CACI International

RMF Engineer, Journeyman

CACI International$63K — $129K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in information security and cybersecurity engineering.
  • Experience with DoD or related defense organizations.
  • Proficiency in RMF implementation and security assessment processes.
  • Background in vulnerability management and continuous compliance activities.
  • Ability to collaborate with diverse technical teams and government stakeholders.
  • Active Secret Clearance.

Responsibilities

  • Support the RMF lifecycle for information systems and mission applications.
  • Develop and maintain essential RMF documentation like SSPs and SAPs.
  • Implement and validate security controls per NIST SP 800-53 requirements.
  • Coordinate with various stakeholders throughout the RMF process.
  • Conduct security assessments and risk analyses.
  • Facilitate vulnerability remediation and corrective actions.
  • Track compliance metrics and conduct continuous monitoring activities.

Benefits

  • Comprehensive healthcare and wellness programs.
  • Financial planning and retirement support.
  • Family support and continuing education resources.
  • Generous time off policies and work-life balance initiatives.
Full Job Description
Job Title: RMF Engineer, Journeyman

Job Category: Security

Time Type: Full time

Minimum Clearance Required to Start: Secret

Employee Type: Regular-Long Term Assignment

Percentage of Travel Required: Up to 10%

Type of Travel: Continental US

* * *

The Opportunity:

CACI is seeking an experiencedRMF Engineer, Journeymanto support cybersecurity compliance and Risk Management Framework (RMF) implementation across the Indo-Pacific. The RMF Engineer, Journeyman serves as CACI's information security professional responsible for implementing, maintaining, and supporting the Department of Defense Risk Management Framework (RMF) for enterprise information systems,logisticsplatforms, operational technologies, and mission support applications. Reporting directly to the Cybersecurity Lead, this position ensures systems are designed, configured, and maintainedin accordance with DoD cybersecurity policies while supporting secure mission execution across distributed and expeditionary environments.

The RMF Engineer works closely with Government stakeholders, information system owners, cybersecurity personnel, systems engineers, network engineers, software developers,logisticsplanners, and mission partners to support system authorization activities, security control implementation, vulnerability remediation, and continuous monitoring. This position contributes to successful program execution by maintainingcybersecurity compliance, reducing operational risk, and enabling secure information sharing throughout the Indo-Pacific theater.

Responsibilities:

  • Support implementation of the DoD Risk Management Framework (RMF) lifecycle for information systems and mission applications.

  • Develop and maintain RMF documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and authorization packages.

  • Implement and validate NIST SP 800-53 security controls supporting system authorization and accreditation activities.

  • Coordinate with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), Authorizing Officials (AOs), and system owners throughout the RMF process.

  • Perform security control assessments, vulnerability reviews, configuration compliance checks, and cybersecurity risk analyses.

  • Support vulnerability remediation efforts using security scanning tools and coordinate corrective actions with engineering and operations teams.

  • Maintain continuous monitoring activities and track cybersecurity compliance metrics for Government leadership.

  • Support system testing, security assessments, audits, inspections, and cybersecurity readiness reviews.

  • Ensure compliance with DoD cybersecurity policies, RMF guidance, NIST standards, DISA Security Technical Implementation Guides (STIGs), and contractual requirements.

  • Prepare cybersecurity reports, executive-level briefings, risk assessments, and technical recommendations.

  • Support contingency operations, operational exercises, and technology deployments requiring secure system implementation.

  • Maintain cybersecurity documentation, configuration baselines, security artifacts, and knowledge management repositories.

  • Coordinate with network engineers, software developers, cloud administrators, andlogisticspersonnel to integrate cybersecurity into operational systems.

  • Promote continuous monitoring, cybersecurity awareness, and continuous process improvement across enterprise systems.

  • Support geographically dispersed operations requiring secure and resilient information systems.

Qualifications: 

Required:  

  • Minimum 5 years of experience supporting information security, cybersecurity engineering, RMF implementation, system security, or cybersecurity compliance for Government or Department of Defense programs. 

  • Experience supporting Department of Defense, Joint, Combatant Command, Service Component, Defense Information Systems Agency (DISA), or Special Operations organizations. 

  • Experience implementing RMF, preparing authorization packages, conducting security assessments, or supporting Authority to Operate (ATO) processes. 

  • Experience supporting vulnerability management, security compliance, and continuous monitoring activities. 

  • Demonstrated ability to coordinate cybersecurity efforts across engineering, operations, and Government stakeholders. 

  • Active Secret Clearance

Desired:

  • Bachelor's Degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, Systems Engineering, or a related technical field. 

  • Experience supporting USSOCOM, SOCPAC, Geographic Combatant Commands, Theater Special Operations Commands (TSOCs), DISA, or Joint Task Forces. 

  • Experience utilizing eMASS, ACAS, SCAP Compliance Checker (SCC), STIG Viewer, Tenable Nessus, Microsoft 365, Power BI, SharePoint, and enterprise cybersecurity management platforms. 

  • Knowledge of the DoD Risk Management Framework (RMF), NIST SP 800-53, NIST SP 800-37, DoDI 8510.01, DISA STIGs, CMMC, and cybersecurity best practices. 

  • Professional certifications such as CompTIA Security+ CE (DoD 8140/8570 compliant), ISC2 Certified Information Systems Security Professional (CISSP), Certified Authorization Professional (CAP), CompTIA CySA+, or equivalent cybersecurity certifications are preferred. 

This position is contingent on funding and may not be filled immediately. However, this position is representative of positions within CACI that are consistently available. Individuals who apply may also be considered for other positions at CACI.


Pay Range:

There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

Since this position can be worked in more than one location, the range shown is the national average for the position.

The proposed salary range for this position is:

$63,300-$129,700

About CACI International

CACI International Inc is a multinational professional services and information technology company. It provides services to many branches of the federal government including defense, homeland security, intelligence, and healthcare. CACI has approximately 23,000 employees worldwide. The company's mission is to provide enterprise and mission technology services and solutions that best fit the needs of its customers. CACI has been named a Fortune World's Most Admired Company, a Washington Post Top Workplace, and a Forbes Best Employer for Diversity.
Learn more about CACI International
Size
22,000 employees
Market Cap
$7.1 billion
Industry
Net Income
$374.4 million
Founded
1962
5 Year Trend
+7.3%
Revenue
$5.8 billion
NASDAQ

Similar Jobs

More Jobs at CACI International

More Information Technology Jobs

Find similar RMF Engineer, Journeyman jobs: