PeopleTec

Risk Management Framework (RMF) Specialist

PeopleTec$95K — $115K *
Aerospace & Defense
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8-10 years of experience in cybersecurity and RMF within DoD or federal environments.
  • Proven expertise leading systems through the DoD RMF lifecycle for successful ATOs.
  • In-depth knowledge of DoD cybersecurity policies and RMF frameworks, including NIST and STIGs.
  • Proficiency with vulnerability assessment tools such as ACAS/Nessus and eMASS.
  • Strong analytical skills for developing remediation and risk mitigation strategies.
  • Excellent verbal, written, and interpersonal communication skills.
  • Must possess an active DoD Secret clearance.

Responsibilities

  • Lead the creation and delivery of RMF documentation and associated artifacts.
  • Guide systems through the entire RMF lifecycle from categorization to reauthorization.
  • Advise stakeholders on implementing DoD cybersecurity requirements and best practices.
  • Develop strategies to mitigate security control deficiencies and vulnerabilities.
  • Analyze vulnerability assessment data to identify risks and formulate mitigation strategies.
  • Mentor junior RMF personnel and enhance RMF processes across the organization.
  • Provide continuous support for cybersecurity monitoring and compliance activities.

Benefits

  • Comprehensive health and wellness programs.
  • Generous vacation and leave policies.
  • Opportunities for professional development and training.
  • Flexible work arrangements to support work-life balance.
  • Collaborative and innovative work environment.
Full Job Description
Opportunity

PeopleTec is currently seeking aRisk Management Framework (RMF) Specialist to support our Huntsville, AL location.

PeopleTec, Inc. is seeking a highly experienced and motivated RMF Specialist to assist with the development, implementation, assessment, and sustainment of RMF packages supporting digital engineering and digital ecosystem initiatives. A successful candidate will provide cybersecurity and RMF expertise, ensure compliance with Department of Defense (DoD) cybersecurity requirements, and lead efforts to achieve and maintain Authority to Operate (ATO) for complex, distributed digital engineering environments.

This position will serve as a cybersecurity advisor to program leadership, engineering teams, system owners, and other stakeholders, providing guidance throughout the RMF lifecycle and helping organizations identify, assess, and mitigate cybersecurity risks. The RMF Specialist will be responsible for coordinating RMF activities across multiple stakeholders and systems while ensuring cybersecurity requirements are effectively incorporated into acquisition, development, testing, and operational activities.

The successful candidate will also provide technical and functional mentorship to junior RMF personnel and contribute to the development and improvement of RMF processes, procedures, and cybersecurity practices across the organization.

Duties:

  • Lead the development, maintenance, review, and delivery of comprehensive RMF documentation, including System Security Plans (SSP), Security Assessment Reports (SAR), Risk Assessment Reports (RAR), Plans of Action and Milestones (POA&M), Policies and Procedures, and associated authorization artifacts.
  • Lead systems through all phases of the RMF lifecycle, from system categorization and control selection through assessment, authorization, continuous monitoring, and reauthorization.
  • Advise system owners, program managers, engineers, cybersecurity personnel, and other stakeholders on the implementation of DoD cybersecurity requirements and RMF best practices.
  • Develop and execute strategies to address security control deficiencies, vulnerabilities, POA&M items, and other cybersecurity risks.
  • Review and analyze vulnerability scan results, STIG assessments, security control assessments, and other cybersecurity assessment data to identify systemic risks and develop appropriate mitigation strategies.
  • Provide oversight of vulnerability management activities, including ACAS/Nessus scanning, STIG compliance, remediation tracking, and security assessment activities.
  • Ensure compliance with applicable DoD cybersecurity policies, including DoDI 8510.01, NIST SP 800-37, NIST SP 800-53, CNSSI guidance, applicable STIGs, and other cybersecurity requirements.
  • Assess cybersecurity risks associated with digital engineering systems, cloud environments, distributed architectures, and developmental and testing environments.
  • Provide cybersecurity guidance during system design, development, integration, acquisition, testing, deployment, and operational activities.
  • Lead the development and validation of risk mitigation strategies and provide recommendations to program leadership regarding residual cybersecurity risk.
  • Identify opportunities to improve RMF processes, standardize documentation, and increase the efficiency and effectiveness of cybersecurity activities across programs.
  • Mentor and provide technical guidance to junior RMF personnel.
  • Represent the cybersecurity/RMF team in technical interchange meetings, program reviews, security assessments, and other stakeholder engagements.
  • Communicate cybersecurity risks, requirements, findings, and recommendations effectively to both technical and non-technical stakeholders.
  • Support cybersecurity continuous monitoring activities and ensure ongoing compliance with authorization requirements.
  • Perform other cybersecurity and RMF-related duties as required.
  • Travel as required (estimated 10%).
Qualifications

Required Skills/Experience:

  • 8-10 years of experience
  • Significant experience developing, implementing, assessing, and maintaining RMF packages within the DoD or federal government environment.
  • Demonstrated experience leading systems through the DoD RMF lifecycle and supporting successful ATO or authorization activities.
  • In-depth knowledge of DoD cybersecurity policies, RMF processes, NIST SP 800-37, NIST SP 800-53, FIPS, CNSSI guidance, and applicable DoD STIG requirements.
  • Proficiency with vulnerability assessment and compliance tools, including ACAS/Nessus, EvaluateSTIG, eMASSter, and eMASS.
  • Demonstrated ability to analyze vulnerability, STIG, and security assessment results and develop effective remediation and risk mitigation strategies.
  • Experience developing and reviewing SSPs, SARs, RARs, POA&Ms, security control implementation statements, and other RMF documentation.
  • Demonstrated ability to independently manage multiple RMF activities, systems, and competing priorities.
  • Strong understanding of cybersecurity principles, risk management, vulnerability management, security controls, and continuous monitoring.
  • Excellent verbal, written, analytical, and interpersonal communication skills.
  • Demonstrated ability to lead and collaborate effectively across multidisciplinary technical and program teams.
  • Must be a U.S. Citizen.
  • An active DoD Secret clearance is required to perform this work. Candidates must hold or be able to obtain and maintain a DoD Secret Security Clearance during their employment.

Education/Certification Requirements:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field.
  • CISSP, CAP, CISM, or equivalent DoD-approved cybersecurity certification.
  • DoD 8570/8140 baseline certification appropriate to the position and assigned duties.

Desired Skills:

  • Demonstrated expertise securing digital engineering systems, distributed architectures, and cloud-based infrastructures.
  • Experience supporting RMF activities for cloud environments, including AWS, Azure, GCP, or DoD-specific cloud platforms.
  • Experience with cloud security architecture, authorization, and implementation.
  • Experience supporting developmental and operational testing environments.
  • Experience with DevSecOps, secure software development, or cybersecurity integration into acquisition and development lifecycles.
  • Experience supporting complex or distributed systems with multiple interconnected components and external dependencies.
  • Active TS/SCI clearance is a plus.

About PeopleTec

PeopleTec, Inc. is a defense contractor that provides engineering and technical services to the United States Department of Defense and other government agencies. The company was founded in 2005 and is headquartered in Huntsville, Alabama. PeopleTec specializes in systems engineering, cybersecurity, and software development. The company has received numerous awards for its work, including the 2019 North Alabama Better Business Bureau Torch Award for Ethics and the 2018 Huntsville/Madison County Chamber of Commerce Small Business of the Year Award. PeopleTec has a strong commitment to giving back to the community and supports a variety of charitable organizations.
Learn more about PeopleTec
Size
500 employees
Industry
Net Income
$10 million
Founded
2005
5 Year Trend
+20%
Revenue
$100 million

Similar Jobs

More Jobs at PeopleTec

More Aerospace & Defense Jobs

Find similar Risk Management Framework (RMF) Specialist jobs: