This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a Risk Management Framework engineer responsible for a critical operational network. This role ensures systems are securely authorized to operate (ATO) by documenting compliance, and coordinating with technical and security stakeholders throughout the system lifecycle.
Job Responsibility:
Lead and support all phases of the Risk Management Framework (RMF) process in accordance with NIST SP 800-37, NIST SP 800-53 Security and Privacy Controls and related standards
Develop, maintain, and update RMF documentation including: System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms)
Coordinate security authorization packages for ATO decisions
Work closely with system engineers, network administrators, program managers, and security leadership
Participate in security working groups, technical reviews, and compliance audits
Communicate security posture and risk status to technical and non-technical stakeholders
Requirements:
Active TS/SCI with a current CI Polygraph
BS in Computer Science, Cyber Security, or related field
At least 3-5 years of experience
Demonstrated hands-on experience executing the RMF lifecycle (all or most phases)
Familiarity with federal cybersecurity compliance environments
One of more of the following active security certifications such as: CompTIA Security+, CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CIAM (Certified Identity and Access Manager)
Ability to operate independently and contribute immediately upon assignment
Self-motivated and eager to work intently to satisfy mission requirements
Adaptable and has the desire to maintain our company culture
Strong communication and coordination skills with technical and non-technical stakeholders
Experience in security working groups, technical reviews, and compliance audits
Ability to multitask and adjust priorities as needed
Nice to have:
Familiarity with current Information Assurance (IA) and cybersecurity tools such as vulnerability management and scanning tools
Experience with assessing security requirements and evaluating systems for gaps in security requirements