Cybersecurity Lead / RMF Team Lead

International Executive Service Corps

San Diego (CA)

On-site

USD 140,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

International Executive Service Corps seeks a Cybersecurity Lead to perform independent RMF assessments for DoD/NAVSEA programs. The role requires active TS/SCI clearance, a Navy QV Level III, and IAM II/III certifications.

You will review SSPs, data flows, and vulnerability data while producing SAR/RAR and mentoring ISSMs/ISOs. The candidate will operate under strict independence, validate NIST 800-53 controls, and work in DoD cybersecurity environments with high risk impact, contributing to

Qualifications

  • Active TS/SCI clearance and U.S. citizenship.
  • Bachelor's degree in CS/IA/Cybersecurity from an accredited institution.
  • 7+ years of cybersecurity experience with 4+ years RMF DoD validation.
  • Current Navy Qualified Validator (NQV) Level III.
  • Active IAM Level II or III baseline certification (e.g., CAP, CASP+, CISM, CISSP).
  • Deep technical expertise in vulnerability data interpretation and cryptographic implementations.
  • Proven ability to produce detailed risk assessment reports for senior government consumption.

Responsibilities

  • Conduct independent, comprehensive assessments of DoD/ DON/ NAVSEA IT, PIT, and OT systems.
  • Maintain independence from system engineering, ISSM, and ISSO during validation.
  • Act as Trusted Agent to Navy SCA and SCAL with objective, risk-based recommendations.
  • Review SSPs, architecture diagrams, data flow diagrams, and baselines for accuracy.
  • Validate NIST 800-53 controls by reviewing test evidence and interviewing personnel.
  • Analyze ACAS, STIG checklists, and manual test data to identify residual risks.
  • Generate SAR and RAR with clear articulation of impact of vulnerabilities.
  • Review POA&M entries ensuring mitigations are technically sound and resourced.
  • Perform extensive eMASS reviews and update control validation status.
  • Provide mentorship to ISSMs and ISSOs on artifact quality and control interpretation.
  • Support continuous monitoring and POA&M closure activities.
  • Maintain registration on the Navy Qualified Validators registry.

Skills

RMF assessments
NIST 800-53
Vulnerability analysis
Report writing
eMASS familiarity

Education

Bachelor's degree in CS/IA/Cybersecurity

Tools

eMASS
ACAS
STIGs

Job description

Job Description:
Position Overview

ORBIS is seeking a Cybersecurity Lead / RMF Team Lead to serve as an independent, third-party assessor for the NSWC Corona CCAM contract. The NQV Level III is a critical oversight role responsible for evaluating the security posture of Navy systems and providing trusted recommendations to the Navy Security Control Assessor (SCA). The successful candidate will ensure that system security controls are implemented correctly and effectively to mitigate risk to Navy operations.

Validation & Assessment Responsibilities:
  • Execute independent, comprehensive assessments of complex IT, PIT, and Operational Technology (OT) systems against DoD, DON, and NAVSEA cybersecurity standards.
  • Maintain strict separation of duties, ensuring complete independence from the system engineering, ISSM, and ISSO functions during the validation process.
  • Act as a Trusted Agent to the Navy SCA and SCA Liaison (SCAL), providing objective, risk-based recommendations regarding system authorizations.
  • Perform detailed reviews of System Security Plans (SSPs), architecture diagrams, data flow diagrams, and hardware/software baselines for accuracy and completeness.
  • Validate the implementation of NIST 800-53 security controls by reviewing test evidence, interviewing personnel, and directly observing system configurations.
  • Analyze automated vulnerability scanning results (ACAS), STIG checklists, and manual test data to verify compliance and identify residual risks.
  • Generate and finalize the Security Assessment Report (SAR) and Risk Assessment Report (RAR), clearly articulating the operational impact of unmitigated vulnerabilities.
  • Review and validate the accuracy of Plan of Action and Milestones (POA&M) entries, ensuring proposed mitigations are technically sound and appropriately resourced.
  • Conduct extensive reviews within eMASS, updating the validation status of individual controls and the overall package prior to SCA submission.
  • Provide continuous feedback and mentorship to ISSMs and ISSOs regarding the quality of package artifacts and the proper interpretation of security controls.
  • Support continuous monitoring efforts by validating the closure of POA&M items, assessing the impact of system upgrades, and reviewing annual security control assessments.
  • Maintain active registration on the official Navy Qualified Validators registry and comply with all ongoing training and professional development requirements.
Required Qualifications & Clearances:
  • Clearance: Must possess an active, TS/SCI and be a United States citizen.
  • Education: Bachelor's degree in Computer Science, Information Assurance, Cybersecurity, or a related STEM field from an accredited institution.
  • Experience: A minimum of seven (7) years of experience in cybersecurity, with at least four (4) years directly involved in executing RMF assessments or validations for the DoD.
  • Certifications (NQV): Must hold a current, active Navy Qualified Validator (NQV) Level III certification and provide formal documentation/appointment letters.
  • Certifications (DoD 8570): Must maintain an active IAM Level II or Level III baseline certification (e.g., CAP, CASP+ CE, CISM, CISSP).
  • Deep technical expertise in interpreting vulnerability data, network traffic analysis, and cryptographic implementations.
  • Proven ability to write comprehensive, technically accurate, and highly detailed risk assessment reports for senior government consumption.
Preferred Qualifications:
  • Active Top Secret clearance.
  • Prior experience validating tactical combat systems, weapons systems, or specialized hull, mechanical, and electrical (HM&E) systems.
  • Experience participating in Navy Cybersecurity Inspection and Certification Program (CSICP) or Command Cyber Readiness Inspections (CCRI).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Manager III
Information System Security Manager III

International Executive Service Corps • San Diego (CA)

On-site
USD 150,000 - 210,000
Information System Security Officer III
Information System Security Officer III

International Executive Service Corps • San Diego (CA)

On-site
USD 120,000 - 180,000
Cybersecurity Program Manager
Cybersecurity Program Manager

International Executive Service Corps • San Diego (CA)

On-site
USD 140,000 - 200,000
RMF Cybersecurity Lead — DoD/Navy Assurance
RMF Cybersecurity Lead — DoD/Navy Assurance

International Executive Service Corps • San Diego (CA)

On-site
USD 140,000 - 180,000
Cybersecurity Analyst V (Senior) with Security Clearance
Cybersecurity Analyst V (Senior) with Security Clearance

People, Technology & Processes, LLC • Washington

On-site
USD 140,000 - 170,000
Cybersecurity Analyst V (Senior)
Cybersecurity Analyst V (Senior)

People, Technology & Processes, LLC • Washington

On-site
USD 120,000 - 170,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Astrion • Washington

On-site
USD 117,000 - 143,000
Cybersecurity Analyst V (Senior)
Cybersecurity Analyst V (Senior)

People Technology And Processes • Washington

On-site
USD 127,000 - 138,000
Cybersecurity Program Lead — RMF/A&A for DoD/Navy
Cybersecurity Program Lead — RMF/A&A for DoD/Navy

International Executive Service Corps • San Diego (CA)

On-site
USD 140,000 - 200,000
Cybersecurity RMF Analyst III
Cybersecurity RMF Analyst III

HRsmart • Louisiana (MO), Norfolk (VA), Tampa (FL)

On-site
USD 90,000 - 140,000