RMF EngineerInnovatus Technology ConsultingLocation: San Diego, CA or Norfolk/Suffolk, VA area (Hybrid - mostly remote)
Clearance: Active DoD Secret clearance (minimum) required
Position OverviewInnovatus is seeking an experienced Risk Management Framework (RMF) Engineer to support Assessment & Authorization (A&A) activities for DoD systems in accordance with NIST and DoD RMF requirements. The role focuses on developing, maintaining, and managing RMF documentation and artifacts throughout the system lifecycle. This is a hybrid position that is mostly remote, with candidates based in the San Diego, CA or Norfolk/Suffolk, VA areas preferred to support occasional on-site collaboration, meetings, or program needs.
Key Responsibilities- Support system categorization by identifying information types, system boundaries, and information flows.
- Develop, update, and maintain RMF artifacts, including System Security Plans (SSPs), Contingency Plans (CPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Continuous Monitoring Strategies, and supporting diagrams.
- Assess and evaluate implemented security controls; identify gaps and work with engineering and cybersecurity teams on remediation.
- Manage and validate RMF packages in eMASS (or equivalent DoD tools), including uploading artifacts and tracking authorization status.
- Support continuous monitoring, ATO package preparation, and authorization/renewal processes.
- Collaborate with system engineers, ISSOs/ISSMs, Security Control Assessors, Authorizing Officials, and government stakeholders.
- Provide guidance on NIST SP 800-53 controls, DoD cybersecurity policies, STIGs, and RMF best practices.
- Contribute to risk assessments, vulnerability management coordination, and compliance documentation as needed.
Required Qualifications- Active DoD Secret security clearance (minimum).
- U.S. citizenship.
- 3+ years of hands-on experience supporting DoD RMF processes and A&A activities.
- Proven experience developing RMF artifacts (SSPs, CPs, control evidence, test plans, POA&Ms, etc.).
- Strong familiarity with NIST SP 800-53, RMF steps (per NIST SP 800-37 / DoDI 8510.01), and authorization workflows.
- Experience with eMASS (or similar authorization management systems) for package management and artifact validation.
- Ability to work independently in a mostly remote environment while collaborating effectively with distributed teams.
- Strong written and verbal communication skills for technical documentation and stakeholder interaction.
Preferred Qualifications- Experience supporting Navy, NAVWAR, or other DoD component systems.
- Familiarity with additional tools such as ACAS, Nessus, or STIG Viewer.
- Relevant certifications (e.g., CAP, Security+, CISSP, CISM, or DoD 8570/8140 IAM Level I/II).
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
What We Offer- Competitive salary and benefits package.
- Mostly remote hybrid flexibility with work-life balance.
- Opportunity to support high-impact DoD missions.
- Professional growth in a mission-driven, veteran-friendly SDVOSB environment.
- Collaborative culture focused on ethics, expertise, and results.