Risk Management Framework Engineer

Leidos Holding$87K — $157K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity or related field and 3+ years of relevant experience
  • Experience with Department of Defense Risk Management Framework or similar authorization processes
  • Proficient in developing and maintaining cybersecurity authorization packages
  • Familiarity with System Security Plans, security controls, and compliance documentation
  • Skilled in identifying deficiencies and coordinating corrective actions
  • Experience in cybersecurity risk assessments and security testing

Responsibilities

  • Develop and maintain accurate Risk Management Framework authorization packages
  • Review and support System Security Plans and related documentation
  • Track authorization schedules and manage related workflows
  • Coordinate with stakeholders to gather required authorization artifacts
  • Identify and resolve issues related to authorization packets
  • Provide RMF guidance to stakeholders and assist with continuous monitoring
  • Conduct quality assurance reviews of RMF submissions before Government assessment

Benefits

  • Hybrid work locations in Alexandria, Virginia, and Seaside, California
  • Opportunity to work with a major partner in cybersecurity
  • Engagement in mission-critical Department of Defense projects
  • Collaborative environment with system owners and technical teams
  • Support for professional development and training opportunities
Full Job Description

Leidos is seeking an experiencedRisk Management Framework (RMF) Engineerto support theDefense Manpower Data Center (DMDC)CyberPRIMESprogram. Leidos is a major partner on the contract and will provide a substantialportionof the cybersecurity workforce supporting theDefense Human Resources Activity (DHRA)and DMDC. The RMF Engineer will support the development, maintenance, assessment, and authorization of cybersecurity packages for DHRA information systems. This position will work directly with system owners, cybersecurity personnel, and Government stakeholders to ensure authorization packages are complete, technicallyaccurate, current, and positioned to move efficiently through the Department of Defense authorization process.

Hybrid Work Locations:

Mark Center, Alexandria, Virginia

Department of Defense Center 6 Monterey Bay, Seaside, California

Clearance: Active Secret security clearance required at time of consideration. U.S. Citizen required.

Mission Environment

DMDC operates a large and complex Department of Defense information environment supporting personnel,manpower, identity, readiness, entitlement, and other mission-critical data and applications.CyberPRIMESsupports the cybersecurity governance and authorization activitiesrequiredtooperatethese systems securely. RMF Engineers will work across multiple authorization boundaries and coordinate with system owners,Information System Security Managers (ISSMs),Information System Security Officers (ISSOs), technical teams, assessors, and Government authorizing stakeholders. Theobjectiveis not simply tomaintaincompliance documentation. The RMF Engineer must understand the underlying system, evaluate how security controls are implemented,identifygaps that create authorization or mission risk, and help system owners move those issues to resolution.

Primary Responsibilities:

  • Develop, review, andmaintaincomplete andaccurateRisk Management Framework authorization packages.

  • Review and support development ofSystem Security Plans (SSPs), system categorization, security-control selection, control implementation documentation, assessment results, authorization packages, and continuous-monitoring reports.

  • Maintain RMF authorization schedules, trackers, repositories, workflows, accounts, tickets, and status information.

  • Maintain and update authorization packages within theEnterprise Mission Assurance Support Service (eMASS).

  • Coordinate with system owners, cybersecurity personnel, technical teams, and Government stakeholders to obtain required authorization artifacts and supporting evidence.

  • Identifymissing artifacts, incomplete documentation, control-implementation gaps, and other issues that may delay authorization.

  • Provide RMF andeMASSguidance to system owners and other program stakeholders.

  • Support Information System Security Manager and Information System Security Officer functions associated with system authorization and continuous monitoring.

  • Review security-control implementation and supporting evidence for completeness, technical accuracy, and compliance with applicable requirements.

  • Support cybersecurity compliance reviews and authorization-status reporting.

  • Develop, review, and trackPlan of Action and Milestones (POA&M)items through remediation and closure.

  • Track conditions associated with anAuthorization to Operate (ATO)and coordinate required corrective actions.

  • Perform quality assurance reviews of RMF submissions before Government review or assessment.

  • Support security-assessment planning, execution, documentation, and reporting.

  • Support continuous authorization and continuous-monitoring activities for authorized systems.

  • Assess the impact of changes in Department of Defense cybersecurity policy or authorization requirements andassistsystem owners in transitioning to new requirements.

  • Perform cybersecurity risk assessments and support security testing associated with system authorization.

  • Evaluate system hardening, vulnerabilities, configuration issues, and other technical security conditions that affect authorization risk.

  • Support vulnerability and compliance remediation activities associated with RMF findings and Plan of Action and Milestones items.

  • Troubleshoot cybersecurity compliance and authorization issues requiring coordination across system owners, engineers, administrators, cybersecurity teams, and Government stakeholders.

  • Provide clear status, risk, and technical information to Government leadershipregardingauthorization progress, deficiencies, and actionsrequiredfor resolution.

Basic Qualifications:

  • Bachelors degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and3 or more years of relevant professional experience. Specific experience, education and training may be considered in lieu of degree.

  • Experience supporting the Department of Defense Risk Management Framework or comparable Federal system authorization processes.

  • Experience developing, reviewing, ormaintainingcybersecurity authorization packages.

  • Experience working with System Security Plans, security controls, assessment artifacts, Plans of Action and Milestones, or continuous-monitoring documentation.

  • Experience assessing security-control implementation and supporting technical evidence.

  • Experienceidentifyingauthorization-package deficiencies and coordinating corrective actions with system owners and technical teams.

  • Experience supporting cybersecurity risk assessment, security testing, vulnerability analysis, system hardening, or compliance activities.

  • Strong technical documentation, organizational, and analytical skills.

  • Ability to manage multiple authorization activities, schedules, findings, and dependencies simultaneously.

  • Ability to work effectively with system owners, engineers, cybersecurity personnel, assessors, and Government stakeholders.

  • U.S. Citizenshiprequired.

  • ActiveSecret security clearancerequired.

Preferred Qualifications:

  • Experience supporting Department of Defense system authorization and continuous-monitoring programs.

  • Hands-on experience with Enterprise Mission Assurance Support Service.

  • Experience supporting Information System Security Manager or Information System Security Officer functions.

  • Experience developing or reviewing System Security Plans and security-control implementation statements.

  • Experience managing Plans of Action and Milestones and authorization conditions through closure.

  • Experience supporting security-control assessments, authorization decisions, and continuous authorization.

  • Experience assessing vulnerabilities, security configurations, and technical findings within an RMF authorization context.

  • Experience performing quality assurance reviews of authorization packages before Government submission.

  • Experience supporting multiple systems or authorization boundaries concurrently.

  • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments.



Original Posting:
September 2, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:
Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos Holding

Leidos Holding Careers

Joining Leidos Holding presents an unparalleled opportunity to advance one's career with a leader in innovation and technology. The company offers a plethora of job opportunities aimed at fostering professional growth and development in a diverse and inclusive environment.

Explore Career Opportunities

Leidos Holding is actively seeking skilled professionals who are passionate about leveraging their expertise to drive innovation and leadership in their fields. With a variety of open positions, Leidos Holding provides a platform for individuals to challenge themselves in a dynamic work environment.

Innovation and Professional Growth

At Leidos Holding, innovation is at the core of everything they do. Employees are encouraged to think creatively and push boundaries. The company supports this drive for innovation through comprehensive professional development and diversity training programs that are designed to enhance skills and foster leadership.

Commitment to Diversity and Inclusion

Leidos Holding is committed to creating a workplace where diversity is not only recognized but celebrated. With a culture that values and promotes diversity, Leidos Holding ensures that all team members have the opportunity to contribute, learn, and grow.

Internship Programs

For those starting their career, Leidos Holding offers internship programs that provide a robust foundation in the industry. Internships are a great way to develop essential skills, gain valuable work experience, and build professional networks.

Benefits and Culture

Employees at Leidos Holding enjoy a range of benefits designed to support their professional and personal lives. The company culture is built on a foundation of respect and integrity, providing a supportive and collaborative environment where every team member is valued.

Join the Team

Leidos Holding is hiring! Explore job opportunities that match your skills and interests. Leidos Holding looks for driven, curious, and innovative individuals to join their team. Positions are available across various disciplines and experience levels.

Stay Connected

Stay informed with the latest career tips, industry insights, and company news from Leidos Holding. Subscribe to receive updates and be the first to know about new job opportunities, company developments, and more.

Prepare for Your Interview

To prepare for an interview at Leidos Holding, candidates should familiarize themselves with the company's missions and values, update their resumes, and be ready to discuss how their background and skills align with the position they are applying for.

Networking and Career Advancement

Leidos Holding encourages its employees to engage in networking within the company to discover new opportunities for career advancement. The leadership team at Leidos Holding is dedicated to supporting employees in their career paths with ample opportunities for networking and growth.

Explore Leidos Holding Jobs and Careers

Discover the exciting career opportunities at Leidos Holding today. With a commitment to employee growth, innovation, and diversity, Leidos Holding is the perfect place to advance your career. Check out the latest job listings and find your perfect fit at Leidos Holding.

SEARCH LEIDOS HOLDING JOBS

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts and insider tips tailored to your preferences from Leidos Holding. See what exciting and rewarding opportunities await in your professional journey.
Learn more about Leidos Holding

Similar Jobs

More Jobs at Leidos Holding

More Aerospace & Defense Jobs

Find similar Risk Management Framework Engineer jobs: