RMF / Cybersecurity Compliance Specialist (Pipeline)

Rippling, Inc.

United States

Remote

USD 120,000 - 170,000

Full time

29 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Lucayan Technology Solutions LLC is seeking an RMF / Cybersecurity Compliance Specialist to support the USACE WWBI program.

You will own cybersecurity compliance, RMF documentation, continuous monitoring, vulnerability management, and authorization artifacts, working closely with software developers, DevSecOps personnel, and Government stakeholders to ensure WWBI complies with DoD, Army, USACE, and CWBI requirements.

Qualifications

  • Experience supporting RMF, including developing and maintaining RMF authorization packages and cybersecurity documentation.
  • Experience using eMASS for RMF artifacts, evidence, and mapping.
  • Familiarity with DoD, Army, USACE cybersecurity requirements and processes.

Responsibilities

  • Develop, update, and maintain RMF authorization documentation (SSP, COOP, IRP, system design docs).
  • Manage security controls and documentation for the WWBI system, including PII considerations.
  • Maintain WWBI authorization boundary documentation, hardware/software/ports/data flows.
  • Coordinate RMF documentation for CWBI Cloud migration and boundary changes.
  • Maintain eMASS records, attach evidence, and manage POA&Ms.

Skills

RMF compliance
eMASS usage
ACAS/SCAP tools
Vulnerability management
Technical writing
Stakeholder communication

Education

Tools

eMASS platform
STIG Viewer
DISA STIGs
ACAS
SCAP

Job description

RMF / Cybersecurity Compliance Specialist (Pipeline)
About Lucayan Technology Solutions LLC

At Lucayan Technology Solutions LLC, we deliver secure, innovative solutions in support of national defense and intelligence missions. As a trusted government contracting partner, we provide top-tier intelligence and technology services that safeguard our nation. Our team is mission-driven, and we are committed to building careers that matter.

Location: This is a US-based remote position.

Employment Type: Full-Time

Security Clearance: No security clearance required. Minimum active Tier 1 (or higher) federal background investigation required prior to start; ability to obtain a CAC if required by duties.

Join Our Pipeline for Future Opportunities!

This posting is intended to establish a pool of qualified candidates for future openings supporting ongoing operations. Positions may become available based on staffing needs, operational requirements, or workforce changes. Qualified applicants may be contacted as opportunities arise.

Job Summary

Lucayan Technology Solutions LLC is seeking an RMF / Cybersecurity Compliance Specialist to support the U.S. Army Corps of Engineers (USACE) Walla Walla Business Intelligence (WWBI) program. This role owns cybersecurity compliance, Risk Management Framework (RMF) documentation, continuous monitoring, vulnerability management, and authorization artifacts, working closely with software developers, DevSecOps personnel, technical leadership, and Government stakeholders to ensure WWBI continuously complies with applicable Department of Defense (DoD), U.S. Army, USACE, and Civil Works Business Intelligence (CWBI) cybersecurity requirements. This position also supports maintenance of the WWBI authorization package and the program's planned migration into the CWBI Cloud and eventual integration into the CWBI security boundary.

Key Responsibilities
  • Develop, update, and maintain WWBI Risk Management Framework authorization documentation, including the System Security Plan (SSP), Continuity of Operations Plan (COOP), Incident Response Plan (IRP), System Design Documents, and related authorization artifacts.
  • Manage and document program-specific security controls applicable to the WWBI system, and support security requirements associated with Personally Identifiable Information (PII).
  • Maintain documentation defining the WWBI authorization boundary, including applicable hardware, software, ports, protocols, interfaces, and data flows.
  • Coordinate cybersecurity documentation and compliance activities associated with WWBI's migration into the CWBI Cloud and eventual incorporation into the CWBI authorization boundary.
  • Maintain WWBI compliance records within the Enterprise Mission Assurance Support Service (eMASS), including uploading, mapping, organizing, and maintaining required RMF documentation, security-control evidence, implementation statements, and supporting artifacts.
  • Support execution of the WWBI continuous-monitoring program, including coordinating and/or performing required ACAS and SCAP security scans, and maintaining a compliance score of at least 90% for applicable SCAP scans.
  • Import and maintain security-scan results within DISA STIG Viewer and eMASS; analyze identified vulnerabilities and coordinate remediation activities with software developers and Government technical personnel.
  • Track Critical and High findings for immediate remediation, Moderate findings for remediation within 60 days, and Low findings for remediation within 120 days; document approved exceptions and outstanding findings within the Plan of Actions and Milestones (POA&M).
  • Develop, maintain, and submit the quarterly POA&M report detailing open, remediated, and outstanding security findings, and support quarterly updates to the RMF documentation package.
  • Provide ACAS/SCAP scan results and associated STIG Viewer files following required scans, and maintain current system security, network topology, logical, and data-flow documentation in coordination with the development team.
  • Complete and maintain security-control checklists required by the USACE CWBI Cloud environment, and monitor changes to CWBI cybersecurity requirements to coordinate implementation of new or modified requirements.
  • Support annual Federal Information Security Management Act (FISMA) reporting requirements and associated forms, checklists, and documentation.
  • Support compliance with applicable DoD Security Technical Implementation Guides (STIGs), Army cybersecurity requirements, and USACE policies, coordinating with developers and DevSecOps personnel to ensure applications and infrastructure remain compliant through modernization and cloud-migration activities.
Required Qualifications
  • Demonstrated experience supporting the DoD Risk Management Framework (RMF), including developing and maintaining RMF authorization packages and cybersecurity documentation.
  • Experience using Enterprise Mission Assurance Support Service (eMASS).
  • Knowledge of DoD, U.S. Army, and/or USACE cybersecurity requirements and processes.
  • Experience with vulnerability management, security controls, POA&Ms, and continuous monitoring.
  • Experience with ACAS, SCAP, DISA STIGs, and STIG Viewer.
  • Ability to interpret technical vulnerability findings and coordinate remediation with software-development and infrastructure teams.
  • Strong technical writing and documentation skills, with strong organizational skills and the ability to manage multiple recurring compliance requirements and deadlines.
  • Ability to communicate effectively with technical personnel, program leadership, and Government stakeholders.
  • Active federal background investigation at the Tier 1 level or higher prior to beginning contract performance.
  • Ability to obtain and maintain CompTIA Security+ or a DoD-approved equivalent within six months of the contract start date, as applicable to the assigned DoD 8140 work role.
Preferred Qualifications
  • Previous experience supporting USACE systems or applications.
  • Experience supporting DoD systems through ATO authorization and continuous monitoring.
  • Experience with AWS GovCloud or other DoD-authorized cloud environments.
  • Familiarity with DevSecOps, GitHub, secure software-development pipelines, and application modernization.
  • Experience supporting cloud migration of systems operating under an existing RMF authorization.
  • Experience with FISMA reporting.
Certifications
  • Active Tier 1 (or higher) background investigation prior to start.
  • CompTIA Security+ or a DoD 8140-approved equivalent required within six (6) months of contract start.
  • CISSP or another advanced DoD-recognized cybersecurity certification desired.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

RMF / Cybersecurity Compliance Specialist
RMF / Cybersecurity Compliance Specialist

Lucayan Technology Solutions LLC • United States

Remote
USD 90,000 - 130,000
Cybersecurity RMF Analyst III
Cybersecurity RMF Analyst III

HRsmart • Louisiana (MO), Norfolk (VA), Tampa (FL)

On-site
USD 90,000 - 140,000
RMF Cybersecurity Compliance Specialist (Remote - DoD)
RMF Cybersecurity Compliance Specialist (Remote - DoD)

Rippling, Inc. • United States

Remote
USD 120,000 - 170,000
RMF Cybersecurity Analyst
RMF Cybersecurity Analyst

Cybersecurity Jobs • Rockaway Township (NJ)

On-site
USD 87,000 - 182,000
Remote RMF & Cybersecurity Compliance Specialist
Remote RMF & Cybersecurity Compliance Specialist

Lucayan Technology Solutions LLC • United States

Remote
USD 90,000 - 130,000
RMF Cybersecurity Analyst II - 505767
RMF Cybersecurity Analyst II - 505767

Delaware Nation Industries • Bath Township (OH)

On-site
USD 70,000 - 100,000
Benefits coverage
401K match
Disability insurance
+3
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

P3S CORPORATION • Dayton (OH)

On-site
USD 95,000 - 120,000
Information Security Analyst (Pipeline)
Information Security Analyst (Pipeline)

Lucayan Technology Solutions LLC • United States

On-site
USD 90,000 - 130,000
Information Systems Security Engineer (RMF)
Information Systems Security Engineer (RMF)

Saalex Corporation in • Newport (RI)

On-site
USD 60,000 - 70,000
Health insurance
Retirement plan
Paid time off
+3
RMF Cybersecurity Analyst II - 505767
RMF Cybersecurity Analyst II - 505767

DNI (Delaware Nation Industries) • Patterson Township (OH)

On-site
USD 90,000 - 120,000
Matching 401K
Parking and Transit Benefits
Professional Development/Education Re−