Lead RMF Cybersecurity Engineer — Remote Ready

Booz Allen Hamilton

Maryland

On-site

USD 113,000 - 257,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health benefits
Paid leave
Tuition assistance
Professional development
Work-life programs

Job summary

Booz Allen Hamilton is seeking an experienced RMF governance professional to own DoD RMF activities and maintain authorization artifacts, eMASS records, and remediation evidence. You will analyze STIG/SCAP/ACAS findings and ensure accurate reflection of the system’s cybersecurity posture.

Responsibilities include managing RMF lifecycles, creating SOPs, coordinating POA&Ms, and collaborating with ISSMs, engineers, and system owners to validate evidence and close actions.

Qualifications

  • 8+ years of experience with DoD RMF or cybersecurity.
  • Experience using eMASS to address security controls, create POA&M, and upload artifacts such as STIG checklists or ACAS scans
  • Experience with the administration of Windows, Linux, AWS Cloud and containerization systems and software configuration
  • Knowledge of NIST SP 800-37, NIST SP 800-53 Rev. 5, DoDI 8510.01, POA&M management, and DoD authorization practices
  • Knowledge of TCP, IP, ports, protocols, firewalls, segmentation, PKI, encryption, IAM, and DoD network security concepts
  • Ability to validate STIG and vulnerability findings, false positives, risk acceptances, mitigations, remediation evidence, and closure packages using ACAS, Nessus scans, STIGs, SCAP, SCC, vulnerability results, configuration reviews, system queries, and manual procedures
  • Ability to analyze system boundaries, data flows, external interfaces, interconnections, inherited controls, and common-control dependencies
  • DoD 8570 or 8140-aligned Certification such as Security+, CISSP, or CASP+ Certification

Responsibilities

  • Manage the RMF lifecycle activities and authorization-package maintenance.
  • Maintain SSP, ConMon Plan, IRP, CMP, control narratives, diagrams, inventories, and supporting evidence.
  • Perform eMASS package administration and quality assurance.
  • Coordinate monthly POA&M updates, evidence validation, milestone tracking, and closure.
  • Analyze NIST SP 800-53 Rev.5 controls and translate requirements into system-specific implementation statements.
  • Develop Security Impact Assessments for proposed system and configuration changes.
  • Develop or coordinate ISAs, MOAs, and MOUs as required for system interconnections.
  • Support T-Req and data-connection reviews and coordinate with ISSM, engineers, and system owners, reviewing tickets for completeness.
  • Prepare packages for continuous monitoring and authorization reviews with stakeholders.
  • Analyze source, destination, ports, protocols, services, data sensitivity, encryption, authentication, boundary protection, and mission need.
  • Identify required security artifacts, approvals, firewall, network actions, and interconnection documentation.
  • Coordinate with ISSM, network and security engineering, system owners, and requestors.
  • Maintain status, metrics, aging reports, and escalation paths.
  • Identify high-risk or nonstandard connection requests for deeper assessment.

Skills

DoD RMF
Cybersecurity
eMASS
POA&M
NIST SP 800-53 Rev.5
DoD 8570 / 8140
Security+
CISSP
CASP+

Education

Bachelor’s degree in Engineering or Cyber

Tools

eMASS
ACAS
Nessus
STIG
SCAP
SCC
POA&M management

Job description

Booz Allen Hamilton is seeking an experienced RMF governance professional to own DoD RMF activities and maintain authorization artifacts, eMASS records, and remediation evidence. You will analyze STIG/SCAP/ACAS findings and ensure accurate reflection of the system’s cybersecurity posture.

Responsibilities include managing RMF lifecycles, creating SOPs, coordinating POA&Ms, and collaborating with ISSMs, engineers, and system owners to validate evidence and close actions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DoD RMF Cybersecurity Engineer
Senior DoD RMF Cybersecurity Engineer

Booz Allen Hamilton • Aberdeen (MD), Northern (KY)

Hybrid
USD 99,000 - 225,000
Senior Cybersecurity Mission Architect (DoD RMF)
Senior Cybersecurity Mission Architect (DoD RMF)

Booz Allen Hamilton • El Segundo (CA)

On-site
USD 99,000 - 225,000
RMF Cybersecurity Lead — Policy & Compliance
RMF Cybersecurity Lead — Policy & Compliance

Phase2 Technology • Arlington (VA)

On-site
USD 62,000 - 141,000
Remote RMF Cybersecurity Engineer (NIST/ACAS)
Remote RMF Cybersecurity Engineer (NIST/ACAS)

Phase2 Technology • Fort Meade (MD)

On-site
USD 61,000 - 141,000
Hybrid RMF & Cybersecurity Compliance Lead
Hybrid RMF & Cybersecurity Compliance Lead

Booz Allen Hamilton • Newport (RI)

Hybrid
USD 62,000 - 141,000
RMF Cybersecurity Lead: Policy & Compliance Expert
RMF Cybersecurity Lead: Policy & Compliance Expert

Booz Allen Hamilton • Arlington (VA), Northern (KY)

Hybrid
USD 62,000 - 141,000
Health benefits
Paid leave
Professional development
Senior RMF Information Security Manager
Senior RMF Information Security Manager

Phase2 Technology • Honolulu (HI)

On-site
USD 86,000 - 198,000
RMF Cybersecurity Engineer — NIST & ACAS Expert
RMF Cybersecurity Engineer — NIST & ACAS Expert

Booz Allen Hamilton • Fort Meade (MD), Northern (KY)

Hybrid
USD 99,000 - 225,000
Cybersecurity RMF & Risk Assessment Expert
Cybersecurity RMF & Risk Assessment Expert

Phase2 Technology • Mississippi

On-site
USD 99,000 - 225,000
Remote Information Security Risk Lead | DoD RMF Expert
Remote Information Security Risk Lead | DoD RMF Expert

Booz Allen Hamilton • Hampton (VA)

Hybrid
USD 113,000 - 257,000