Key ResponsibilitiesSupport execution of the RMF process across all six steps: Categorize, Select, Implement, Assess, Authorize, and MonitorDevelop, review, and maintain security authorization documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports (RARs)Conduct security control assessments against NIST SP 800-53/800-53A control baselines and document findingsPerform security categorization of information systems using FIPS 199/200 and NIST SP 800-60Coordinate with system owners, ISSOs, and ISSMs to identify, track, and remediate security vulnerabilities and control deficienciesSupport continuous monitoring activities, including periodic control assessments, vulnerability scanning review, and configuration compliance checksAssist in the preparation and submission of Authorization to Operate (ATO), Interim ATO (IATO), and Authorization to Test (ATT) packagesUtilize GRC tools (e.g., eMASS, Xacta, CSAM, Archer) to manage authorization packages and track compliance statusReview and analyze security assessment results, audit logs, and scan reports (e.g., ACAS/Nessus, STIG checklists) to identify risksSupport development and tracking of POA&Ms, ensuring timely remediation of identified weaknessesEnsure compliance with applicable frameworks, including FISMA, DoD RMF, CNSSI 1253, and agency-specific cybersecurity policiesPrepare risk briefings and status reports for leadership, Authorizing Officials (AOs), and government stakeholdersStay current on evolving NIST guidance, DoD/agency policy updates, and emerging cybersecurity threats affecting authorization requirementsRequired QualificationsBachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field (or equivalent experience)3+ years of experience supporting RMF, C&A/A&A processes within federal, DoD, or Intelligence Community environmentsWorking knowledge of NIST SP 800-37, 800-53, 800-53A, 800-60, and FIPS 199/200Experience developing or reviewing SSPs, SARs, POA&Ms, and RAR documentationFamiliarity with DoD or agency-specific implementation guides (e.g., DoDI 8510.01, Citizenship required; active security clearance or eligibility to obtain one, per position requirementsPreferred QualificationsActive Secret clearanceCISSP, CAP (Certified Authorization Professional), or CISM certificationExperience with cloud authorization processes (FedRAMP, DoD Cloud Computing SRG)Familiarity with vulnerability scanning tools (ACAS/Nessus, Tenable) and SCAP compliance checkersExperience supporting Cybersecurity Service Provider (CSSP) or SOC operationsKnowledge of Zero Trust Architecture principles and their application to RMFExperience working within Intelligence Community (IC) or Defense Industrial Base (DIB) environments About Semper Valens Solutions:Semper Valens Solutions, Inc. (SVS) is a Service-Disabled Veteran Owned Small Business (SDVOSB) providing Cost Effective Software and Systems Engineering, Field Support, Training and Full Life cycle Support Management to the DOD and VA community.