Bachelor's degree in Cybersecurity, IT, Computer Science, Engineering, or related field, or equivalent experience.
10+ years of experience in cybersecurity or information assurance.
Must meet DoD 8140 Cyber Workforce Qualification Program requirements.
Relevant advanced certifications such as CISSP, CISM, CRISC, CISA, or SecurityX; CISSP or CISM preferred.
Significant hands-on experience with DoD RMF processes.
Experience with eMASS, NIST SP 800-37, NIST SP 800-53/53A, and DISA STIGs.
Responsibilities
Serve as the senior RMF/ISSM subject matter expert and technical lead.
Provide mentorship and guidance to a team of approximately nine RMF professionals.
Lead DoD RMF activities throughout the system lifecycle.
Develop and review security documentation and authorization artifacts.
Manage and review RMF packages in eMASS.
Support security control assessments and authorization reviews.
Analyze vulnerabilities and remediation strategies.
Benefits
Limited work-from-home flexibility based on mission requirements.
Opportunity to mentor and lead a team of cybersecurity professionals.
Engagement in high-stakes DoD RMF activities.
Access to advanced cybersecurity tools and frameworks.
Full Job Description
Principal Cybersecurity Analyst - RMF
Salary Range $130,000 to $145,000
We are seeking an experienced Principal Cybersecurity Analyst to serve as a senior technical lead supporting Department of Defense (DoD) Risk Management Framework (RMF) activities.
This position will provide technical leadership, mentorship, and guidance to a team of approximately nine cybersecurity professionals performing RMF and Assessment & Authorization (A&A) activities. This is a technical leadership position with no direct reports.
The position is primarily onsite with limited work-from-home flexibility, based on mission and customer requirements. An active DoD Secret clearance is required.
Key Responsibilities
Serve as the senior RMF/ISSM subject matter expert and technical lead.
Provide technical direction, mentorship, and guidance to a team of approximately nine RMF professionals.
Lead and support DoD RMF activities throughout the system lifecycle.
Develop and review SSPs, POA&Ms, security control implementation statements, assessment evidence, continuous monitoring documentation, and other authorization artifacts.
Manage and review RMF packages in eMASS.
Review team deliverables for technical accuracy, completeness, and compliance.
Support security control assessments, ATO activities, audits, and authorization reviews.
Analyze vulnerabilities, STIG findings, security risks, and remediation strategies.
Coordinate with ISSMs, ISSOs, System Owners, engineers, Security Control Assessors, and Authorizing Official representatives.
Mentor team members and serve as the escalation point for complex RMF and cybersecurity issues.
Requirements
Required Qualifications
Active DoD Secret security clearance.
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline, or an equivalent combination of education and relevant experience as permitted by contract requirements.
10+ years of cybersecurity, information assurance, information security, or related experience.
Candidate must meet applicable DoD 8140 Cyber Workforce Qualification Program requirements for the assigned work role and proficiency level.
Relevant advanced certifications such as: CISSP, CISM, CRISC, CISA, SecurityX, or other DoD-approved qualification options applicable to the designated work role. CISSP or CISM is strongly preferred.
Significant hands-on DoD RMF experience.
Experience with eMASS, NIST SP 800-37, NIST SP 800-53/53A, DISA STIGs, POA&Ms, vulnerability management, and ATO processes.
Experience providing technical leadership or mentorship to cybersecurity professionals.
Strong written, verbal, analytical, and customer-facing communication skills.
Preferred Qualifications
5+ years of direct DoD RMF experience.
Previous experience as an ISSM, senior ISSO, or RMF Lead.
Experience leading RMF/A&A activities for classified DoD systems.
Extensive hands-on eMASS experience.
Experience taking systems through initial or recurring ATO.
Experience with ACAS/Tenable, DISA STIGs, SCAP, and continuous monitoring.