Conduct ongoing security risk assessments using findings from cloud and Kubernetes posture reviews, vulnerability and CVE analysis, DISA STIG scans, network monitoring, software-supply-chain reviews, configuration-drift detection, and endpoint protection tools. Experience developing and maintaining RMF artifacts such as SSPs, control implementation statements, traceability matrices, PPSM packages, POA&Ms, risk assessments, assessment plans and reports, vulnerability results, and supporting evidence.