Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Pueo Business Solutions LLC in the United States is seeking a highly experienced RMF Security Control Assessor (Expert) to conduct comprehensive assessments of security controls and produce authoritative documentation. The role requires strong RMF, NIST, and SA&A knowledge and involves advising key stakeholders on impact levels.
The ideal candidate will manage RMF artifacts, coordinate with program offices, and stay ahead of evolving IC policies to refine inspection protocols and security
Description
Pueo is known for bringing the best talent and unique tools to every opportunity. Pueo's Parliament (aka workforce) is composed of professionals who are seeking the opportunity to work in a business organization that thrives on career development and independence. In support of mission and professional growth, our Parliament has supported the development of multiple patents, proprietary tools, and applications as well as trademarked processes.
Our organization emphasizes career development across multiple career environments (at the members own pace) and ensures those who contribute broadly are properly rewarded. Pueo has four career environments where every member of the parliament can participate. Each environment has opportunities available for all levels. Opportunities are framed by an employee's desires and capabilities, and we ensure challenges, growth, and unique experiences are available for employees at all levels.
Our Career Environments (Program, Functional, Service, and Leadership) provide numerous opportunities for employees to invest in their personal growth and those things that offer fulfillment. We invest in helping our members create and execute their career development plans. Our Pods (small teams of 5 or less) are comprised of personnel with similar skillsets to ensure mentorship, understanding, and peer support.
The RMF Security Control Assessor (Expert) conducts a comprehensive assessment of the security controls employed within or inherited by an Information System (IS) to determine their overall effectiveness, and submits the Body of Evidence (BoE), composed of the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and draft Authorization to Operate (ATO) Letter, to the Authorizing Official (AO) or Delegated Authorizing Official (DAO) for review and authorization decision.
The SCA also advises key stakeholders, such as the Program Office, Data Owner and Authorizing Official/Delegated Authorizing Official concerning the security categorization and impact levels for confidentiality, integrity, and availability for the information on a system.
Support the Assessment and Authorization (A&A) Risk Management Framework process for all client managed systems, networks, and enclaves (all security domains); ensure validity and accuracy review of all associated documentation; support remote sites when required.
Advise ISSOs on categorization and selection of security controls (RMF steps 1 and 2) and conduct Technical Exchange Meetings (TEMs) where they collaborate with other security professionals.
Communicate finding impacts through presentations and written deliverables.
Stay current with the latest trends and technologies related to IC policy to continuously refine security inspection protocols.
Expert knowledge and hands-on experience with RMF, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management.
Expert with documenting and/or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines.
Basic knowledge of Zero Trust Framework.
Solid interpersonal and communication skills to interact with various stakeholders and team members effectively.
Expert hands-on experience interrupting compliance and vulnerability scanning tool reports from (XACTA, STIGS, ACAS, PRISMA, Splunk, Trellix (HBSS), and/or other vulnerability scanners)
Some experience leading security projects and initiatives.
Team-player with collaboration qualities and experience working in mixed technical teams.