Cybersecurity RMF Lead
$62k - $141kBooz Allen Hamilton
The Opportunity:
Design, implement, and manage policies and procedures to ensure database and software security. Apply advanced consulting skills or extensive technical expertise and full industry knowledge. Develop innovative solutions to complex problems. Work without considerable direction. Mentor and may supervise team members.
You Have:
5+ years of experience with RMF, including supporting system categorization, control selection, implementation, and continuous monitoring
Experience supporting Assessment & Authorization (A&A) activities such as evidence collection, POA&M updates, and security documentation
Experience evaluating and interpreting security controls such as NIST SP 800 53 to ensure compliance throughout the system lifecycle
Experience integrating Zero Trust principles into RMF packages and system security architecture
Secret clearance
Bachelor’s degree in Management Information Systems, Information Technology, Computer Science, Mathematics, Business, Engineering, or Physical Science
CompTIA Advance Security Practitioner (CASP+), CompTIA Security+, or Systems Security Certified Practitioner (SSCP) Certification
Nice If You Have:
Experience leading RMF efforts across multiple systems, including providing oversight, task delegation, and ensuring continuous compliance throughout operations
Experience conducting security engineering analyses, including advising system owners on risk impacts, mitigations, and RMF aligned design tradeoffs
Experience integrating RMF workflows with DevSecOps or Agile execution environments, including sprint-based compliance validation and continuous monitoring
Experience performing enterprise risk assessments, documenting findings, and advising leadership on security posture and compliance roadmaps
DoD 8140 CWF-Aligned Certifications
Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $62,000.00 to $141,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.Identity Statement
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Candidate AI Usage Policy
AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided .
Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
Remote : If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
Hybrid : If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
Onsite : If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
- Bna Inc in Washington, DC is seeking a Senior ISSO to lead cybersecurity compliance and security operations for federal information systems.... ...activities, supporting classified environments, and requires strong RMF and vulnerability management expertise. The ideal candidate...Suggested
- ...are authorized, operated, and maintained in compliance with NIST RMF and SAA requirements, working with system owners, ISSOs, ISSEs, assessors, and Authorizing Officials. Responsibilities include leading the SAA/ATO process, guiding on baseline controls, and coordinating...Suggested
- Guidehouse is seeking a cybersecurity professional to lead and support RMF and A&A documentation, including SSPs, SARs, and POA&Ms, across on-premise and cloud platforms. The role supports cATO goals through automated control validation and evidence workflows. The candidate...Suggested
- ...Arlington, VA, seeks a Systems Integration Manager to lead technical programs from planning through execution... ...Schedules (IMS), coordinate across engineering, cybersecurity, procurement, and operations, and support RMF authorization documentation for DoD IT systems. The...Suggested
- ...Information Security Analyst to support a DoD client with enterprise cybersecurity for a large program serving military families. This hybrid... ...Alexandria, VA and an active Secret clearance. The position leads RMF/eMASS, threat detection, vulnerability management, incident...Suggested
- Guidehouse is seeking a cybersecurity professional to lead RMF and A&A activities for federal clients, focusing on documentation, control implementation, and continuous authorization. You will work across on‑premise and cloud platforms, aligning with FedRAMP, FISMA, and...
- People Technology And Processes is seeking a Cybersecurity Analyst V (Senior) in Washington D.C. This full-time position entails leading RMF lifecycle execution, overseeing vulnerability management, and helping to compile Security Authorization Packages. A Bachelor’s degree...Full time
- ...SPA) seeks an Information Systems Security Manager (ISSM) to lead RMF activities for APACS and related systems. You will maintain authorizations... ...effective security controls. The role requires 8+ years in cybersecurity for DoD systems, TS/SCI clearance, and strong RMF/eMASS...
- ...Systems Integration Manager to oversee DoD programs, coordinating between program management, engineering, cybersecurity, and operational teams. You will manage IMS, RMF documentation, and procurement activities, ensuring ATO/IATT processes, risk management, and successful...
- Systems Planning and Analysis, Inc. seeks an Information Systems Security Manager (ISSM) to lead RMF, eMASS, and related cybersecurity activities for APACS and associated systems, protecting sensitive data and maintaining authorizations to operate. The role collaborates...
- Zermount, Inc is seeking an ISSO Program Manager to lead security governance and RMF activities for a federal client. This role combines project management with cybersecurity expertise to ensure secure, compliant operations across enterprise systems. The role requires...
- ...seeking an Information System Security Manager (ISSM) to oversee the cybersecurity posture of DoD information systems for a fast-paced Air Force... ...Management Center program. This on-site role requires DoD RMF, risk assessments, security policy development, and continuous...
- ...System Security Manager (ISSM) to oversee the cybersecurity posture of DoD information systems,... ...and implement security policies, conduct RMF-based risk assessments, and manage ATO processes... ...policy experience, and the ability to lead cross‑functional teams while delivering...
- ...Systems Security Manager to support U.S. Navy systems from our Fairfax, VA office. The ISSM will lead RMF activities, manage eMASS accreditation, and advise on cybersecurity risk across the SDLC. The ideal candidate will have 8+ years in cybersecurity with 3+ years as...Work at office
- IPT Associates (IPTA) in Fort Belvoir, VA is seeking a Cybersecurity SME specializing in Assessment and Authorization (A&A) to join our team. You will apply RMF and NIST guidelines to authorize and sustain complex information systems across large environments, including...
- E-Logic Inc. seeks a Lead ISSO to support the U.S. International Development Finance Corporation (DFC) Information System Security... ...DFC's enterprise environment. The role requires hands-on cybersecurity expertise and the ability to interface with federal leadership...
- Jobtailor in Washington, DC seeks an experienced project manager to lead cybersecurity assessment and authorization initiatives across multiple programs. You will oversee integrated project plans, schedules, and deliverables while ensuring risk management and regulatory...2 days per week
- ...seeks an Information System Security Manager (ISSM) to oversee cybersecurity posture for DoD information systems on a fast-paced Air Force Life... ...Security Engineers, and cross-functional teams to implement RMF, risk assessments, audits, and continuous monitoring, ensuring...
$135k - $165k
RMF/Assessment & Authorization Team Lead Bethesda, Maryland, United States SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered...Contract workFor contractorsFor subcontractorWork at office- ...a Senior/Alternate ISSO to support DFC’s cybersecurity program. This role will perform senior ISSO... ...duties for assigned systems and support RMF, continuous monitoring, vulnerability... ...Alternate ISSO must be qualified to assume Lead ISSO duties during scheduled or unscheduled...
- Astrion is seeking a Senior Cybersecurity Analyst located at the Washington Navy Yard in Washington, DC. This role involves leading efforts in the Risk Management Framework process, providing cybersecurity expertise, and ensuring compliance with DoD standards. The ideal...Full time
- ...to delivering impactful results that strengthen missions and drive lasting value. ResponsibilitiesLMI is seeking a skilled ISSM / RMF Lead to manage information systems security and Risk Management Framework (RMF) activities across a network of technical communications...Full time
$112.8k - $257k
...enterprise DevSecOps, AI, and ML. Apply leading-edge principles, theories, and concepts.... ...delivery across key areas such as development, cybersecurity, data engineering and analytics, and... ..., including Risk Management Framework (RMF), Security Requirements Guides (SRG),...Full timeContract workPart timeWork at officeLocal areaRemote work$69.4k - $158k
..., LeadThe Opportunity:When our country’s cybersecurity is on the line, simply reacting is not enough... ...Officer (ISSO) on our team, you’ll lead the assessment of the Department of War's... ...against current cyber policies, including RMF, and identify areas of improvement and work...Full timeContract workPart timeWork at officeLocal areaRemote work- ...Cybersecurity Lead The Cybersecurity Lead will provide the Defense Nuclear Facilities Safety Board (DNFSB) support and implement all phases of the Risk Management Framework (RMF). Responsibilities Ensure information systems maintain an appropriate level of...Temporary workFor contractorsWork at officeImmediate startFlexible hours
$150k - $175k
...federal contracting company, is seeking a Lead Systems Administrator with strong Linux... ...across multiple datacenters, partnering with cybersecurity and engineering teams, and providing Tier... ...platforms (IL5-IL6+)Knowledge of STIGs, RMF, and DoD cybersecurity standardsKnowledge...Local areaRemote workRelocation package- ...analysis in various areas and technologies for RMF Assessment and Authorization (A&A)... ...implementation). Risk Management: Leading the identification, assessment, and mitigation... ...: Collaborating closely with IT, cybersecurity, and senior management teams to align security...
$112.8k - $257k
DFIR Team Lead The Opportunity: Lead and inspire a team of skilled incident response analysts, fostering a culture of technical... ...major incidents and coordinating efforts to contain and resolve cybersecurity issues. Convey status updates to critical stakeholders,...Full timeContract workPart timeWork at officeLocal areaRemote workAfternoon shift- ...Overview SecurePro is seeking experienced Lead and Senior Information System Security Officers (ISSOs) to support a federal cybersecurity program in Washington, DC. The team will... ..., including Risk Management Framework (RMF) and authorization activities, continuous...Contract work
- ...Job Description Job Description Position: Cybersecurity Lead Clearance: Secret Location: Crystal City, VA (Hybrid Telework) Type... ...NIST Standards SP 800-171 (CMMC), SP 800-37 & 800-53 (FISMA RMF), SP 800-30 (Risk Assessment), SP -800-161 (C-SCRM), SP 800-2...Full timeTemporary workWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity RMF Lead. Be the first to apply!
- IT cyber security Arlington, VA
- cyber security intern Arlington, VA
- cybersecurity technical writer Arlington, VA
- cybersecurity certificate Arlington, VA
- cybersecurity grc Arlington, VA
- cybersecurity Arlington, VA
- remote cyber security Arlington, VA
- cybersecurity administrator Arlington, VA
- senior cybersecurity engineer Arlington, VA
- cyber security lead Arlington, VA


