Deloitte · 1 week ago
RMF Information System Security Engineer
Deloitte is a leading consulting firm that focuses on transforming technology platforms and driving innovation. They are seeking a Project Delivery Senior Analyst to prepare and maintain Security Assessment Plans, conduct vulnerability assessments, and integrate security controls to meet Risk Management Framework requirements.
AccountingConsultingFinancial ServicesLegalProfessional ServicesRisk Management
Responsibilities
Prepare and maintain Security Assessment Plans (SAPs) and execute technical assessments during RMF Step 2 and RMF Step 4
Identify, evaluate, and analyze vulnerability findings using Assured Compliance Assessment Solution (ACAS)
Conduct Security Content Automation Protocol (SCAP) and/or EvaluateSTIG scans to assess system vulnerabilities and compliance
Validate implementation of secure system configurations and hardening according to DoD and Navy standards
Develop and enforce security controls and configurations to meet Risk Management Framework (RMF) requirements
Integrate Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) throughout the system lifecycle, particularly for Facility Related Control Systems (FRCS) hardware/software
Review and validate control implementation statements (aligned with NIST 800-53) for accuracy and completeness
Develop and support mitigation actions, including documentation and remediation of vulnerabilities via Plan of Actions & Milestones (POA&Ms)
Collaborate with cross-functional teams to implement security controls and respond to emerging cyber threats
Provide technical RMF consultative expertise at every stage of the RMF process, including ongoing support for IT and OT systems
Qualification
Required
Bachelor's degree
Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
Active Secret security clearance required
2+ years of experience with RMF and Cybersecurity engineering or Operational Technology Systems
Experience in vulnerability scanning, system hardening and applying STIGs/SRGs
Ability to be on-site in Norfolk, VA 3-4 days/week
Preferred
IAT/IAM Level II/III Certification
Company
Deloitte
Deloitte is a business consulting company that offers audit, consulting, financial advisory, and tax services.
Funding
Current Stage
Late StageLeadership Team
Recent News
2026-01-08
Company data provided by crunchbase