Risk Management Support Lead

Jobtailor

Illinois

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor seeks an experienced cybersecurity professional to manage RMF lifecycle for DoD enterprise systems, align ISSE activities with government priorities, and lead vulnerability management using ACAS and DISA STIG baselines.

The role requires DoD TS/SCI eligibility, DoD IAM Level III, and credentials in CEH/GPEN/NESSUS. Travel to Scott AFB quarterly is expected; 7‑day RMF SLAs apply. A bachelor’s degree and 7+ years IT with 5+ years cybersecurity are expected.

Qualifications

  • Active DoD Top Secret/SCI clearance required at start.
  • DoD IAM Level III baseline qualifications (CISSP/CISM/GSLC) required at start.
  • Valid penetration testing credential (CEH/GPEN/LPT/CEPT).
  • DC3 Cyber 101 course completion required.
  • Bachelor’s degree or equivalent technical training.

Responsibilities

  • Manage on-site contract deliverables and align with combatant command priorities.
  • Lead RMF lifecycle across ~40 enterprise systems; evaluate controls and finalize ATOs.
  • Develop tool requirements and create STIGs from DISA SRGs.
  • Align ISSE lifecycle with NIST SP 800-160 volumes I & II.
  • Oversee weekly ACAS scans, continuous risk dashboards, and DISA STIG baselines.
  • Manage IAVM program, distribute alerts, track compliance, process POA&Ms.
  • Lead SwA code diagnostics using Fortify; tune configs and publish logs.
  • Coordinate SCAR workflows with 7-day SLAs for RMF submissions.
  • Coordinate with JDDE for data sharing and PPSM registrations.
  • Provide CRF deployment oversight; run ETL pipelines with Databricks, Python, SQL, Qlik.

Skills

Active security clearance
CCR I level evaluations
Strong communication
Security risk assessments
CCR I/Vulnerability management

Education

Bachelor’s degree or technical training in CS/Engineering/Info Management

Tools

VULNERATOR
eMASS
ACAS/Nessus
HBSS (ePO/HIPS/AV)
Fortify
Tenable Nessus Auditor
Databricks
Python
SQL
Qlik

Job description

Responsibilities
  • Manage complex on‑site contract deliverables and coordinate directly with the Government functional lead to align team activities with combatant command priorities.
  • Lead the technical execution of the RMF lifecycle across approximately 40 enterprise systems, independently evaluating security controls, tracking categorizations, and finalizing ATO packages.
  • Reconstruct and recommend advanced cybersecurity software tools and assist in the development of tool requirements and product‑specific STIGs derived from applicable DISA SRGs.
  • Provide expert Information Systems Security Engineering (ISSE) lifecycle alignment in strict accordance with NIST SP 800‑160 Volume I and Volume II trust and cyber resiliency models.
  • Supervise the execution of weekly automated network vulnerability scanning (ACAS), continuous risk dashboard monitoring, and verification against DISA STIG/SRG baselines.
  • Oversee the command’s Information Assurance Vulnerability Management (IAVM) program, managing the distribution of security alerts, tracking macro compliance trends, and processing complex POA&Ms.
  • Serve as the lead technical expert for Software Assurance (SwA) code diagnostics, utilizing automated application scanning tools (such as Fortify) to evaluate source code, tune configurations to eliminate false positives, and publish annual summary analysis logs.
  • Manage Security Control Assessor Representative (SCAR) workflows, performing rapid triage of all RMF‑related submissions within strict 7‑business‑day service level thresholds.
  • Coordinate across the Joint Deployment and Distribution Enterprise (JDDE) to facilitate technical data‑sharing, evaluate system reciprocity, and manage DoD Ports, Protocols, and Services Management (PPSM) registries.
  • Provide technical engineering oversight for the deployment of the Cybersecurity Readiness Framework (CRF), executing complex ETL data pipelines and analytics workloads using Databricks, Python, SQL, and Qlik.
Requirements
  • Active Department of Defense Top Secret/SCI (Tier 5 Investigation) required.
  • Travel on‑site to Scott Air Force Base required one week per quarter.
  • Must satisfy DoD 8570.01‑M / DoDM 8140.03 Information Assurance Management (IAM) Level III baseline qualification requirements (e.g., active CISSP, CISM, or GSLC) at the commencement of work.
  • Must hold a validation/penetration testing credential (e.g., CEH, GPEN, LPT, or CEPT) and a Tenable Certified NESSUS Auditor (or ACAS equivalent) certification.
  • REQUIRED Foundational Qualification: Defense Cyber Crime Center (DC3) Cyber 101 course completion.
  • Bachelor’s degree or related technical training in Computer Science, Engineering, Information Management, or a related mission‑area professional discipline required.
  • A minimum of seven (7) years of progressive IT experience combined with at least five (5) years of direct, specialized Cybersecurity experience.
  • Proven expert experience conducting CCRI‑level evaluations and hands‑on proficiency with tools including VULNERATOR, eMASS, ACAS/NESSUS, and HBSS (ePO, HIPS, AV).
  • Deep engineering knowledge of core computing environments across varying Operating Systems (Windows, Unix/Linux), Boundary Defenses (firewalls, routers), and Web/Database services (SQL Server, Oracle, Apache, IIS).
  • Strong conceptual thinking and communication skills, with a documented track record of authoring high‑fidelity Security Risk Assessments, standard operating procedures (SOPs), and technical analysis of alternatives (AoA) whitepapers.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

RMF Lifecycle Lead — DoD Cybersecurity Expert
RMF Lifecycle Lead — DoD Cybersecurity Expert

Jobtailor • Illinois

On-site
USD 120,000 - 180,000
Risk Management Framework Cyber SME
Risk Management Framework Cyber SME

TMC TECHNOLOGIES • Albuquerque (NM)

On-site
USD 90,000 - 130,000
RMF Subject Matter Expert
RMF Subject Matter Expert

Centuria • Lincoln (MA)

On-site
USD 120,000 - 180,000
Advisory Information Security Manager – ISSM
Advisory Information Security Manager – ISSM

Jobtailor • Huntsville (AL)

On-site
USD 110,000 - 170,000
Cybersecurity Engineer
Cybersecurity Engineer

Jobtailor • San Diego (CA)

On-site
USD 120,000 - 190,000
RMF Subject Matter Expert
RMF Subject Matter Expert

Socket.dev • Lincoln (MA)

On-site
USD 120,000 - 170,000
Information Assurance Engineer
Information Assurance Engineer

Agile IT Synergy, LLC • Tampa (FL)

On-site
USD 90,000 - 130,000
Information Assurance / Security Specialist
Information Assurance / Security Specialist

Vinstuen Femmeren jazzværtshus • Bethesda (MD)

On-site
USD 120,000 - 170,000
Cyber Analyst-RMF Specialist
Cyber Analyst-RMF Specialist

Saic • Colorado Springs (CO)

On-site
USD 120,000 - 160,000
Information Assurance / Security Specialist
Information Assurance / Security Specialist

Diverse Systems Group, LLC • Bethesda (MD)

On-site
USD 110,000 - 150,000