RMF Specialist jobs in United States
cer-icon
Apply on Employer Site
company-logo

Data Intelligence, LLC · 22 hours ago

RMF Specialist

Data Intelligence, LLC is searching for a full time RMF Specialist to support a DoD Navy effort. The role involves cybersecurity engineering and Assessment & Authorization activities to ensure compliance and security posture for mission-critical systems.

Cyber SecurityInformation TechnologyProject Management
check
Comp. & Benefits
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote
Hiring Manager
Lindsey McManus
linkedin

Responsibilities

Perform technical planning and systems engineering to ensure information assurance (IA) compliance and strong cyber posture across confidentiality, integrity, availability, authentication, and non-repudiation
Conduct ACAS vulnerability scans and STIG compliance assessments on standalone and networked systems
Execute SCAP scans to support automated STIG validation and compliance reporting
Apply operating system and application patches, perform software upgrades, and conduct regression testing to ensure system integrity
Provide day-to-day cybersecurity operations and maintenance support, including server, network, and policy enforcement activities
Deliver technical and analytical cybersecurity recommendations to engineering and program teams
Identify and report cybersecurity policy violations to the ISSM and program leadership
Track security baselines and participate in Configuration Control Board (CCB) meetings related to infrastructure and network changes
Develop and maintain cybersecurity documentation supporting system operations, maintenance, and issue resolution
Create, update, and manage POA&M entries based on ACAS, SCAP, and STIG artifacts to support continuous monitoring
Support RMF Assessment & Authorization activities in an ISSO/ISSE capacity in accordance with Department of the Navy policies and instructions
Perform RMF Step 5 authorization support and RMF Step 6 continuous monitoring activities
Support efforts for ATO package development and validation as applicable
Conduct annual security reviews and annual security control testing
Manage POA&M tracking, vulnerability remediation, and risk mitigation activities
Plan and execute cybersecurity testing to assess and document security control effectiveness
Evaluate the quality and completeness of security control implementations against RMF requirements
Perform ongoing vulnerability and compliance scanning in support of continuous monitoring
Support Developmental Test & Evaluation (DT&E), Operational Test & Evaluation (OT&E), penetration testing, and tabletop exercises
Assist with technical and management processes supporting operational verification, installation testing, and system readiness
Provide cybersecurity support to test events and evaluation activities across the system lifecycle

Qualification

Risk Management Framework (RMF)ACAS vulnerability scanningSTIG assessmentsIAM Level II certificationEMASS utilizationPOA&M managementCybersecurity engineeringContinuous monitoringCybersecurity documentationTechnical planning

Required

Minimum of five (5) years of full-time professional experience performing Risk Management Framework (RMF) activities
Active, current security clearance that is at least secret level
Demonstrated experience with STIG assessments (manual and automated, including SCAP benchmarks)
Demonstrated experience with ACAS vulnerability scanning
Demonstrated experience with eMASS utilization and workflow execution
Demonstrated experience with POA&M development and management
Demonstrated experience with RMF Step 5 authorization activities in an ISSE capacity
Education, Certification Requirements: Bachelor's Degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information Systems, Information Technology, Computer Engineering, Electrical or Electronics Engineering, Software Engineering, Computer Science, Mathematics with a concentration in Computer Science, or a closely related discipline
Active IAM Level II (or higher) certification (CAP, SecurityX [formerly CASP], CISM, CISSP, GSLC, CCISO, or HCISPP)

Benefits

Medical, dental and vision insurance
401k
PTO
11 paid holidays

Company

Data Intelligence, LLC

twittertwitter
company-logo
Data Intelligence, LLC (DI) provides mission focused systems engineering, full lifecycle software development and cybersecurity solutions for complex IT and C5ISR system.

Funding

Current Stage
Growth Stage

Leadership Team

J
Jim Scarpello
Managing Director
linkedin
M
Marty Dunleavy
Owner
linkedin
Company data provided by crunchbase