OpportunityPeopleTec is currently seeking aRisk Management Framework (RMF) Specialist to support our Huntsville, AL location.
PeopleTec, Inc. is seeking a highly experienced and motivated RMF Specialist to assist with the development, implementation, assessment, and sustainment of RMF packages supporting digital engineering and digital ecosystem initiatives. A successful candidate will provide cybersecurity and RMF expertise, ensure compliance with Department of Defense (DoD) cybersecurity requirements, and lead efforts to achieve and maintain Authority to Operate (ATO) for complex, distributed digital engineering environments.
This position will serve as a cybersecurity advisor to program leadership, engineering teams, system owners, and other stakeholders, providing guidance throughout the RMF lifecycle and helping organizations identify, assess, and mitigate cybersecurity risks. The RMF Specialist will be responsible for coordinating RMF activities across multiple stakeholders and systems while ensuring cybersecurity requirements are effectively incorporated into acquisition, development, testing, and operational activities.
The successful candidate will also provide technical and functional mentorship to junior RMF personnel and contribute to the development and improvement of RMF processes, procedures, and cybersecurity practices across the organization.
Duties:
- Lead the development, maintenance, review, and delivery of comprehensive RMF documentation, including System Security Plans (SSP), Security Assessment Reports (SAR), Risk Assessment Reports (RAR), Plans of Action and Milestones (POA&M), Policies and Procedures, and associated authorization artifacts.
- Lead systems through all phases of the RMF lifecycle, from system categorization and control selection through assessment, authorization, continuous monitoring, and reauthorization.
- Advise system owners, program managers, engineers, cybersecurity personnel, and other stakeholders on the implementation of DoD cybersecurity requirements and RMF best practices.
- Develop and execute strategies to address security control deficiencies, vulnerabilities, POA&M items, and other cybersecurity risks.
- Review and analyze vulnerability scan results, STIG assessments, security control assessments, and other cybersecurity assessment data to identify systemic risks and develop appropriate mitigation strategies.
- Provide oversight of vulnerability management activities, including ACAS/Nessus scanning, STIG compliance, remediation tracking, and security assessment activities.
- Ensure compliance with applicable DoD cybersecurity policies, including DoDI 8510.01, NIST SP 800-37, NIST SP 800-53, CNSSI guidance, applicable STIGs, and other cybersecurity requirements.
- Assess cybersecurity risks associated with digital engineering systems, cloud environments, distributed architectures, and developmental and testing environments.
- Provide cybersecurity guidance during system design, development, integration, acquisition, testing, deployment, and operational activities.
- Lead the development and validation of risk mitigation strategies and provide recommendations to program leadership regarding residual cybersecurity risk.
- Identify opportunities to improve RMF processes, standardize documentation, and increase the efficiency and effectiveness of cybersecurity activities across programs.
- Mentor and provide technical guidance to junior RMF personnel.
- Represent the cybersecurity/RMF team in technical interchange meetings, program reviews, security assessments, and other stakeholder engagements.
- Communicate cybersecurity risks, requirements, findings, and recommendations effectively to both technical and non-technical stakeholders.
- Support cybersecurity continuous monitoring activities and ensure ongoing compliance with authorization requirements.
- Perform other cybersecurity and RMF-related duties as required.
- Travel as required (estimated 10%).
Qualifications
Required Skills/Experience:
- 8-10 years of experience
- Significant experience developing, implementing, assessing, and maintaining RMF packages within the DoD or federal government environment.
- Demonstrated experience leading systems through the DoD RMF lifecycle and supporting successful ATO or authorization activities.
- In-depth knowledge of DoD cybersecurity policies, RMF processes, NIST SP 800-37, NIST SP 800-53, FIPS, CNSSI guidance, and applicable DoD STIG requirements.
- Proficiency with vulnerability assessment and compliance tools, including ACAS/Nessus, EvaluateSTIG, eMASSter, and eMASS.
- Demonstrated ability to analyze vulnerability, STIG, and security assessment results and develop effective remediation and risk mitigation strategies.
- Experience developing and reviewing SSPs, SARs, RARs, POA&Ms, security control implementation statements, and other RMF documentation.
- Demonstrated ability to independently manage multiple RMF activities, systems, and competing priorities.
- Strong understanding of cybersecurity principles, risk management, vulnerability management, security controls, and continuous monitoring.
- Excellent verbal, written, analytical, and interpersonal communication skills.
- Demonstrated ability to lead and collaborate effectively across multidisciplinary technical and program teams.
- Must be a U.S. Citizen.
- An active DoD Secret clearance is required to perform this work. Candidates must hold or be able to obtain and maintain a DoD Secret Security Clearance during their employment.
Education/Certification Requirements:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field.
- CISSP, CAP, CISM, or equivalent DoD-approved cybersecurity certification.
- DoD 8570/8140 baseline certification appropriate to the position and assigned duties.
Desired Skills:
- Demonstrated expertise securing digital engineering systems, distributed architectures, and cloud-based infrastructures.
- Experience supporting RMF activities for cloud environments, including AWS, Azure, GCP, or DoD-specific cloud platforms.
- Experience with cloud security architecture, authorization, and implementation.
- Experience supporting developmental and operational testing environments.
- Experience with DevSecOps, secure software development, or cybersecurity integration into acquisition and development lifecycles.
- Experience supporting complex or distributed systems with multiple interconnected components and external dependencies.
- Active TS/SCI clearance is a plus.