RMF / ISSO Lead

Development InfoStructure

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Systems, Cybersecurity, Computer Science, or related field (or equivalent experience)
  • Minimum 7 years in RMF / A&A / ISSO support for federal systems
  • Experience managing ATO lifecycle and POA&Ms under NIST 800-53
  • Certifications: CISSP, CAP, or CGRC (or comparable RMF/GRC certification)
  • Strong working knowledge of NIST RMF, NIST 800-53 Rev. 5, FIPS 199/200, and FISMA

Responsibilities

  • Manage RMF lifecycle for systems to ensure compliance with NIST 800-53 Rev. 5
  • Maintain Risk Management Strategy, RMF Program Plan, and tailored baselines
  • Provide RMF expertise and guidance to system owners and stakeholders
  • Develop and maintain RMF authorization artifacts and documentation
  • Communicate risk posture and compliance updates to senior leadership
  • Support audits and assessments, tracking corrective actions

Benefits

  • Opportunity for offsite work with necessary occasional travel to NIH facilities
  • Core hours Monday-Friday with a standard timeframe for work
  • Engagement in a critical role supporting national health initiatives through cybersecurity
  • Possibility to work on advanced AI/ML security frameworks
  • Participation in leading risk management programs for federal systems
Full Job Description
Job Overview
The RMF / ISSO Lead serves as the leader for the Risk Management Framework (RMF) program and Authority to Operate (ATO) lifecycle under the Information Security Program Support Services (ISPSS) effort supporting the NIH Office of the Director, Office of Information Technology (OD OIT), responsible for managing the RMF lifecycle under NIST 800-53 Rev. 5, leading Assessment and Authorization (A&A) package development, and maintaining the enterprise risk register and POA&Ms. This role drives execution across system categorization and authorization, continuous monitoring, audit and assessment support, and RMF guidance to system owners and ISSOs in close coordination with NIH/OD OIT leadership.

This is a full-time position with work performed primarily offsite, though travel to NIH/OD facilities in the Bethesda, MD area will be required on an as-needed basis. Core hours are Monday-Friday, 7:00 AM - 6:00 PM EST, and after-hours support for emergency incidents will be required as needed by NIH/OD. Position is contingent upon award and client approval.

Primary Duties
Lead RMF Program & Governance
  • Manage the RMF lifecycle for new and existing systems and maintain continuous compliance with the NIST 800-53 Rev. 5 baseline
  • Maintain the enterprise Risk Management Strategy, RMF Program Plan, common controls, and tailored baselines
  • Provide RMF subject matter expertise and guidance to system owners, ISSOs, and stakeholders
  • Support C-SCRM and EO 14028 requirements, including third-party/SBOM risk analysis
Develop A&A Packages & Documentation
  • Develop and maintain RMF authorization artifacts: SSP, BIA, FIPS 199 categorization, PTA/PIA, Configuration Management Plan, and e-Authentication documentation
  • Develop boundary/architecture documents (BSM, ABND) and support control scoping, tailoring, and overlays (e.g., OD AI Overlay; NIST AI RMF 1.0 for AI/ML systems)
  • Provide governance and final QA review of System Authorization Packages prior to submission to the Authorizing Official
  • Maintain independence: package developers shall not perform SCA/SAR validation for the same system
Drive Continuous Monitoring & Risk Reporting
  • Populate and maintain the enterprise Risk Management Register and manage POA&Ms to timely remediation
  • Identify, prioritize, and provide enhanced oversight for High Value Assets (HVAs)
  • Coordinate and execute annual Contingency Plan Tests and maintain ConMon plans
  • Communicate risk posture, compliance status, and authorization updates to senior leadership
Support Audits & System Owners
  • Support internal/external assessments and audits (OIG, GAO, HHS, independent assessors) and track corrective actions
  • Manage the Risk Mitigation Waiver Register and annual waiver reassessment
  • Facilitate RMF training, office hours, and how-to guides for system owners and technical staff


Required Qualifications

Education & Experience
  • Bachelor's degree in Information Systems, Cybersecurity, Computer Science, or a related field (or equivalent experience)
  • Minimum 7 years in RMF / A&A / ISSO support for federal systems
  • Demonstrated experience managing the ATO lifecycle and POA&Ms under NIST 800-53
Required Certifications
  • CISSP, CAP, or CGRC (or comparable RMF/GRC certification)
Technical Skills
  • Strong working knowledge of NIST RMF, NIST 800-53 Rev. 5, FIPS 199/200, and FISMA
  • Experience authoring SSPs and full A&A packages; familiarity with GRC/compliance tools (e.g., JCAM)
  • Familiarity with FedRAMP CSP package review and control inheritance
Leadership Capabilities
  • Clear written documentation and the ability to guide system owners through complex RMF processes
  • Strong organization and tracking discipline across many concurrent authorizations


Preferred Qualifications
  • Prior NIH/HHS RMF or ISSO support experience
  • Experience with AI/ML security overlays and NIST AI RMF 1.0
  • Cloud A&A experience (FedRAMP, NIH STRIDES)

Clearance
  • Must be able to obtain and maintain the NIH/OD/OIT required clearance level and complete all suitability/onboarding requirements

Salary Range
  • $110,000 - $130,000

}

Similar Jobs

More Jobs at Development InfoStructure

More Information Technology Jobs

Find similar RMF / ISSO Lead jobs: