RMF Security Control Assessor (Expert)

Pueo Business Solutions LLC

McLean (VA)

On-site

USD 140,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Pueo Business Solutions LLC in the United States is seeking a highly experienced RMF Security Control Assessor (Expert) to conduct comprehensive assessments of security controls and produce authoritative documentation. The role requires strong RMF, NIST, and SA&A knowledge and involves advising key stakeholders on impact levels.

The ideal candidate will manage RMF artifacts, coordinate with program offices, and stay ahead of evolving IC policies to refine inspection protocols and security

Qualifications

  • Security professional with RMF and NIST 800-series knowledge.
  • Experience documenting SSP, SAR, SAP, and other RMF artifacts.
  • Top-Secret clearance with SCI eligibility and CI Poly.
  • Bachelor's degree or 16+ years of combined experience.
  • Certifications: CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP.

Responsibilities

  • Conduct comprehensive RMF assessment of information systems and prepare BoE, SSP, SAR, POA&M, and ATO Letter.
  • Advise stakeholders on security categorization and impact levels.
  • Support A&A RMF process for client systems and ensure documentation validity.
  • Lead TEMs with other security professionals and present findings.
  • Stay current with IC policy trends to refine inspection protocols.
  • Interact with program offices and data owners for security control decisions.

Skills

RMF expertise
NIST 800-series guidance
SA&A processes
Continuous Monitoring
POA&M policies
Vulnerability scanning tools
Stakeholder communication
Leadership
Interpersonal skills

Education

Bachelor's degree in related field
16+ years total experience

Tools

XACTA
STIGS
ACAS
PRISMA
Splunk
Trellix HBSS

Job description

Description

Pueo is known for bringing the best talent and unique tools to every opportunity. Pueo's Parliament (aka workforce) is composed of professionals who are seeking the opportunity to work in a business organization that thrives on career development and independence. In support of mission and professional growth, our Parliament has supported the development of multiple patents, proprietary tools, and applications as well as trademarked processes.

Our organization emphasizes career development across multiple career environments (at the members own pace) and ensures those who contribute broadly are properly rewarded. Pueo has four career environments where every member of the parliament can participate. Each environment has opportunities available for all levels. Opportunities are framed by an employee's desires and capabilities, and we ensure challenges, growth, and unique experiences are available for employees at all levels.

Our Career Environments (Program, Functional, Service, and Leadership) provide numerous opportunities for employees to invest in their personal growth and those things that offer fulfillment. We invest in helping our members create and execute their career development plans. Our Pods (small teams of 5 or less) are comprised of personnel with similar skillsets to ensure mentorship, understanding, and peer support.

Essential:

The RMF Security Control Assessor (Expert) conducts a comprehensive assessment of the security controls employed within or inherited by an Information System (IS) to determine their overall effectiveness, and submits the Body of Evidence (BoE), composed of the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and draft Authorization to Operate (ATO) Letter, to the Authorizing Official (AO) or Delegated Authorizing Official (DAO) for review and authorization decision.

The SCA also advises key stakeholders, such as the Program Office, Data Owner and Authorizing Official/Delegated Authorizing Official concerning the security categorization and impact levels for confidentiality, integrity, and availability for the information on a system.

Other:

Support the Assessment and Authorization (A&A) Risk Management Framework process for all client managed systems, networks, and enclaves (all security domains); ensure validity and accuracy review of all associated documentation; support remote sites when required.

Advise ISSOs on categorization and selection of security controls (RMF steps 1 and 2) and conduct Technical Exchange Meetings (TEMs) where they collaborate with other security professionals.

Communicate finding impacts through presentations and written deliverables.

Stay current with the latest trends and technologies related to IC policy to continuously refine security inspection protocols.

Knowledge:

Expert knowledge and hands-on experience with RMF, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management.

Expert with documenting and/or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines.

Basic knowledge of Zero Trust Framework.

Skills:

Solid interpersonal and communication skills to interact with various stakeholders and team members effectively.

Expert hands-on experience interrupting compliance and vulnerability scanning tool reports from (XACTA, STIGS, ACAS, PRISMA, Splunk, Trellix (HBSS), and/or other vulnerability scanners)

Abilities:

Some experience leading security projects and initiatives.

Team-player with collaboration qualities and experience working in mixed technical teams.

Requirements
Required Qualifications:
Certifications:
  • CASP+ CE
  • CCNP Security
  • CISA
  • CISSP (or Associate)
  • GCED
  • GCIH
  • CCSP
Education:
  • Possess a Bachelors ’s degree in related field, or an additional 4 years of relevant experience/equivalent.
Other:
  • 12 Years of experience, Bachelor’s degree may be substituted in lieu of a college degree with 4 years of additional experience/equivalent for a total of 16+ years.
Clearance:
  • Hold a Top-Secret Security Clearance with SCI eligibility.
  • Ability to Pass CI Poly.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Control Assessor
Security Control Assessor

Pueo Business Solutions LLC • Virginia (MN)

On-site
USD 120,000 - 190,000
Security Control Assessor
Security Control Assessor

Omniscius Consulting • Arlington (VA)

On-site
USD 120,000 - 180,000
Security Control Assessor
Security Control Assessor

RMantra Solutions • Virginia (MN)

On-site
USD 100,000 - 130,000
Senior Security Controls Assessor (TS/SCI #26-143)
Senior Security Controls Assessor (TS/SCI #26-143)

Strategic Analysis, Inc. • Arlington (VA)

On-site
USD 120,000 - 180,000
Security Control Assessor
Security Control Assessor

Caliber Systems Inc. • Denver (CO), Northern (KY)

On-site
USD 94,000 - 127,000
RMF Project Manager
RMF Project Manager

Pueo Business Solutions LLC • McLean (VA)

On-site
USD 120,000 - 160,000
Senior RMF Security Control Assessor | TS/SCI Eligible
Senior RMF Security Control Assessor | TS/SCI Eligible

Pueo Business Solutions LLC • McLean (VA)

On-site
USD 140,000 - 210,000
Information Systems Security Manager
Information Systems Security Manager

Pueo Business Solutions LLC • McLean (VA)

On-site
USD 120,000 - 170,000
Senior IT Program Manager
Senior IT Program Manager

Pueo Business Solutions LLC • McLean (VA)

On-site
USD 140,000 - 180,000
Security Control Assessor (SCA)
Security Control Assessor (SCA)

Integrity Solutions, Engineering, and Analytics Corporation • Virginia (MN)

On-site
USD 110,000 - 170,000