Risk Management Framework (RMF) Lead

Abacus Technology Corporation

Bedford (MA)

On-site

USD 149,000 - 167,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health and Dental Insurance
401(k) with Matching
Life Insurance
Disability Insurance (Short/Long-Term)
Paid Time Off
Paid Holidays
Professional Training, Certification &

Job summary

Abacus Technology Corporation seeks an RMF Lead to guide DoD RMF activities for Wing Cyberspace Office at Hanscom AFB. The role focuses on RMF lifecycle execution, artifact management in eMASS, and ensuring compliance with DoD/NIST policies.

You will mentor cybersecurity staff, support security inspections, and coordinate with ISSMs, system owners, and network teams to sustain secure operations.

Qualifications

  • 10+ years of cybersecurity experience with a strong emphasis on RMF in DoD or Federal environments.
  • Experience developing and managing RMF artifacts in eMASS and supporting ATO/ATC/IATT processes.
  • Hands-on experience with security control assessments, vulnerability management, and POA&Ms.

Responsibilities

  • Lead RMF lifecycle activities for all base systems and enclaves.
  • Develop, maintain, and validate RMF artifacts in eMASS for DoD/Air Force requirements.
  • Provide guidance to ISSMs, ISSOs, and system owners on ATO packages and continuous monitoring.

Skills

RMF expertise
leadership
communication
security assessments
mentoring

Education

Bachelor’s degree in a related field
Security+ certification
CISSP preferred

Job description

Overview

Abacus Technology is seeking a Risk Management Framework (RMF) Lead to support the Wing Cyberspace Office (WCSO) in managing and executing DoD Risk Management Framework processes at Hanscom AFB. This is a full-time position.

Responsibilities
  • Serve as the lead RMF Subject Matter Expert supporting the Wing Cyberspace Office (WCSO) for all systems and enclaves within the base enterprise.
  • Lead the management, implementation, and execution of the Risk Management Framework (RMF) lifecycle (Categorize, Select, Implement, Assess, Authorize, and Monitor) for supported systems.
  • Develop, maintain, and validate RMF artifacts within Enterprise Mission Assurance Support Service (eMASS) to ensure completeness, accuracy, and compliance with DoD and Air Force requirements.
  • Provide expert guidance to ISSMs, ISSOs, and system owners on ATO packages, reauthorization efforts, and continuous monitoring strategies.
  • Ensure continuous compliance with DoD, Air Force, NSA, and NIST cybersecurity policies and directives, including NIST SP 800-53 and DoDI 8510.01.
  • Conduct risk assessments and security control evaluations, recommending mitigation strategies to reduce risk to acceptable levels.
  • Review and validate Security Technical Implementation Guides (STIGs), vulnerability alerts, and cybersecurity directives for implementation across supported systems.
  • Support Authorization to Operate (ATO), Authority to Connect (ATC), and Interim Authorization (IATT) processes as required.
  • Develop and manage Plans of Action & Milestones (POA&Ms) and track remediation efforts to closure.
  • Provide direct support during cybersecurity inspections and audits (e.g., CCRI, IG, SAV), including preparation, execution, and remediation.
  • Advise on system architecture, boundary definitions, and control inheritance to improve RMF efficiency and cybersecurity posture.
  • Collaborate with network, system, and cybersecurity teams to ensure secure integration and sustainment of systems.
  • Analyze and report cybersecurity posture metrics and trends, providing recommendations for continuous improvement.
  • Mentor and provide RMF training and knowledge transfer to cybersecurity staff and stakeholders across the Wing.
Qualifications

10+ years experience in cyber security, with a strong emphasis on Risk Management Framework (RMF) within the DoD or Federal environment. Bachelor’s degree in a related field. Additional years of experience may be substituted for degree requirements. Must be Security+ certified. CISSP certification preferred. Extensive experience with DoD RMF processes, ATO lifecycle management, and continuous monitoring. Demonstrated expertise in eMASS and RMF package development and management. Strong knowledge of Air Force, DoD, and Federal cyber security directives, policies, and instructions. Hands-on experience conducting security control assessments, vulnerability management, and POA&M tracking. Experience supporting cyber security inspections (e.g., CCRI, IG inspections, SAVs). Able to interpret and implement STIGs, security guidance, and vulnerability remediation requirements. Strong ability to work independently and collaboratively, providing technical leadership across multiple stakeholders. Excellent communication skills, with the ability to translate complex cyber security concepts into actionable guidance. Must be a US citizen and hold a current Secret clearance.

The projected compensation range for this position is $149,000-$167,100. There are multiple factors that can impact a final salary, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (if remote or different from the stated location for this position), education and certifications as well as Federal Government Contract Labor categories. In addition, Abacus Technology offers a benefits package that includes: Health and Dental Insurance; 401(k) and Matching; Life Insurance; Short- and Long-Term Disability; Paid Time Off; Paid Holidays; and Professional Membership, Technical Training, Certification, and Education Assistance.

Applicants selected will be subject to a U.S. government security investigation and must meet eligibility requirements for access to classified information.

EOE/M/F/Vet/Disabled

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Risk Management Framework (RMF) Lead
Risk Management Framework (RMF) Lead

Abacus Technology • Massachusetts

On-site
USD 149,000 - 167,000
Health and Dental Insurance
401(k) and Matching
Life Insurance
+4
RMF Subject Matter Expert
RMF Subject Matter Expert

Socket.dev • Lincoln (MA)

On-site
USD 120,000 - 170,000
Risk Management Framework Lead – DoD Cyber Compliance
Risk Management Framework Lead – DoD Cyber Compliance

Abacus Technology • Massachusetts

On-site
USD 149,000 - 167,000
Health and Dental Insurance
401(k) and Matching
Life Insurance
+4
RMF Subject Matter Expert
RMF Subject Matter Expert

Centuria • Lincoln (MA)

On-site
USD 120,000 - 180,000
RMF Subject Matter Expert
RMF Subject Matter Expert

Centuria Corporation • Northern (KY)

Hybrid
USD 120,000 - 160,000
System Cyber Security Engineer
System Cyber Security Engineer

Abacus Technology Corporation • Massachusetts

On-site
USD 151,000 - 165,000
Health and Dental Insurance
401(k) with Matching
Life Insurance
+4
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Abacus Technology Corporation • Massachusetts

On-site
USD 176,000 - 195,000
Senior RMF Lead: DoD Cyber Risk & Compliance
Senior RMF Lead: DoD Cyber Risk & Compliance

Abacus Technology Corporation • Bedford (MA)

On-site
USD 149,000 - 167,000
Health and Dental Insurance
401(k) with Matching
Life Insurance
+4
RMF Cyber Risk Lead for DoD | TS Preferred
RMF Cyber Risk Lead for DoD | TS Preferred

Centuria • Lincoln (MA)

On-site
USD 120,000 - 180,000
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

P3S CORPORATION • Dayton (OH)

On-site
USD 95,000 - 120,000