RMF Information System Security Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

Deloitte · 1 week ago

RMF Information System Security Engineer

Deloitte is a leading consulting firm that focuses on transforming technology platforms and driving innovation. They are seeking a Project Delivery Senior Analyst to prepare and maintain Security Assessment Plans, conduct vulnerability assessments, and integrate security controls to meet Risk Management Framework requirements.

AccountingConsultingFinancial ServicesLegalProfessional ServicesRisk Management
check
Growth Opportunities
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Prepare and maintain Security Assessment Plans (SAPs) and execute technical assessments during RMF Step 2 and RMF Step 4
Identify, evaluate, and analyze vulnerability findings using Assured Compliance Assessment Solution (ACAS)
Conduct Security Content Automation Protocol (SCAP) and/or EvaluateSTIG scans to assess system vulnerabilities and compliance
Validate implementation of secure system configurations and hardening according to DoD and Navy standards
Develop and enforce security controls and configurations to meet Risk Management Framework (RMF) requirements
Integrate Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) throughout the system lifecycle, particularly for Facility Related Control Systems (FRCS) hardware/software
Review and validate control implementation statements (aligned with NIST 800-53) for accuracy and completeness
Develop and support mitigation actions, including documentation and remediation of vulnerabilities via Plan of Actions & Milestones (POA&Ms)
Collaborate with cross-functional teams to implement security controls and respond to emerging cyber threats
Provide technical RMF consultative expertise at every stage of the RMF process, including ongoing support for IT and OT systems

Qualification

RMF experienceCybersecurity engineeringVulnerability scanningSystem hardeningIAT/IAM Level II/III CertificationSTIGs/SRGs applicationActive Secret security clearanceBachelor's degree

Required

Bachelor's degree
Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
Active Secret security clearance required
2+ years of experience with RMF and Cybersecurity engineering or Operational Technology Systems
Experience in vulnerability scanning, system hardening and applying STIGs/SRGs
Ability to be on-site in Norfolk, VA 3-4 days/week

Preferred

IAT/IAM Level II/III Certification

Company

Deloitte

company-logo
Deloitte is a business consulting company that offers audit, consulting, financial advisory, and tax services.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Anne Muraya
Chief Executive Officer - East Africa
linkedin
leader-logo
Joe Ucuzoglu
Global Chief Executive Officer
linkedin
Company data provided by crunchbase