Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

RMF & ISSM Support Specialist

Sentar

RMF & ISSM Support Specialist

Sentar is proud to be an employee-owned company, fostering a culture of empowerment, collaboration, and innovation. Sentar is dedicated to developing the critical talent that the connected world demands to create solutions to address the convergence of cybersecurity, intelligence, analytics, and systems engineering. We invite you to join the team where you can build, innovate, and secure your career.

Sentar is seeking a RMF & ISSM Support Specialist that sits remotely!

The Defense Health Agency (DHA) supports the delivery of integrated, affordable, and high-quality health services to Military Health System (MHS) beneficiaries and is responsible for driving greater integration of clinical and business processes across the MHS. Our DHA teams make a difference daily by ensuring the security of the health records of active duty and retired military and their families!

The Defense Health Cyber Risk Management Team requires a RMF & ISSM Support Specialist to provide key services to a government client. This individual will be responsible for assigned Information Systems Security Manager (ISSM) efforts to complete RMF packages (Security Plans, Annual Security Reviews, Authorizations, POA&Ms, etc.), conduct continuous monitoring of assigned systems, and provide relevant cyber security expertise to ongoing programmatic lines of effort.

This position for JOMIS Cyber Support, Risk Management Executive Division (RMED) supported by the Defense Health Agency (DHA). The RMF & ISSM Support SME navigates and coordinates workflow, activity, and documentation necessary to achieve successful RMF objectives for DHA medical devices and systems.

Duties: Cloud & Application Security Engineering

  • Architect and implement secure, zero trust, defense-in-depth solutions across infrastructure, platform, and application layers for cloud-hosted and DDIL environments;
  • Develop and enforce cloud security baselines and automated policy guardrails using IaC tools (Terraform, Ansible, AWS Config Rules, Azure Policy);
  • Engineer IAM solutions including RBAC, ABAC, MFA, least-privilege, and PAM across cloud and application environments;
  • Secure containerized workloads (Kubernetes/OpenShift) including pod security policies, network policies, secrets management, and runtime threat detection (Falco, Prisma Cloud/Twistlock);
  • Embed security into CI/CD pipelines per the DoD DevSecOps Reference Design, automating SAST, DAST, SCA, container image scanning, and STIG compliance validation;
  • Integrate application security across the SDLC including secure code review, SAST, DAST, SCA, and API security testing;
  • Design and implement cloud-native SIEM/monitoring capabilities (AWS Security Hub, CloudTrail, Azure Sentinel) supporting continuous monitoring and RMF compliance;
  • Implement data protection strategies including encryption at rest/in transit and cryptographic key management (AWS KMS, Azure Key Vault);
  • Lead threat modeling and security architecture reviews for new and evolving JOMIS capabilities;
  • Evaluate and harden DDIL/edge security configurations for disconnected and bandwidth-constrained operational environments;

RMF & Compliance

  • Execute end-to-end RMF authorization activities including SSP development, SCAs, POA&M management, and ATO package maintenance in eMASS, CMRS, COAMS, and Phoenix;
  • Apply NIST SP 800-53 controls, DISA STIGs/SRGs, and DoD/DHA IA requirements to assess, document, and remediate system security posture;
  • Conduct vulnerability analysis using ACAS/Nessus, STIG Viewer, and SCAP; analyze HBSS/ESS output and configurations; perform root cause analysis on cybersecurity shortfalls;
  • Review and validate authorization boundary diagrams, architecture/data flow diagrams, hardware/software inventories, IP/subnet assignments, and Med-COI Zone taxonomy artifacts;

Stakeholder Engagement & Reporting

  • Serve as senior technical security advisor to program leadership, IPTs, and government stakeholders through engineering review boards and architecture working groups;
  • Coordinate with ISSMs, system/network administrators, software engineers, and CIOs to validate and document control implementation;
  • Submit Weekly Status Reports (WSRs) and lead/attend stakeholder meetings on RMF and security engineering status.

Qualifications:

  • 6–8+ years of hands-on cybersecurity engineering experience in DoD or Federal environments, with demonstrated depth across RMF, cloud security, and application security domains;
  • RMF/Compliance: Hands-on eMASS experience; proven ability to develop and manage ATO packages, SSPs, SCAs, and POA&Ms proficiency with ACAS/Nessus, SCAP, STIG Viewer, HBSS/ESS analysis;
  • Cloud Security: 3+ years securing AWS GovCloud and/or Azure Government environments; experience with cloud-native security tooling (Security Hub, CloudTrail, Azure Sentinel, Defender), secure landing zone design, and network micro-segmentation;
  • IaC & Automation: Proficiency with Terraform, Ansible, CloudFormation, or Helm for automated, policy-compliant infrastructure deployment and security hardening;
  • Application Security: Experience with SAST, DAST, SCA, and API security testing integrated into CI/CD pipelines (GitLab, Jenkins, or equivalent); familiarity with secure SDLC practices per DoD DevSecOps Reference Design;
  • Containers & Microservices: Hands-on Kubernetes/OpenShift security including pod security standards, image scanning, secrets management, and runtime detection tooling;
  • IAM/Zero Trust: Demonstrated implementation of RBAC, ABAC, MFA, PAM, and zero trust access models in cloud and application environments;
  • DDIL/Edge: Familiarity with DDIL architecture security challenges including offline operations, data synchronization, and edge hardening;
  • Frameworks: Strong working knowledge of NIST SP 800-53, NIST SP 800-144, NIST SP 800-115, DISA STIGs/SRGs, DoD DevSecOps Reference Design, and DoD 8570/8140;
  • Strong written and verbal communication skills; ability to translate complex technical findings for both technical and executive audiences.

Clearance Level: Active Secret Clearance

Education: Bachelor's Degree in Cybersecurity, Computer Science, Systems Engineering, or related STEM field; or equivalent demonstrable experience

Certifications:

IAT Level II required (e.g., CompTIA Security+ CE); One or more of the following strongly desired: CISSP, CASP+, CCSP, AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate; Additional certifications such as CSSLP, GWEB, GPEN, or CEH are a plus

Benefits at Sentar: Our unique ownership model attracts top talent, giving employees the freedom to take initiative and drive meaningful improvements. In addition to cultivating a thriving and inclusive work environment, Sentar offers an extensive benefits package designed to support the well-being of employees and their families. Employee ownership is the foundation of our culture, promoting participation, teamwork, and accountability while ensuring long-term financial security and a commitment to excellence.

  • Voluntary Medical, Dental, Vision, with Health Savings or Flexible Spending Plan options
  • Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options
  • Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees
  • Generous 401(k) match
  • Competitive PTO plan that graduates quickly with years of service
  • Other leave programs; holiday schedule along with bereavement, maternity, jury and military duty
  • Mental health awareness programs
  • Tuition reimbursement
  • Professional development reimbursement
  • Recognition and Awards programs

If you are not ready to apply for this position, submit your resume here to join our talent community. We'll keep you updated occasionally on new job opportunities.

Sentar is an Affirmative Action and Equal Opportunity Employer M/F/Vets/Persons with Disabilities. Our culture is one of inclusivity and support. Sentar is proudly an Equal Opportunity and VEVRAA Federal Contractor Employer M/F/Vets/Persons with Disabilities. Follow these links to learn more about your

Vacancy posted 1 hour ago
Similar jobs that could be interesting for youBased on the RMF & ISSM Support Specialist in United States vacancy
  • $135k - $145k

     ...SME) to oversee compliance and manage security documentation at Langley Air Force Base in Hampton, VA. The ideal candidate has strong ISSM experience and must be TS/SCI cleared, with hands-on skills in XACTA and DOD security policies. This fully onsite position offers a... 
    Suggested

    GovCIO

    Hampton, VA
    4 days ago
  • $66.9k - $115k

     ...Research, An Accenture Federal Services Company, is seeking a Cyber Support Specialist in Columbus, Ohio. This role focuses on supporting cybersecurity activities related to the Risk Management Framework (RMF). Responsibilities include assisting with assessments, defining... 
    Suggested

    ASM Research, An Accenture Federal Services Company

    Columbus, OH
    4 days ago
  • Position Overview Cyber Support Specialist a key role in supporting cybersecurity activities required to validate and sustain compliance with the Risk Management Framework (RMF) for project infrastructure and services. This position assists with Assessment and Authorization... 
    Suggested
    Contract work
    Work at office
    Rotating shift

    ASM Research, An Accenture Federal Services Company

    Hartford, CT
    1 day ago
  •  ...solutions provider in Alexandria, Virginia is seeking an IT Support Specialist to provide cybersecurity and Risk Management Framework support...  ...an active DoD Secret clearance. The role involves developing RMF documentation, managing eMASS entries, and conducting security... 
    Suggested
    Work at office

    Systems Planning & Analysis

    Alexandria, VA
    4 days ago
  • $66.9k - $115k

     ...Research, An Accenture Federal Services Company, is seeking a Cyber Support Specialist in Atlanta, Georgia. This role involves supporting...  ...activities for compliance with the Risk Management Framework (RMF). Key responsibilities include assisting with assessments, implementing... 
    Suggested

    ASM Research, An Accenture Federal Services Company

    Atlanta, GA
    4 days ago
  •  ...security standards and policies. Responsibilities include reviewing RMF packages, validating security controls, and preparing for...  ...Cyber Security or a related field. The role requires direct on-site support. This is a full-time position offering a competitive salary... 
    Full time

    Ignite Now

    Huntsville, AL
    2 days ago
  •  ...Research, An Accenture Federal Services Company is seeking a Cyber Support Specialist in Richmond, Virginia. This role is critical in supporting...  ...maintaining compliance with the Risk Management Framework (RMF). Responsibilities include assisting with Assessment and... 

    ASM Research, An Accenture Federal Services Company

    Richmond, VA
    1 day ago
  • Booz Allen Hamilton is seeking a Cybersecurity Mission Specialist and Information System Security Manager in New York. You will enhance the...  ...compliance with Department of War standards and executing RMF processes. The ideal candidate has over 3 years of experience in... 

    Booz Allen Hamilton

    Florida, NY
    5 days ago
  • $50 - $68 per hour

     ...Insight Global is looking for a Secret ISSO Support Specialist supporting a large government client, working hybrid in NW Washington, DC. This...  ...• 5-7 years supporting federal IT security compliance or RMF environments • Experience supporting at least one ATO lifecycle... 
    Contract work
    For contractors

    Insight Global

    Washington DC
    1 day ago
  • $15.91 - $25.77 per hour

    Overview The Certified Recovery Support Specialist (CRSS) provides experience, education and professional services to assist and support individuals in developing and/or maintaining recovery-oriented, wellness-focused lifestyles. Qualifications Certification &... 
    Local area
    Shift work

    Carle Health

    Peoria, IL
    1 hour ago
  •  ...Cybersecurity RMF Specialist, responsible for developing cybersecurity policy and providing RMF support for cloud environments in a full-time remote position, requiring an active TS/SCI clearance. Key Responsibilities Develop and oversee cybersecurity policies and RMF... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    3 days ago
  •  ...Overview The Senior RMF Specialist/ISSO is responsible for guiding IT systems through the entire Risk Management Framework (RMF) lifecycle...  ...'s security posture within the Enterprise Mission Assurance Support System (eMASS), ensuring all data is accurate and up to date.... 
    Temporary work
    Work at office
    Immediate start
    Flexible hours

    Integral Services Company

    Rock Island, IL
    3 days ago
  •  ...Apogee Global RMS is seeking a GRC / NIST RMF Specialist to support federal programs requiring disciplined governance, risk, and compliance execution. This role is built for practitioners who understand the full lifecycle of NIST RMF, can translate controls into actionable... 

    Apogee Global RMS

    Waldorf, MD
    5 days ago
  • $104k - $166k

     ...RMF/eMASS Specialist, Senior Job Locations US-VA-Herndon Requisition ID 2026-165280 Position Category...  ...Specialist, Senior to join our team in the greater DMV area, supporting the Army National Guard. Responsibilities Lead RMF... 
    Contract work
    Shift work

    Peraton

    Herndon, VA
    5 days ago
  • $88.6k - $139.37k

     ...Cybersecurity/RMF Specialist – Secret Clearance | Rockledge, FL  Cambridge International Systems, Inc.  Join a dynamic global team united...  ...We are currently seeking a Cybersecurity/RMF Specialist to support operations in Rockledge, FL. This is a full-time, CONUS... 
    Full time
    Contract work
    Temporary work
    Part time
    Casual work
    Local area
    Immediate start
    Worldwide
    Relocation package
    Night shift
    Afternoon shift

    Cambridge International Systems

    Rockledge, FL
    1 day ago
  • $25 per hour

    (In-Home Support - Mental Health & Addiction Recovery) Recovery Consultants | Flexible Schedule | W2 Employment Recovery Consultants is hiring compassionate, reliable individuals to provide in-home recovery and mental health support as a Recovery Companion. This is a non... 
    Hourly pay
    Part time
    Flexible hours

    Recovery Consultants

    San Francisco, CA
    5 days ago
  •  ...TimeEducation Level: High SchoolTravel Percentage: Up to 25%Job Shift: AnyJob Category: Health CarePosition Summary The Certified Peer Support Specialist assigned to the Crisis Stabilization Center Services work daily in partnership with the Mobile Crisis Response Team and our... 
    Full time
    Shift work
    Rotating shift

    Edgewater Health

    Gary, IN
    16 days ago
  • Apogee Global RMS in Washington seeks a GRC / NIST RMF Specialist to enhance governance, risk, and compliance processes for federal programs. The ideal candidate will lead NIST RMF execution and develop vital strategic documents. Strong knowledge of federal security baselines... 

    Apogee Global RMS

    Washington DC
    5 days ago
  • Job Description Job Description Turn Your Experience Into Impact. Peer Support Specialist opening at The Recovery Village!
    Full time
    Part time

    The Recovery Village

    Salem, OR
    6 days ago
  •  ...dental and ancillary care to a vulnerable population who deserve the best care. We are currently seeking to fill our Enrollment Support Specialist position to carry out this important mission. This position requires routine travel throughout the state to nursing homes... 
    Remote work
    Night shift

    ExcelHealth Group

    Murfreesboro, TN
    15 days ago
  •  ...The Information System Security Manager (ISSM) is the primary cybersecurity authority for...  ...ensuring 100% compliance with DoD 8510.01 (RMF) and 32 CFR Part 117 (NISPOM). You will...  ...proficiency with the Enterprise Mission Assurance Support Service (eMASS) or Xacta for system... 
    Interim role

    General Dynamics Corporation

    Bath, ME
    2 days ago
  •  ...Logistics Administrative Support Specialist Medical Device Deployment in the Capital Region The Defense Health Agency's (DHA) National...  ...prescribes MHS GENESIS readiness, Risk Management Framework (RMF)/cyber security compliance, and medical device standardization... 
    Work at office

    KurzSolutions

    Falls Church, VA
    5 days ago
  • Integral Consulting Services is seeking a Senior RMF Specialist/ISSO to manage the Risk Management Framework lifecycle for US Army projects...  ..., and professional training reimbursement. Join us in supporting national security initiatives with the necessary top-secret clearance... 

    Integral Consulting Services

    Huntsville, AL
    3 days ago
  • $88.6k - $139.37k

     ...and security challenges worldwide. Job Title: Cybersecurity/RMF Specialist Location: Rockledge, FL (full-time, CONUS) Clearance: Current...  ..., disaster recovery, and continuous monitoring plans to support system resilience and ATO requirements. Oversee implementation... 
    Full time
    Contract work
    Casual work
    Local area
    Immediate start
    Worldwide
    Relocation package
    Night shift
    Afternoon shift

    Cambridge International Systems, Inc.

    Florida, NY
    1 day ago
  •  ...Solutions, LLC is seeking an Information System Security Specialist II in Virginia Beach, VA, to support cybersecurity authorization activities and ensure...  ...The ideal candidate will have hands-on experience with RMF processes, vulnerability management, and security compliance... 

    DirectViz Solutions, LLC

    Virginia Beach, VA
    4 days ago
  • $88.6k - $139.37k

    Cambridge International Systems Inc is looking for a Cybersecurity/RMF Specialist to join our team in Rockledge, FL. This full-time position requires an active DoD Secret clearance and involves managing compliance activities aligned with the Risk Management Framework (... 
    Full time

    Cambridge International Systems Inc

    Florida, NY
    4 days ago
  • NV5 is seeking a Risk Management Framework Specialist in St. Louis, MO, to manage cybersecurity processes for Air Force systems. The role involves leading RMF implementation, conducting risk assessments, and ensuring compliance with DoD policies. Candidates must have at... 

    NV5

    Saint Louis, MO
    3 days ago
  • Responsibilities Lead all aspects of the RMF process, from system categorization and security control selection to implementation and...  ...'s security posture within the Enterprise Mission Assurance Support System (eMASS), ensuring all data is accurate and up to date. Implement... 
    Temporary work
    Flexible hours

    Integral Federal, Inc.

    Huntsville, AL
    1 day ago
  • $100k - $115k

     ...Security in Virginia Beach is seeking an experienced Intel Security Specialist to support the Naval Surface Warfare Center. The ideal candidate must...  ...Validator certification, possess ten years of experience in RMF validation, and be proficient in vulnerability assessments... 

    Watershed Security

    Virginia Beach, VA
    1 day ago
  • $27.5 per hour

     ...Job Description Job Description This is a remote position. Posting Title: Administrative Support Specialist Industry: Corporate & Business Services Salary: $27.50 Work Experience: Less than 3 years Summary The Administrative Support... 
    Work experience placement
    Work at office
    Remote work

    Gotham Biotech

    Portland, ME
    8 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to RMF & ISSM Support Specialist. Be the first to apply!