Hill, NC | Denver/Colorado Springs, CO | Dallas/Fort Worth, TX. WHAT YOU’LL DO (SCOPE OF RESPONSIBILITY) - Lead Authorization Work streams: Independently drive the end-to-end authorization lifecycle for Game Warden across FedRAMP and US agency ATO packages, managing initial authorizations, annual assessments, and significant change requests.
- Artifact Ownership: Author, refine, and maintain high-quality System Security Plans (SSPs), control implementation narratives, Plans of Action & Milestones (POA&Ms), and supporting authorization artifacts.
- Proactive Continuous Monitoring: Manage day-to-day continuous monitoring activities, including monthly POA&M updates, vulnerability and patch reporting, significant change reviews, and annual control assessments. Drive findings and control gaps to closure with engineering teams.
- Technical Point of Contact: Serve as the primary front-line technical point of contact for 3PAOs, agency reviewers, and sponsor authorization officials during assessments, readiness reviews, and audits.
- Engineering Partnership: Partner closely with Product, Engineering, Security Operations, and Cybersecurity Assessment teams to map complex cloud-native controls to FedRAMP and NIST 800-53 requirements, ensuring defensible evidence collection.
- Translate Policy to Tech: Act as a bridge between compliance and engineering.
- Leverage GRC Automation: Utilize and help optimize our GRC and evidence automation tooling to streamline control mapping and evidence collection. Write basic scripts or queries (e.g., Python, Bash, SQL, simple API calls) to automate repetitive compliance tasks and save the team time.
- Process Evolution: Contribute to the continuous improvement of 2F’s authorization processes, tooling, and evidence workflows as we scale our portfolio across frameworks and environments.
- Framework Expertise: Strong, practical working knowledge of NIST 800-53 (Rev 4/5), NIST 800-37 (RMF), and FedRAMP-specific guidance and templates.
- Cloud Architecture Literacy: Solid understanding of modern cloud environments and how cloud-native patterns (AWS services, containers, Kubernetes, CI/CD pipelines) map to technical controls.
- Assessment Track Record: Proven success supporting 3PAO assessments, annual reviews, or agency ATO efforts from the vendor or integrator side.
- Communication: Exceptional written communication skills; a proven ability to produce assessor-ready technical documentation and clear control narratives.
- Clearance & Certifications: - Active U.S.
- Active professional security certification such as CISSP, CISM, or Security+. PREFERRED QUALIFICATIONS - DoD Authorizations: Hands-on experience with DoD IL4/IL5 authorizations, DISA Cloud Computing SRG, or agency-specific ATO processes.
- GRC Tooling: Experience with modern GRC and evidence automation platforms (e.g., Drata, Xacta, RegScale, or similar), including configuring integrations and building reusable evidence workflows.
- Compliance-as-Code: Exposure to infrastructure-as-code (Terraform) and cloud-native observability tooling in support of automated, continuous control evidence.
- Mission Focused: Prior experience working in cleared or classified environments with government authorization stakeholders, and a strong interest in matters of national security.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.