Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber RMF Specialist

SHR Consulting Group

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process. Cyber RMF Specialist Full Time Arlington, VA, VA, US 9 days ago Requisition ID: 1452 SHR – S oftware H ardware R e-engineered About SHR Consulting Group: SHR is a premier technology integrator solving our nation’s most complex modernization and readiness challenges across the defense, federal civilian, and intelligence markets. Our robust portfolio of offerings includes high-end solutions in systems engineering and integration; enterprise IT, including cloud services; cyber; software; advanced analytics and AI. With an intimate understanding of our customers’ challenges and deep expertise in existing and emerging technologies, we integrate the best components from our own portfolio and our partner ecosystem to deliver innovative, effective, and efficient solutions. We are a rapidly growing organization seeking experienced Cyber RMF Specialist to provide IT expertise for supporting a DISA environment. This position is responsible for executing the DoD Risk Management Framework (RMF) and broader cyber compliance functions across the assigned IT portfolio. The Cyber RMF Specialist ensures that systems, accreditation boundaries, and supporting processes are properly assessed, documented, monitored, and maintained, and that the resulting compliance posture adheres to DoD security standards, organizational values, and contractual performance requirements. This role supports Government customers across one or more classification domains and may require work across standard business hours or on a shift/rotational schedule depending on task order requirements. The Cyber RMF Specialist works in close partnership with system owners, system administrators, the cybersecurity team, and the Authorizing Official's staff to ensure systems achieve and sustain Authorization to Operate (ATO) status and remain compliant with all applicable DoD, CYBERCOM, and DISA policies, directives, and orders. Duties will vary based on position and area of focus: Execute RMF activities in accordance with DoD Instruction 8510.01 across the six RMF steps: Categorize, Select, Implement, Assess, Authorize, and Monitor. Develop, review, and maintain System Security Plans (SSPs), Risk Assessment Reports (RARs), Security Assessment Reports (SARs), and supporting Assessment and Authorization (A&A) artifacts. Coordinate with system owners and engineering teams to capture system descriptions, accreditation boundaries, data flows, and information types in accordance with CNSSI 1253 and NIST SP 800-53. Support ATO sustainment, reauthorization, and ongoing authorization activities for assigned accreditation boundaries. eMASS Administration: Administer the Enterprise Mission Assurance Support Service (eMASS) including system registration, control implementation status updates, artifact uploads, and workflow routing to the assessor and Authorizing Official. Continuous Monitoring: Execute continuous monitoring activities including control reassessment, configuration drift analysis, and recurring evidence collection to maintain authorization currency. Control Mapping: Maintain accurate mappings between deployed technical controls, NIST SP 800-53 control statements, and DoD overlays so that compliance evidence is traceable end-to-end. POA&M and Vulnerability Management Develop, track, and update Plan of Action and Milestones (POA&Ms) on the cadence required by Government leadership. Coordinate with technical SMEs to scope remediation actions, validate completion, and submit milestone updates. Conduct root cause analysis for repeat findings and recommend systemic controls to drive down the vulnerability backlog. Post-Inspection Discrepancies: Develop and submit follow-on POA&Ms after Government inspections, audits, or assessments within Government-required timelines. Risk Acceptance Coordination: Prepare risk acceptance packages where remediation is not feasible and coordinate Government approval through the appropriate authority. STIG, IAVM, and Cyber Hygiene Conduct STIG compliance assessments using SCAP-based tools, STIG Viewer, and manual checks against deployed systems. Develop and maintain schedules for manual STIG checks and ensure recurring execution by responsible technical teams. Analyze ACAS / Nessus vulnerability scan output, develop weekly scan analysis reports, and coordinate remediation with system owners. Track new Information Assurance Vulnerability Management (IAVM) advisories and STIG releases; produce recurring metrics on coverage and remediation status. Boundary Posture Management: Maintain assigned accreditation boundaries at a non-critical vulnerability posture as defined by Government quality standards and report any deviations to leadership. Cyber Tasking and Deployment Compliance Acknowledge receipt of TASKORDs, OPORDs, and other Government cyber tasking within the required response window. Decompose Government cyber tasking into actionable work, assign to responsible parties, and track to closure with auditable evidence. Deployment Compliance: Coordinate with system administrators and engineering teams to validate compliance of new deployments and produce recurring reporting on deployment, software introduction, and patching tool status. Cyber Workforce Compliance: Track DoD 8570.01-M and DoD 8140 workforce certification compliance for cyber personnel; coordinate certification renewals and provide monthly compliance reporting to the cybersecurity team. Cybersecurity and Compliance Coordination Ensure all assigned systems maintain compliance with DoD Security Technical Implementation Guides (STIGs), Information Assurance Vulnerability Alerts (IAVAs), and applicable Command Cyber Tasking Orders (CCTOs). Support cybersecurity incident response activities including evidence collection, timeline reconstruction, and after-action reporting. Participate in cybersecurity coordination calls, RMF working groups, and Government-led security reviews. Adhere to DoD 8570.01-M / DoD 8140 Information Assurance workforce requirements applicable to the assigned role. Documentation and Communication Develop, update, and maintain SOPs, Work Instructions (WIs), and technical documentation for all supported compliance functions. Provide status updates, incident reports, and After Action Reports (AARs) as required by Government leadership. Participate in configuration change control board (CCB) processes; ensure security impact of changes is assessed prior to approval. Collaborate with network, cybersecurity, storage, and application teams to resolve cross-functional compliance issues. Provide content for recurring leadership briefings on RMF status, ticket metrics, vulnerability posture, and SLA impact. Provide technical support and training to end users and junior staff as needed. Security Clearance Requirement U.S. Citizenship and a minimum active Secret security clearance is required for this position. Certain task orders or work locations may require a Top Secret (TS) or TS/SCI clearance. All personnel must be able to obtain and maintain the required clearance level and must possess a valid DoD Common Access Card (CAC). Personnel may be required to access systems across multiple classification domains, including Unclassified (NIPR), Secret (SIPR), and Top Secret/Collateral networks. Education Requirements Bachelor's degree in Computer Science, Computer Engineering, Information Technology, Information Systems, Cybersecurity, or a closely related technical field; OR Associate's degree in a related technical field plus additional qualifying experience; OR Equivalent combination of education, training, and directly relevant DoD IT experience as defined by labor category level below: Junior (0-2 years) - Works under supervision; executes defined tasks; learns SOPs and tools Mid (3-5 years) - Works independently on most tasks; supports complex troubleshooting; mentors juniors Senior (6+ years) - SME-level expertise; leads technical efforts; guides architecture and compliance decisions Minimum Qualifications Working knowledge of the DoD Risk Management Framework (RMF) and NIST SP 800-53, NIST SP 800-37, and CNSSI 1253. Experience with eMASS or an equivalent A&A workflow tool. Working knowledge of DoD STIGs, IAVAs, SCAP, and STIG Viewer. Experience analyzing ACAS / Nessus vulnerability scan results. Familiarity with Windows Server, Active Directory, and common DoD IT infrastructure. Ability to apply DoD STIGs and IAVAs to maintain system compliance. Ability to create and maintain technical documentation, SOPs, and compliance artifacts. Ability to work shift hours, weekends, or on-call rotations as required by task order. Strong oral and written communication skills; ability to brief technical topics to non-technical stakeholders. Preferred Qualifications Experience in a DoD, Intelligence Community, or Federal Government IT environment. Familiarity with ITIL service management practices. Experience with Tanium, Splunk, or other endpoint compliance and SIEM tooling. Familiarity with Continuous Monitoring (CONMON), Cyber Hygiene, and JFHQ-DODIN operations. Experience supporting Authorizing Official (AO) packages and ATO submissions. Familiarity with cloud RMF (DoD Cloud Computing Security Requirements Guide, FedRAMP) and applicable overlays. Knowledge of cloud platforms (Microsoft Azure Government, AWS GovCloud) and hybrid infrastructure environments. Experience with PowerShell, Python, or other scripting languages for compliance automation. Knowledge of DoD Identity, Credential, and Access Management (ICAM) frameworks. Required Certifications Personnel must meet DoD Directive 8570.01-M / DoD 8140 baseline certification requirements applicable to their assigned Cyber IT/Cybersecurity role. One of the following certifications satisfies the minimum IAT Level II requirement: CySA+ (CompTIA Cybersecurity Analyst) GIAC Security Essentials (GSEC) Systems Security Certified Practitioner (SSCP) Additional computing environment (CE) certifications may be required depending on the specific technologies managed (e.g., Microsoft, VMware, Red Hat, Cisco). Certifications must be current and maintained throughout the period of performance. Desired Additional Certifications Certified Authorization Professional (CAP) or Governance, Risk and Compliance Certification (CGRC). Certified Information Systems Security Professional (CISSP). Certified Information Security Manager (CISM). ACAS Vulnerability Management certification. Work Environment and Physical Requirements Work is performed in a Government facility or contractor site supporting classified and/or unclassified IT environments. Personnel may be required to work in data centers or consolidated server rooms with associated environmental conditions (temperature, noise, physical equipment). Occasional lifting of IT equipment up to 50 lbs may be required. Personnel may be required to support 24x7 operations via scheduled shifts or on-call arrangements. Travel to alternate Government sites may be required on an as-needed basis. Competitive salary based on experience Comprehensive benefits package including health, dental, vision, and retirement plans Paid time off and holidays We are an Equal Opportunity Employer and consider all qualified applicants without regard to protected characteristics under applicable law. EEO/AA Employer/Veteran/Disabled. #J-18808-Ljbffr

Vacancy posted 21 hours ago
Similar jobs that could be interesting for youBased on the Cyber RMF Specialist in Arlington, VA vacancy
  • SHR CONSULTING GROUP, LLC is looking for a Cyber RMF Specialist based in Arlington, VA. This full-time position involves executing the DoD Risk Management Framework, ensuring compliance with security standards, and supporting Government customers across various domains... 
    Cyber
    Full time

    SHR CONSULTING GROUP, LLC

    Arlington, VA
    2 days ago
  •  ...owned company in Washington, DC is seeking a Senior Information Systems Security Specialist. The role requires over 10 years of experience in Navy Cybersecurity programs, strong knowledge of Cyber Security and Risk Management Framework. A Bachelor’s degree in a related... 
    Cyber

    International Executive Service Corps

    Washington DC
    4 days ago
  •  ...supporting DoD cybersecurity operations, including vulnerability management and compliance activities per the Risk Management Framework (RMF). Candidates should have over 5 years of relevant experience, a high school diploma or GED, and a DoD Top Secret clearance. The... 
    Cyber

    Chenega Corporation

    Oakton, VA
    3 days ago
  • $131.3k - $237.35k

     ...Koitecc Solutions is seeking an experienced SME Zero Trust Cyber Security Analyst in Alexandria, VA. This role involves designing and enhancing...  ...12-15 years of cybersecurity experience, and strong knowledge of RMF processes. Attractive salary range is $131,300 to $237,350, along... 
    Cyber

    Koitecc Solutions

    Alexandria, VA
    5 days ago
  •  ...RiVidium is seeking a Cyber Threat Intelligence Specialist to support our planned MODES III team supporting Military Community and Family Policy (MC&FP...  ...compliance; maintains privileged security oversight, manages RMF control validation, eMASS updates, ATO renewals,... 
    Cyber
    Contract work

    Rividium Inc

    Alexandria, VA
    4 days ago
  • TLN Worldwide Enterprises Inc is looking for a Senior Cyber Security Analyst to provide expert-level cybersecurity support for Navy systems. This position involves leading Risk Management Framework (RMF) activities, ensuring compliance with DoD security requirements, and... 
    Cyber
    Worldwide

    TLN Worldwide Enterprises Inc

    Washington DC
    5 days ago
  • DecisionPoint Corporation is seeking a Cyber Security Analyst - Intermediate to support cybersecurity governance and operational defense. This role involves RMF/A&A and TRM specialization, alongside frontline SOC support through Microsoft Sentinel monitoring. The applicant... 
    Cyber
    Remote job

    DecisionPoint Corporation

    Washington DC
    3 days ago
  • $191.85k

     ...You will serve as an IT Cybersecurity Specialist (INFOSEC) under a Program Office within TEAMSUB...  ...(FISMA) and Risk Management Framework (RMF) guidelines. You will perform regular...  ...maintain qualifications in DoDM 8140.03 Cyber Workforce Qualification and Department of... 
    Cyber
    Full time
    Part time
    Interim role
    Work at office
    Immediate start
    Relocation

    Naval Sea Systems Command

    Washington DC
    1 day ago
  • $100k - $150k

     ...Sigma Defense is seeking a Senior Cybersecurity Specialist to provide advanced technical and analytical...  ...and maintenance of cybersecurity architecture, cyber engineering artifacts, cybersecurity performance metrics, RMF authorization packages, and enclave-level cyber... 
    Cyber
    Contract work

    SOLUTE Careers

    Washington DC
    3 days ago
  • $66.9k - $115k

     ...Research, An Accenture Federal Services Company in Washington, DC, seeks a Cyber Support Specialist to support cybersecurity activities ensuring compliance with the Risk Management Framework (RMF). This role involves collaborating with stakeholders, conducting... 
    Cyber

    ASM Research, An Accenture Federal Services Company

    Washington DC
    2 days ago
  • A cybersecurity solutions provider is seeking a Cyber Security Analyst - Intermediate to support cybersecurity governance and defense. This role requires expertise in RMF/A&A processes and SOC operations, utilizing tools like Microsoft Sentinel for monitoring. Preferred... 
    Cyber
    Remote job

    DecisionPoint Corporation

    Washington DC
    3 days ago
  •  ...and science and technology. #MC SPA is seeking an IT Support Specialist to support NAVSEA's Naval Special Warfare Program Office.#FC...  ...support to NAVSEA PMS 340, including developing and maintaining RMF documentation, managing eMASS entries, conducting security control... 
    Cyber
    Work at office

    Systems Planning and Analysis, Inc

    Alexandria, VA
    2 days ago
  • $103.2k - $172k

     ...seeking Information Assurance/Cybersecurity Specialists (Junior, Mid, and Senior) with a...  ...tasks that require expertise in firewall, cyber, cloud computing, implementation/configuration...  ...Assist in maintaining compliance with RMF and other DoD cybersecurity frameworks... 
    Cyber
    Contract work
    Work experience placement
    H1b
    Local area

    SMX Corporation

    Washington DC
    6 days ago
  • R&P Technologies is hiring a Cyber Security Analyst to support the fleet modernization of Navy programs. The role requires at least 10 years...  ...and a thorough understanding of Navy Risk Management Framework (RMF). Qualified candidates must have CISSP or CompTIA Security+... 
    Cyber

    R&P Technologies

    Washington DC
    2 days ago
  • $95k - $150k

     ...We are seeking a Cybersecurity Assurance Specialist to join our TekSynap Defense team. REQUIRED...  ...knowledge of Risk Management Framework (RMF) principles and processes. Proficiency...  ...Assurance Certification (GIAC) Global Industriel Cyber Security Professional (GICSP) Global... 
    Cyber
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Remote work
    Monday to Friday
    Weekend work
    Day shift
    Afternoon shift

    TekSynap

    Washington DC
    4 days ago
  • NV5, Inc. is seeking a Risk Management Framework (RMF) Specialist in Washington, DC to oversee cybersecurity processes and ensure compliance with DoD and Air Force policies. The role involves implementing RMF for Air Force information systems and conducting thorough risk... 

    NV5, Inc.

    Washington DC
    2 days ago
  •  ...Senior Cyber-Security Analyst / Navy Validator Provides Information Assurance (IA) support for the Office of Naval Research (ONR) in...  ...systems and networks. Implements Navy Risk Management Framework (RMF) Implementation Plan IAW DODI 8510.01. Develops, coordinates,... 
    Cyber
    For contractors
    Work at office
    Local area

    Saliense Consulting LLC

    Arlington, VA
    4 days ago
  • $112.8k - $257k

     ...Job Number: R0238707 Cybersecurity and RMF Engineer, Lead The Opportunity Are you looking for an opportunity to share your experience in cyber security and systems engineering that will support the US Air Force? As a systems security and network security engineer, you... 
    Cyber
    Full time
    Part time
    Local area

    Phase2 Technology

    Arlington, VA
    5 days ago
  •  ...enterprise IT, including cloud services: cyber, software, advanced analytics, and AI. With...  ...Change and Configuration Management Specialist to lead and execute the configuration and...  ...Familiarity with DoD Risk Management Framework (RMF), STIGs, and IAVM compliance impacts on... 
    Cyber
    Work at office
    Local area

    Shrgroup.net

    Arlington, VA
    5 days ago
  •  ...Level 2 assessments. The CMMC Assessment Specialist plays a key role representing clients in...  ...Professional certifications such as the Cyber AB’s CCA (preferred) or CCP, or other industry...  ...800‑171) or federal information systems (RMF, NIST SP 800‑53) preferred. Bachelor’s... 
    Cyber
    For contractors
    Work at office
    Remote work

    C3 Integrated Solutions

    Arlington, VA
    5 days ago
  •  ...Information Assurance Specialist Advanced Decision Vectors, LLC (ADV), established in 2009,...  ...provides hands-on Information Assurance and Cyber Assurance support across SCI and Special...  ...with DoD cybersecurity policies, RMF requirements, and approved security authorization... 
    Cyber
    Full time
    Temporary work
    For contractors
    Work at office
    Remote work
    Monday to Friday
    Flexible hours

    ADVANCED DECISION VECTORS, LLC

    Washington DC
    5 days ago
  • ASRC Federal is looking for a Vulnerability Assessor in Alexandria, VA who will support the DoWEA Enterprise Cyber Program. This hybrid role involves identifying and analyzing system vulnerabilities to enhance cybersecurity compliance. The ideal candidate will have over... 
    Cyber

    ASRC Federal

    Alexandria, VA
    2 days ago
  •  ...providing oversight for Security Assessment and Authorization activities. The ideal candidate will have a Bachelor's degree in a related field and significant experience in IT security, including RMF assessments and a strong understanding of NIST guidance. #J-18808-Ljbffr... 
    Cyber
    Remote work

    Koitecc Solutions

    Silver Spring, MD
    23 hours ago
  •  ...measures. If you are passionate about cybersecurity and eager to contribute to impactful projects, this position is perfect for you. Join a forward-thinking firm that values creativity, growth, and community in the ever-evolving landscape of cyber threats. #J-18808-Ljbffr... 
    Cyber

    Scout Solutions Inc Defunct

    Washington DC
    4 days ago
  • Diligent Consulting Inc is seeking a Cyber Security Incident and Event Management/Elastic Specialist in Washington, DC. The role requires a clear understanding of Elastic and SIEM processes. Candidates must be US citizens with a Secret Clearance and have at least three... 
    Cyber

    Diligent Consulting Inc

    Washington DC
    4 days ago
  • NOVA Corporation is seeking a part-time Information System Security Officer (ISSO) to support the United States Court of Appeals for the Armed Forces in Washington, DC. This role includes managing the cybersecurity lifecycle and requires active DoD Secret clearance along...
    Cyber
    Part time

    NOVA

    Washington DC
    4 days ago
  •  ...LMI Government Consulting is seeking a Cyber Engineer in McLean, Virginia, to integrate and deploy the LIGER AI platform. The role demands 5+ years in cybersecurity solutions, including RMF and eMASS experience, alongside active TS/SCI clearance. Responsibilities include... 
    Cyber

    LMI Government Consulting

    McLean, VA
    4 days ago
  •  ...Chenega Corporation is hiring a Senior Cyber Security Engineer in Vienna, VA, to support crucial DoD and Intel missions. This role involves...  ...Top Secret Security Clearance. Responsibilities include applying RMF processes, conducting vulnerability assessments, and... 
    Cyber

    Chenega Corporation

    Vienna, VA
    4 days ago
  • $120k - $132k

     ...maintain communication with intelligence communities. Candidates must have at least a Bachelor's degree and extensive experience in cyber threat analysis. The role includes cataloging threat activity and requires travel. SkyePoint offers competitive compensation ranging... 
    Cyber

    SkyePoint Decisions, Inc.

    Arlington, VA
    5 days ago
  • Coalfire in Washington, D.C. is seeking a Senior Information System Security Officer (SR ISSO) to oversee cybersecurity compliance and risk assessments. The ideal candidate will have at least 5 years of experience in ISSO duties, including systems security assessments....
    Cyber
    Flexible hours
    3 days per week

    Coalfire

    Washington DC
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber RMF Specialist. Be the first to apply!