Risk Management Framework Subject Matter Expert
Apavo Corporation
Risk Management Framework (RMF) Subject Matter Expert
The RMF Subject Matter Expert (SME) supports cybersecurity and compliance efforts across multiple customer environments and system types within the Department of Defense and Intelligence Community. This role combines elements of ISSO, ISSM, and Security Control Assessor (SCA) responsibilities to support all phases of the Risk Management Framework (RMF) lifecycle in accordance with NIST SP 800-37 Rev. 2.
The RMF SME will provide technical guidance, assessment support, operational security oversight, and authorization package development while partnering with system owners, engineers, ISSOs, SCAs, and government stakeholders to maintain compliant and secure environments.
RMF SME responsibilities include, but are not limited to:
- Support RMF activities across all six RMF steps: Categorize, Select, Implement, Assess, Authorize, and Monitor.
- Develop, review, and maintain RMF documentation including SSPs, SARs, SAPs, RARs, POA&Ms, contingency plans, and authorization packages.
- Support security control selection, tailoring, implementation, and assessment activities aligned to NIST SP 800-53 Rev. 5.
- Conduct or support independent security control assessments and validation activities.
- Perform ISSO operational security responsibilities including account reviews, audit reviews, vulnerability tracking, configuration management coordination, and continuous monitoring activities.
- Utilize eMASS, Xacta, or equivalent GRC/A&A platforms to manage RMF activities and system artifacts.
- Interpret and analyze STIG findings, SCAP scans, ACAS results, and vulnerability assessment data to support remediation efforts.
- Develop and track POA&Ms and coordinate remediation activities with technical and program teams.
- Support ongoing continuous monitoring (ConMon) strategies, reporting, and compliance reviews.
- Provide cybersecurity guidance to system owners, engineers, and leadership regarding RMF compliance and risk posture.
- Ensure cybersecurity documentation and processes align with DoD RMF requirements, DoDI 8510.01, ICD 503, CNSSI 1253, and applicable customer guidance.
- Support cloud and hybrid environments as applicable, including AWS and Azure-based systems.
- Assist with executive-level briefings, risk discussions, and authorization recommendations.
The RMF SME is expected to perform additional duties as assigned in support of Apavo cybersecurity services and strategic growth initiatives.
Requirements
- Strong working knowledge of NIST SP 800-37 Rev. 2 and NIST SP 800-53 Rev. 5.
- Experience supporting DoD RMF and/or Intelligence Community RMF frameworks including ICD 503 and CNSSI 1253.
- Hands-on experience with eMASS, Xacta, or equivalent GRC/A&A platforms.
- Experience developing and reviewing RMF artifacts and ATO packages.
- Familiarity with STIGs, SCAP, ACAS, vulnerability management, and remediation processes.
- Understanding of continuous monitoring strategies and compliance reporting.
- Strong analytical, communication, and documentation skills.
- Ability to collaborate effectively with technical teams, security leadership, and government stakeholders.
- Experience supporting cloud-based environments and security authorizations is preferred.
- Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or related technical discipline preferred.
- Active TS/SCI clearance required. Candidates must be eligible for CI Polygraph processing or willing to obtain one if required.
- Must possess a DoD 8570/8140 IAM Level II or IAT Level III compliant certification such as CISSP, CISM, CASP+, or equivalent.
- Preferred certifications include CAP/CGRC, CCSP, or other RMF/GRC-focused certifications.
Apavo is considering candidates across multiple experience levels:
- Mid-Level: 5–8 years of RMF, ISSO, SCA, or cybersecurity compliance experience
- Senior-Level: 8–12 years of progressively responsible RMF and cybersecurity experience
- Principal-Level: 12+ years of experience, including prior leadership experience as an ISSM, ISSO Lead, SCA Lead, or equivalent cybersecurity management role
This is typical office or administrative work, and there is no exposure to adverse environmental conditions.
This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Apavo Corporation provides equal employment opportunities to all applicants and employees and strictly prohibits any type of harassment or discrimination in regards to race, religion, age, color, sex, disability status, national origin, genetics, sexual orientation, protected veteran status, gender expression, gender identity, or any other characteristic protected under federal, state, and/or local laws.
Consistent with the Americans with Disabilities Act (ADA), it is the policy of Apavo Corporation to provide reasonable accommodation when requested by a qualified applicant or employee with a disability, unless such accommodation would cause an undue hardship. The policy regarding requests for reasonable accommodation applies to all aspects of employment, including the application process. If reasonable accommodation is needed, please contact Apavo Human Resources.
Employment with Apavo Corporation is on an at-will basis, meaning either you or the Company can terminate the employment relationship, at any time, for any or no reason, and with or without cause or notice. As an at-will employee, your employment with Apavo Corporation is not guaranteed for any length of time.
- ...Senior Medical Coding Subject Matter Expert Federal Health Contract Support, Defense Health Agency... ...Eastern Time Reports to: Contract Manager, ASRT, Inc. Clearance: U.S.... ...or a comparable federal coding audit framework. • Two or more active coding credentials...SuggestedFull timeContract workFor contractorsLocal areaRemote workWorldwideMonday to Friday
- ...Logistics and Supply Chain management, systems and analysis, Cybersecurity... ...an Additive Manufacturing Subject Matter Expert that will thrive in a... ...capability and regulatory frameworks to enhance supply chain... ...advocate for AM capabilities. Risk Assessment : Support...SuggestedContract workRemote workFlexible hours
- ...QinetiQ US's dedicated experts in defense, aerospace... ...save lives; reduce risks to society; and maintain... ...Strategic Engagement Subject Matter Expert to lead... ...regulations, and policy frameworks * Ability to work in... ...organizational and project management skills * TS/SCI...SuggestedWork at office
- ...seeking a highly experienced and strategic Subject Matter Expert (SME) with deep expertise in... ...logistics planning within the VHA's framework. System Implementation:... ...Centralized Accounting for Local Management (CALM) Financial Management System...SuggestedLocal area
- ...Subject Matter Expert - Transition and Economic Development ProSidian is a Management and Operations Consulting Services Firm focusing on providing value to clients through... ...ProSidian services focus on the broad spectrum of Risk Management, Compliance, Business Process, IT...SuggestedFull timeWork at office
- ...Blue Sky Innovators is seeking a mid-level Anti-Tamper (AT) Subject Matter Expert to support the Anti-Tamper Executive Agent (DoD ATEA)... ...review, and refinement of Anti-Tamper policies, guidance, and frameworks Translate technical Anti-Tamper concepts and system...
$180k - $225k
...Technology Security Foreign Disclosure Subject Matter Expert This is a unique opportunity to... ...program security initiatives and develop risk management methodologies that incorporate... ...supporting artifacts), Adaptive Acquisition Framework, system security engineering, threat...Contract workWork at office- ...Senior Subject Matter Expert GMRC014 ProSidian is a Management and Operations Consulting Services Firm focusing on providing value to clients through tailored... ...ProSidian services focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness...Full timeFor contractorsInternshipWork at office
$150k - $200k
...quality in every aspect. As experts in healthcare IT, Apex is committed... ...experienced Senior Domain Subject Matter Experts to provide deep... ...clarification of findings, and risk reduction through accurate... ...health data governance frameworks, interoperability standards,...Contract workRemote work- ...Enterprise Architecture Subject Matter Expert IV Title: Enterprise Architecture... ...of network engineering management plans and network... ...network solutions and their framework Perform network modeling... ...managing very complex and/or high risk programs, and shall not serve...
$165.75k - $224.25k
...CI/CD Subject Matter Expert Continuous Integration / Continuous Deployment... ...-day practices to federal frameworks (NIST RMF/CSF, Zero Trust/TIC... ...without drama. By baking risk controls into the pipeline,... ...guardrail breach. Feature Management: Design of flag strategies...Contract workRemote workWork from homeFlexible hours$18k
...Energy Subject Matter Expert (Flexible Work Location) ProSidian is a Management and Operations Consulting Services Firm focusing on providing value to clients through... ...ProSidian services focus on the broad spectrum of Risk Management, Compliance, Business Process, IT...For contractorsWork at officeImmediate startFlexible hours- ...AI Risk & Evaluation Subject Matter Expert General Information Requisition # 968 Locations USA-VA-Arlington... ...seeking an experienced AI Risk Management & Evaluation Subject Matter Expert to support the development of frameworks, methodologies, and operational...Full timeLocal areaRemote work2 days per week1 day per week
- ...Cybersecurity Cloud Subject Matter Expert (SME) Serves as the primary cloud security architect responsible for ensuring... ...position requires deep expertise in DoD cybersecurity frameworks, FedRAMP compliance, Risk Management Framework (RMF), and the unique security...Contract work
$150k - $180k
...business challenges across financial management, healthcare, and government industries... ...are seeking an experienced Momentum Subject Matter Expert (SME) for a high-visibility modernization... ...(VA). The role uses Scaled Agile Framework (SAFe) practices with enterprise governance...Remote work$86.8k - $198k
...JCIDS Program Analysts Subject Matter Expert The Opportunity: As a Program Analysts Subject Matter Expert (SME), you will interpret,... ...Experience with DoDI 5000 series and Adaptive Acquisition Framework Possession of excellent communication skills for technical...Full timeContract workPart timeWork at officeLocal areaImmediate startRemote work- ...seeking a Public Affairs and Outreach Subject Matter Expert to support the Cybersecurity and... ..., is a tribally-owned firm providing management consulting services to U.S. government... ...Suitability. Familiarity with FEMA frameworks, National Response Framework (NRF), and...Full timeContract workWork at officeLocal areaVisa sponsorshipWork visaFlexible hours
- ...building a bench of highly qualified subject matter experts and professional training consultants... ...policy formulation and implementation. Management & Leadership:Organizational... ...or related legal and administrative frameworks. Public Diplomacy & Strategic Communications...Full timeWork at officeOverseas
- ...User Interface Subject Matter Expert (SME) / UI Team Lead Nationwide IT Services, NIS, is seeking... ...applications leveraging modern frameworks, messaging technologies, and enterprise... ...implementations, including configuration management of high-availability cloud OpenSearch...For contractorsWork at office
- ...highly experienced AWIPS Cloud Migration Subject Matter Expert (SME) Consultant to support upcoming... ...a firm grasp of NOAA/NWS operational frameworks. This role requires a consultant who... ...practices. Offer lifecycle management guidance for AWIPS infrastructure components...
$141k - $180k
...Overview Job Title: Project Specialist / Subject Matter Expert Location: White Oak, MD Function... ...for providing program and project management leadership for a portfolio of large,... ...comprehensive Project Plans, incorporating risk management, resource allocation, and...Full timeLocal area- ...officials regarding process, content and/or deliverables as required - Contribute content, identify best practices, and knowledge of subject matter, translate subject matter terminology as appropriate - Provide recommendations verybally and in writing - Usual work with a...Contract work
- ...Job Description (JD)_Audio-Video (A-V) Subject Matter Expert (SME): Key Responsibilities:... ...for physical damage within a strict framework to trigger immediate remediation orders... ...walls and raceways, executing clean wire management so zero cables are visible to room occupants...Contract workFor contractorsImmediate startRelocation
- ...Fraud Analytics Subject Matter Expert General Information Requisition # 684 Locations USA... ...of fraud detection, anomaly detection, risk scoring, and network analysis... ...mathematics, statistics, engineering, management information systems, decision science,...Full timeWork at officeLocal areaRemote work
$150k - $180k
...Engineering Team is seeking a senior design professional with subject-matter expertise in Department of Defense (DoD)/U.S. Navy facility... ...facility renovation and construction is preferred ~ Strong management skills and ability to manage an active portfolio of projects...Hourly payFull timePart timeWork at officeRelocationFlexible hours$9k
Modern Technology Solutions Incorporated (MTSI) is seeking an Air Warfare Systems Subject Matter Expert specializing in air warfare. You will be critical in advancing U.S. national security by ensuring cutting-edge air domain capabilities are integrated into multi-domain...Full timeImmediate startWorldwideFlexible hours- ...Enterprise Solutions and Management (ESM) is a rapidly growing government contractor... .... We are hiring a Senior ATO/A&A Subject Matter Expert to support an enterprise-level... ...collecting, and reporting on all applicable Risk Management Framework (RMF) controls, and provides formal...For contractorsWork at officeLocal areaImmediate startRemote work
- ...Oncology Physician Subject Matter Expert Prometheus Federal Services (PFS... ...while a dedicated project management team leads day-to-day execution... ...and mitigation of program risks, issues, and dependencies,... ...performance measurement frameworks ~ Proven ability to manage...Full timeContract workPart timeFlexible hours
- ...possibly looking for a Blood Program Subject Matter Expert to provide support for our government... ...Military Standardized Requirement. Manage and oversee donor screening processes,... ...a Tier II Investigation for a Moderate Risk Public Trust Position The Alaka`ina...
- ...Title: Cybersecurity ~ Subject Matter Functional Expert IV Location: Alexandria, VA Clearance: TS/SCI with the ability to obtain and maintain... ...area of technical expertise Coordinate with contract management and government personnel to ensure the problems have...Contract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Risk Management Framework Subject Matter Expert. Be the first to apply!
- fulfillment expert Alexandria, VA
- guest service support expert Alexandria, VA
- technology expert Alexandria, VA
- subject matter expert Alexandria, VA
- risk assurance Alexandria, VA
- technology risk Alexandria, VA
- risk management coordinator Alexandria, VA
- rn risk management Alexandria, VA
- efficiency expert
- social media expert



