NAVSEA Risk Management Frame (RMF) Information Systems Security Engineer (ISSE) Junior-Mid Role

Arcfield

Newport (RI)

On-site

USD 70,000 - 105,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health Insurance
Paid Time Off
Short Term Disability
Long Term Disability
Retirement and Savings
Learning and Development
Wellness programs

Job summary

Arcfield is seeking a Junior-Mid RMF ISSE to support NUWCDIVNPT in A&A and maintain ATOs for systems, apps, networks, and devices. The role emphasizes a disciplined RMF process, security assessments per NIST SP 800-53/53A, and development of Security Plans, POA&Ms, and risk analyses.

Qualifications include 2+ years in cybersecurity, 8570.01M IAM/IAT Level II, U.S. citizenship, and an active Secret clearance; familiarity with ACAS, STIGs, and eMASS is preferred.

Qualifications

  • 2+ years of professional cybersecurity experience with RMF.
  • Experience developing RMF packages including POA&Ms and Security Plans.
  • Ability to work with NIST SP 800-53 & 800-37 RMF guidance.

Responsibilities

  • Support A&A to maintain ATOs for systems, apps, networks, devices.
  • Review Security Plans, test reports, and POA&Ms; perform risk analyses.
  • Provide RMF guidance and training for the team in eMASS.

Skills

RMF expertise
NIST SP knowledge
Documentation & reporting
Stakeholder coordination
Multitasking
Team collaboration
Excellent communication

Education

BS in cybersecurity or related field
MS in related field

Tools

ACAS
STIGViewer
eMASS
STIG OSS Manager

Job description

Responsibilities

Support the NUWCDIVNPT in a Junior-Mid RMF ISSE Role and perform tasks related to Assess and Authorize (A&A) to maintain Authorizations to Operate (ATOs) systems (i.e., applications, networks, devices), and perform the following:

  • Provide a disciplined, structured, and flexible process for managing security and privacy risk that includes information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring.
  • Become familiar with the system/site by reviewing the Assessment and Authorization (A&A) System Security Plan for existing systems; identify any issues with the Security Plan and Procedures; execute the Security Assessment Plan and process Security Test Report; review POA&Ms; develop/perform Risk Assessment analysis.
  • Keep abreast of and provide the team updated information on Navy RMF policies and procedures. Review DoD, DON, NAVSEA CS-related documentation (i.e., RMF Process Guide, Navy SCA Risk Assessment Guide, DoN Standard Operating Procedures, NAVSEA Business Rules).
  • Be comfortable conducting independent security control assessments in accordance with NIST SP 800-53, 800-53A, CNSSI 1253, and the Risk Management Framework (RMF) described in NIST SP 800-37.
  • Clearly articulate requirements and other information in written documentation such as Security Plan, Contingency Plan, Contingency Plan Test, Business Impact Analysis, etc.
  • Provide guidance and training in eMASS to team members.
  • Demonstrate strong organizational and time-management skills: multitasking, working individually and with a team, having a positive attitude, being self-motivated and reliable, being trustworthy, having strong interpersonal and diplomatic skills, and being able to handle stress in a professional manner.
  • Attend stakeholder meetings, capture and track action items, and follow up with stakeholders to ensure timely completion.
Qualifications
  • BS 2-4, MS 0-2
  • Minimum 2+ years of professional cybersecurity experience and Risk Management Framework
  • Demonstrated expert-level experience with Risk Management Framework
  • Experience in RMF policy development, process improvement, and strategy implementation
  • Demonstrated efficiency and expert-level experience in RMF package development, including POA&Ms (mitigation statements), Security Plans, Risk Assessments, architecture diagrams, asset inventories, and system/site policies, procedures, and processes
  • Must have an 8570.01M IAM/IAT Level II Certificate (Security + at a minimum CAP or CASP /CISSP preferred)
  • Knowledge National Institute of Standards and Training Special Publications (NIST SPs) knowledge
  • Must be able to manage multiple projects at a time
  • Assessment and Authorization (A&A formerly C&A, i.e. RMF and DIACAP respectively)
  • Experience with ACAS, STIG OSS Manager, STIGViewer, eMASS
  • Knowledge and experience with practices and procedures for CMMI Software Development Level 3 or greater is a plus
  • Knowledge in Continuous Monitoring
  • Excellent customer service and organization skills
  • Excellent oral and written communication skills
  • Demonstrated expert-level experience with DISA STIGs and SRGs
  • Position requires U.S. Citizenship
  • Possess and Maintain an active Secret security clearance
Equal Pay Act

This is the projected compensation range for this position. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (For Remote Opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, Arcfield invests in its employees beyond just compensation. Arcfield ’s benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, Short Term and Long-Term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections. Min: $70,123.69 Max: $104,662.23

EEO Statement

We are an equal opportunity employer and federal government contractor. We do not discriminate against any employee or applicant for employment as protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

NAVSEA Risk Management Frame (RMF) Information Systems Security Engineer (ISSE) Mid-Senior Role
NAVSEA Risk Management Frame (RMF) Information Systems Security Engineer (ISSE) Mid-Senior Role

Arcfield • Newport (RI)

On-site
USD 87,000 - 152,000
Health Insurance
Paid Time Off
Holiday Pay
+5
NAVSEA Risk Management Frame (RMF) Information Systems Security Engineer (ISSE) Mid-Senior Role
NAVSEA Risk Management Frame (RMF) Information Systems Security Engineer (ISSE) Mid-Senior Role

Arcfield • Newport (RI)

On-site
USD 87,000 - 152,000
NAVSEA Risk Management Frame (RMF) Information Systems Security Engineer (ISSE) Mid-Senior Role
NAVSEA Risk Management Frame (RMF) Information Systems Security Engineer (ISSE) Mid-Senior Role

Arcfield • Middletown (RI)

On-site
USD 87,000 - 152,000
Health Insurance
Paid Time Off
401(k) Retirement
+1
NAVSEA Risk Management Frame (RMF) Information Systems Security Engineer (ISSE) Junior-Mid Role
NAVSEA Risk Management Frame (RMF) Information Systems Security Engineer (ISSE) Junior-Mid Role

Arcfield • Middletown (RI)

On-site
USD 70,000 - 105,000
Health Insurance
Life Insurance
Paid Time Off
+6
Information Systems Security Engineer (ISSE) – RMF
Information Systems Security Engineer (ISSE) – RMF

New Directions Technologies, Inc • Port Hueneme (CA)

On-site
USD 75,000 - 96,000
Information Systems Security Engineer (ISSE) / Systems Security Analyst - Federal Client
Information Systems Security Engineer (ISSE) / Systems Security Analyst - Federal Client

Vinsys Information Technology Inc • Santa Rita (GU)

On-site
USD 110,000 - 160,000
Senior Principal Cyber Information Systems Security Engineer
Senior Principal Cyber Information Systems Security Engineer

Saic • Norfolk (VA)

On-site
USD 160,000 - 200,000
Information Systems Security Engineer (RMF)
Information Systems Security Engineer (RMF)

Saalex Corporation • Newport (RI)

On-site
USD 60,000 - 70,000
Health care
401k/IRA
Life Insurance
+5
Senior Principal Cyber Information Systems Security Engineer
Senior Principal Cyber Information Systems Security Engineer

CareerArc • Charleston (SC)

On-site
USD 140,000 - 190,000
RMF Cyber Security Analyst - 306210
RMF Cyber Security Analyst - 306210

DNI (Delaware Nation Industries) • Virginia Beach (VA)

On-site
USD 110,000 - 115,000
Covers 100% of employee premiums (Medi
Matching 401K
Short- and Long-Term Disability
+3