RMF Security SME

Steampunk

McLean (VA)

On-site

USD 130,000 - 180,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Steampunk is seeking an RMF Security SME to modernize our security posture by automating control implementation and continuous monitoring in cloud environments. This role blends deep RMF knowledge with hands-on DevSecOps engineering to build secure, auditable systems.

You will interpret NIST SP 800-53 controls, map requirements to automated pipelines, and collaborate across engineering, data science, and design teams to balance security with usability and speed in delivery.

Qualifications

  • Ability to obtain a U.S. government Security Clearance.
  • Experience architecting, designing, developing, and implementing cloud solutions.
  • Experience with one or more cloud platforms (AWS, Azure, or GCP).
  • 5 years of experience conducting monitoring, risk assessment, threat modeling, and security testing in cloud environments.
  • 5 years of experience applying the RMF, including documenting POA&Ms, SSPs, and A&A support documentation.
  • Active, relevant cloud/security certifications (e.g., CISSP, AWS/SOC, CAP) as approved.

Responsibilities

  • Serve as RMF SME, interpreting NIST SP 800-53 controls and mapping to automated implementations.
  • Design and implement control automation pipelines using IaC and OSCAL.
  • Identify and drive implementation of controls in secure cloud solutions and zero-trust components.
  • Collaborate with stakeholders to balance security requirements with usability.
  • Review infrastructure as code for control coverage, risk, and compliance impact.
  • Conduct risk and control assessments to meet RMF/NIST baselines.
  • Automate vulnerability management, patching, and control monitoring/reporting.
  • Embed RMF requirements into SDLC/CI/CD pipelines with developers and DevSecOps engineers.
  • Support data protection and encryption controls for data at rest/in transit.
  • Produce SSPs, POA&Ms, and control assessment artifacts.

Skills

RMF expertise
Cloud security
DevSecOps
Threat modeling
Automated control implementation
Continuous monitoring

Education

No degree 9 years
Bachelor's degree
Master's degree

Tools

AWS
Azure
GCP
OSCAL
XACTA
eMASS

Job description

Overview

We are seeking an RMF Security SME to help modernize our security posture by shifting from manual compliance to automated control implementation and continuous monitoring. This role bridges deep knowledge of the Risk Management Framework (RMF) and security controls with hands-on cloud and DevSecOps engineering, working alongside engineers, data scientists, designers, and analysts to build secure, usable, and auditable systems.

Contributions
  • Serve as the RMF subject matter expert, interpreting NIST SP 800-53 controls and mapping technical and operational requirements to automated implementation and continuous monitoring
  • Design and implement control automation pipelines that convert manual compliance activities (control implementation, evidence collection, continuous monitoring) into repeatable, automated processes using infrastructure as code and compliance-as-code approaches (e.g., OSCAL)
  • Identify anddrive implementation of controls aroundsecure cloud-based solutions, including zero-trust architecture components, identity and access management (IAM) policy, and data privacy controls
  • Partner with stakeholders to balance security requirements with usability, translating RMF and compliance requirements into practical technical solutions
  • Review infrastructure as code authored by others to assess control coverage, security risk, and compliance impact
  • Conduct risk assessments and control assessments to ensure systems meet NIST, FISMA, and other applicable compliance frameworks
  • Recommend solutions for automatingsecurity processes such as vulnerability management, patch management, and control monitoring/reporting
  • Collaborate with software developers and DevSecOps engineers to embed security controls and RMF requirements into the SDLC and CI/CD pipeline
  • Support control mapping design and implementation of data protection and encryption for data at rest and in transit
  • Document the as-is control environment, perform gap analyses against RMF/NIST baselines, and produce artifacts articulating remediation options and recommendations
  • Drive automation for core RMF Processes & generation of A&A documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and control assessment artifacts.
  • Identify, analyze, and resolve infrastructure vulnerabilities and application deployment issues affecting control compliance
  • Engineer solutions and recommend continuous improvements to control automation and security operations
  • Present regular status updates and provide cross-training to team members on RMF processes and control automation practices
Qualifications

Required:

  • Ability to obtain a U.S. government Security Clearance
  • One of the following, based on education level: no degree with 9 years of relevant experience, a Bachelor's degree with 5 years of relevant experience, or a Master's degree with 3 years of relevant experience
  • Experience architecting, designing, developing, and implementing cloud solutions
  • Experience with one or more cloud platforms (AWS, Azure, or GCP)
  • 5 years of experience conducting monitoring, risk assessment, threat modeling, and security testing in cloud environments
  • 5 years of experience applying the Risk Management Framework (RMF), including documenting POA&Ms, SSPs, and Assessment & Authorization (A&A) support documentation
  • Demonstrated understanding of NIST 800-53 (or equivalent) security controls and experience translating control requirements into technical and operational implementations
  • At least one active, relevant professional certification tied to the cloud/security technology being deployed or maintained (e.g., AWS Certified Security Specialty, AWS Certified Solutions Architect Associate, Microsoft Certified Azure Administrator Associate, CISSP, or CAP), subject to program manager approval

Preferred:

  • Additional certifications beyond the one required above
  • Experience with compliance automation platforms and standards such as OSCAL, eMASS, Xacta, or CSAM
  • Experience automating control assessment, continuous monitoring (ConMon), and A&A documentation workflows
  • Excellent written and verbal communication, interpersonal, and collaborative skills
  • Experience documenting as-is environment states, performing gap analyses, and producing options/recommendation artifacts
About steampunk

Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $130,000 to $180,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk's total compensation package for employees. Learn more about additional Steampunk benefits here.

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Steampunk is aChange Agentin the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through ourHuman-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As anemployee owned company, we focus on investing in our employees to enable them to do the greatest work of their careers - and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visithttp://www.steampunk.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Risk Management Specialist
Cyber Risk Management Specialist

Steampunk • Bloomington (IL)

On-site
USD 100,000 - 150,000
Cyber Risk Management Specialist
Cyber Risk Management Specialist

Steampunk • McLean (VA)

On-site
USD 100,000 - 150,000
Cloud Engineer
Cloud Engineer

Steampunk • Bloomington (IL)

On-site
USD 100,000 - 175,000
Cyber Risk Management Specialist
Cyber Risk Management Specialist

Steampunk, Inc. • McLean (VA)

On-site
USD 100,000 - 150,000
Employee ownership
Solution Architect - Technical Lead
Solution Architect - Technical Lead

Steampunk • McLean (VA)

On-site
USD 112,000 - 225,000
DevSecOps Engineer
DevSecOps Engineer

Steampunk • Bloomington (IL)

On-site
USD 80,000 - 175,000
Test Engineering Team Lead
Test Engineering Team Lead

Steampunk • Bloomington (IL)

On-site
USD 110,000 - 160,000
Audit Coordination and Management Lead
Audit Coordination and Management Lead

Steampunk • McLean (VA)

On-site
USD 125,000 - 175,000
Test Engineering Team Lead
Test Engineering Team Lead

Steampunk • McLean (VA)

On-site
USD 110,000 - 160,000
Vulnerability Management Lead
Vulnerability Management Lead

Steampunk • Bloomington (IL)

On-site
USD 125,000 - 175,000