RMF Security Lead - Real-Time DevSecOps & Compliance

Parsons

Baltimore (MD)

On-site

USD 158,000 - 284,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Parsons is seeking an Information Systems Security Manager in the United States to lead a shift toward a dynamic, real-time RMF-based posture. You will govern secure DevSecOps platforms, align automated risk thresholds, and coordinate with engineers and compliance to ensure continuous authorization.

The role requires extensive RMF, TS/SCI w/Poly, and cloud security expertise across AWS and Azure, with DoD IAM/IAT III and CISM/CISSP/SecurityX credentials.

Qualifications

  • Minimum 15 years relevant experience with Masters in CS, Cybersecurity, Information Assurance, Information Security System Engineering, or related discipline from an accredited college or University.
  • Active DoD IAM and/or IAT Level III, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or SecurityX.
  • Mastery of the Risk Management Framework (RMF) and associated federal cybersecurity standards, including NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
  • Demonstrated understanding and experience with Enterprise-level Cloud Architecture & Security principles, including control inheritance and shared responsibility models across AWS and Azure.
  • DevSecOps practices, automated pipeline security (SAST, DAST, SCA), and CI/CD tools.
  • Experience as SETA contractor.
  • Demonstrated experience providing technical leadership on assignments.
  • Active TS SCI w/Polygraph required

Responsibilities

  • Govern a secure, pre-accredited DevSecOps platform designed for downstream applications to inherit security controls seamlessly.
  • Define, implement, and maintain automated risk thresholds, security baselines, and compliance rules integrated into CI/CD pipelines
  • Oversee real-time configuration tracking, live vulnerability assessments, and threat analytics to ensure ongoing compliance
  • Act as the interface translating automated pipeline data, SBOMs, and tool generated security metrics into actionable risk acceptance frameworks to the Task Lead.
  • Guide and orchestrate the POA&M process, transitioning it from a manual tracking spreadsheet to an automated, tool-driven lifecycle RMF
  • Set formal governance criteria outlining exactly what level of security vulnerabilities will automatically break a software build or block a production deployment
  • Validate that Terraform scripts, Helm charts, and cloud-native templates used to spin up environments are programmatically hardened against DISA STIGs and NIST baselines
  • Enforce rigorous software supply chain security standards, including automated container scanning, open-source dependency tracking, signature validation, and compliance with SLSA frameworks
  • Govern the Least Privilege Access model across the entire development community, strictly partitioning and isolated tenant developer environments from live, production-level pipelines
  • Serve as a collaborative bridge between system administrators, software engineers, cloud architects, and compliance officers to shift security left into the early design phases
  • Establish goals and plans that meet project objectives.

Skills

15+ years experience
RMF knowledge
DoD IAM/IAT III
CISM CISSP SecurityX
AWS & Azure security
DevSecOps CI/CD
SETA contractor
Leadership experience
TS SCI w/Poly

Education

Masters in CS/Cybersecurity

Tools

Terraform
Helm
CI/CD tooling

Job description

Parsons is seeking an Information Systems Security Manager in the United States to lead a shift toward a dynamic, real-time RMF-based posture. You will govern secure DevSecOps platforms, align automated risk thresholds, and coordinate with engineers and compliance to ensure continuous authorization.

The role requires extensive RMF, TS/SCI w/Poly, and cloud security expertise across AWS and Azure, with DoD IAM/IAT III and CISM/CISSP/SecurityX credentials.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Compliance Engineer — TS/SCI (Poly) & RMF A&A
Security Compliance Engineer — TS/SCI (Poly) & RMF A&A

Socket.dev • Seattle (WA)

On-site
USD 117,000 - 167,000
Senior IA Security Lead: RMF, Cloud & DevSecOps
Senior IA Security Lead: RMF, Cloud & DevSecOps

Integral Federal, Inc. • Fort Meade (MD)

On-site
USD 165,000 - 188,000
Senior Information Systems Security Manager (RMF/NIST)
Senior Information Systems Security Manager (RMF/NIST)

Armada LTD • Washington

On-site
USD 130,000 - 190,000
RMF Security Lead (TS/SCI) — ATO & Compliance Expert
RMF Security Lead (TS/SCI) — ATO & Compliance Expert

Veilant • Tysons (VA)

On-site
USD 190,000 - 232,000
Flexible PTO + holidays
401k match up to 10% + 3% safe harbor
Medical (HSA & PPO) + dental + vision
+5
TS/SCI InfoSec Officer: DoD Cyber & RMF Expert
TS/SCI InfoSec Officer: DoD Cyber & RMF Expert

Parsons • Baltimore (MD)

On-site
USD 104,000 - 181,000
Senior DevSecOps Cybersecurity Engineer (DoD RMF)
Senior DevSecOps Cybersecurity Engineer (DoD RMF)

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Senior Information Security Analyst - RMF & Compliance Lead
Senior Information Security Analyst - RMF & Compliance Lead

Wood River Federal • San Antonio (TX)

On-site
USD 100,000 - 150,000
Information Systems Security Manager
Information Systems Security Manager

Parsons • Baltimore (MD)

On-site
USD 158,000 - 284,000
Senior ISSM Leader — RMF, Cloud & Secure DevOps
Senior ISSM Leader — RMF, Cloud & Secure DevOps

Socket.dev • Tampa (FL)

On-site
USD 140,000 - 180,000
Mission-Critical Security Engineer | RMF & Cloud Security
Mission-Critical Security Engineer | RMF & Cloud Security

Jobtailor • King of Prussia (PA)

On-site
USD 120,000 - 170,000