Security Compliance (ATO) Specialist

About Concept Plus

Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm.


Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty.


We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment.


For more information, visit www.conceptplus.com.


About the role

Concept Plus is seeking a Security Compliance (ATO) Specialist to ensure the client OCI/ExaCC and Cloudflare solutions meet FedRAMP High, NIST 800-53 r5, and HIPAA requirements, and supports continuous Authorization to Operate (cATO) processes across the program.


What you'll do

  • Map solution designs and configurations to FedRAMP High and NIST 800-53 r5 controls.
  • Support continuous ATO activities: control assessment, POA&M management, and evidence collection.
  • Advise architecture and engineering teams on compliant-by-design patterns and guardrails.
  • Review IaC and cloud configurations for security control coverage.
  • Support HIPAA and client security requirements and Section 508 compliance of deliverables.


Required Qualifications

  • US Citizen
  • Deep knowledge of FedRAMP High and NIST 800-53 r5.
  • Experience with ATO / continuous ATO processes in federal environments.
  • Cloud security assessment experience (OCI, AWS, or Azure).
  • Familiarity with HIPAA and healthcare data protection.
  • Ability to translate controls into actionable engineering guidance.
  • 7+ years information security/compliance with 3+ years supporting federal ATO.
  • Must satisfy client security requirements and obtain/maintain applicable client background investigation and clearance.


Preferred Qualifications

  • Prior CMS ATO experience.
  • Experience with GRC tooling and cloud-native security services (Cloud Guard).
  • CISSP, CCSP, or CAP certification.


Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.


Health/Federal Civilian Sector

Remote (United States)

Compartir en:

Condiciones del servicioPrivacidadCookiesDesarrollado por Rippling