Want to know if you’re a fit? Upload your resume and let our AI show you.
Skills
Automationunmatched
Communication Skillsunmatched
Computer Securityunmatched
Customer Support/Serviceunmatched
Documentationunmatched
Federal Governmentunmatched
Financial Controlunmatched
Information Technology & Information Systemsunmatched
Internet Securityunmatched
Maintain Complianceunmatched
Network Administration/Managementunmatched
Network Operations Centerunmatched
Network Securityunmatched
On Site Supportunmatched
Privacy Controlsunmatched
Regulatory Complianceunmatched
Risk Analysisunmatched
Risk Managementunmatched
Risk Management Framework (RMF)unmatched
Secret Clearanceunmatched
Security Analysisunmatched
Security Monitoringunmatched
Security Protocolsunmatched
Systems Administration/Managementunmatched
Technical Writingunmatched
Testingunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
United States Department of Defense (DoD)unmatched
Work From Homeunmatched
Description
This position is for a RMF security engineer and requires 5 years of experience with RMF / Security Engineering. Provides end-to-end A&A support for DoD cybersecurity, privacy, and financial controls implementation, testing, monitoring, and enforcement. Interprets risks and recommends approaches to meeting DoD compliance and cybersecurity requirements in accordance with NIST Risk Management Framework (RMF) Controls and DoD Policy. As a member of this team, you will support the Defense Manpower Data Center (DMDC) IT GEMS program. You will primarily work remotely with occasional onsite support at the Marks Center in Alexandria, VA.
Required Skills/Experience:
5 years experience in an RMF / Security Engineering role to include:
Experience in mapping, implementing, interpreting, and documenting RMF security controls
Experience managing the eMASS cybersecurity management tool
Experience developing and submitting at least six (6) ATO packages
Secret Clearance
Additional requirements include:
Thorough understanding of the Risk Management Framework (RMF) Assessment and Authorization (A&A) process within the federal government, including knowledge of all phases of the RMF lifecycle.
Proven experience in assisting client risk management tasks, such as managing POA&M, conducting Security Tests and Evaluations (ST&E), creating system documentation, performing authorizations, carrying out risk assessments, handling third-party audits, ensuring compliance with NIST 800-53 standards, and performing threat assessments according to the RMF lifecycle and processes.
Demonstrated proficiency to plan and monitor security control implementation for the protection of networks, enclaves, and information systems.
Strong communication abilities, including working closely with highly technical administrators to enhance overall security measures.
Ability to generate and interpret ACAS scans to identify system vulnerabilities and monitor remediation efforts or mitigation strategies.
Working knowledge and experience implementing and evaluating manual Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP), and SCAP Compliance Checker (SCC).
Working knowledge of common assessment & authorization (A&A) application platforms e.g. eMASS, CSAM, Xacta, etc.
Previous experience in a technical role such as a system or network administrator is a plus.