Job DescriptionCOLSA is seeking a Cyber Engineer with prior U.S. Navy experience and a strong understanding of Risk Management Framework (RMF) processes, procedures, and tools. The ideal candidate will have hands-on experience supporting cybersecurity compliance activities within Navy environments.
Principal Duties and Responsibilities (*Essential functions) - Design, develop, and integrate AI models, intelligent agents, and software tools to automate cybersecurity processes
- Oversee compliance with RMF control requirements and ensure all control evidence is accurate, complete, and up to date.
- Coordinate with cybersecurity teams, system administrators, engineering staff, and external assessors during audits, assessments, and inspections.
- Ensure proper implementation of security controls throughout the system lifecycle and validate compliance with DoW cybersecurity policies.
- Provide guidance to technical teams on RMF expectations, cybersecurity requirements, and proper documentation practices.
- Track vulnerabilities, assessment results, and remediation efforts, ensuring timely closure and accurate documentation.
- Communicate system security status, risks, and notable issues to leadership and stakeholders.
Required ExperienceRequired Qualifications- Bachelor's degree in computer science, information technology, cyber security, engineering, or related field or equivalent work experience. Advanced degree preferred.
- Minimum of 10 or more years of experience in information security, cyber security, or a related field.
- Previous Navy experience, preferably in cybersecurity, information assurance, or systems engineering roles.
- Demonstrated experience with the RMF lifecycle, including documentation, control implementation, security assessments, and continuous monitoring.
- Practical knowledge of RMF-related tools such as eMASS and other DoW compliance systems.
- Experience serving as an Information Systems Security Officer (ISSO) or Information Systems Security Manager (ISSM), with responsibilities that include maintaining system security documentation, managing POA&Ms, supporting audits, and ensuring compliance with DoW cybersecurity policies.
- Active Security+CE certification or equivalent.
- Active Secret security clearance
Preferred Qualifications- Experience with NIST SP 800-53 Rev 5 privacy controls.
- Relevant certifications such as CISSP, CISM, or other DoD 8570-compliant credentials.
Applicant selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information.