RMF Security SME

UNAVAILABLE

McLean (VA)

On-site

USD 120,000 - 160,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

UNAVAILABLE is seeking an RMF Security SME to modernize security posture by moving from manual compliance to automated control implementation with continuous monitoring. The role blends RMF/NIST expertise with hands-on cloud and DevSecOps engineering, partnering with engineers, data scientists, designers, and analysts to build secure, auditable systems.

The candidate will design automation pipelines, map controls to automated workflows, and embed RMF into the SDLC and CI/CD processes, ensuring

Qualifications

  • Experience translating RMF/NIST controls into automated, auditable implementations.
  • Experience with cloud/DevSecOps and security automation.
  • Active security certification (CISSP or cloud security) preferred.

Responsibilities

  • Serve as RMF SME, mapping controls to automated implementations and continuous monitoring.
  • Design control automation pipelines using IaC and compliance-as-code approaches.
  • Identify and drive secure cloud controls, incl. IAM, zero-trust, and data privacy controls.
  • Collaborate with stakeholders to balance security with usability and translate RMF into technical solutions.
  • Review infrastructure as code for control coverage, risk, and compliance impact.
  • Conduct risk and control assessments to meet NIST/FISMA and other frameworks.
  • Automate vulnerability management, patch management, and control monitoring/reporting.
  • Embed RMF requirements into SDLC and CI/CD pipelines with software developers.
  • Support data protection and encryption across data at rest and in transit.
  • Document current controls and gap analyses; produce remediation options and recommendations.
  • Drive automation for RMF processes and A&A artifacts (SSPs, POA&Ms).
  • Identify, analyze, and resolve infrastructure vulnerabilities affecting compliance.
  • Propose continuous improvements to control automation and security operations.
  • Present status updates and cross-train team members on RMF processes.

Skills

Security clearance
Cloud/DevSecOps
RMF/NIST expertise
Threat modeling
Automation / IaC

Education

No degree with 9 years of relevant experience
Bachelor's degree w/ 5 years relevant experience
Master's degree w/ 3 years relevant experience

Tools

OSCAL
eMASS
Xacta
CSAM
AWS
Azure
GCP

Job description

Overview

We are seeking an RMF Security SME to help modernize our security posture by shifting from manual compliance to automated control implementation and continuous monitoring. This role bridges deep knowledge of the Risk Management Framework (RMF) and security controls with hands‑on cloud and DevSecOps engineering, working alongside engineers, data scientists, designers, and analysts to build secure, usable, and auditable systems.

Responsibilities
  • Serve as the RMF subject matter expert, interpreting NIST SP 800-53 controls and mapping technical and operational requirements to automated implementation and continuous monitoring
  • Design and implement control automation pipelines that convert manual compliance activities (control implementation, evidence collection, continuous monitoring) into repeatable, automated processes using infrastructure as code and compliance-as-code approaches (e.g., OSCAL)
  • Identify anddrive implementation of controls aroundsecure cloud-based solutions, including zero‑trust architecture components, identity and access management (IAM) policy, and data privacy controls
  • Partner with stakeholders to balance security requirements with usability, translating RMF and compliance requirements into practical technical solutions
  • Review infrastructure as code authored by others to assess control coverage, security risk, and compliance impact
  • Conduct risk assessments and control assessments to ensure systems meet NIST, FISMA, and other applicable compliance frameworks
  • Recommend solutions for automatingsecurity processes such as vulnerability management, patch management, and control monitoring/reporting
  • Collaborate with software developers and DevSecOps engineers to embed security controls and RMF requirements into the SDLC and CI/CD pipeline
  • Support control mapping design and implementation of data protection and encryption for data at rest and in transit
  • Document the as‑is control environment, perform gap analyses against RMF/NIST baselines, and produce artifacts articulating remediation options and recommendations
  • Drive automation for core RMF Processes & generation of A&A documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and control assessment artifacts.
  • Identify, analyze, and resolve infrastructure vulnerabilities and application deployment issues affecting control compliance
  • Engineer solutions and recommend continuous improvements to control automation and security operations
  • Present regular status updates and provide cross‑training to team members on RMF processes and control automation practices
Qualifications
  • Ability to obtain a U.S. government Security Clearance
  • One of the following, based on education level: no degree with 9 years of relevant experience, a Bachelor's degree with 5 years of relevant experience, or a Master's degree with 3 years of relevant experience
  • Experience architecting, designing, developing, and implementing cloud solutions
  • Experience with one or more cloud platforms (AWS, Azure, or GCP)
  • 5 years of experience conducting monitoring, risk assessment, threat modeling, and security testing in cloud environments
  • 5 years of experience applying the Risk Management Framework (RMF), including documenting POA&Ms, SSPs, and Assessment & Authorization (A&A) support documentation
  • Demonstrated understanding of NIST 800-53 (or equivalent) security controls and experience translating control requirements into technical and operational implementations
  • At least one active, relevant professional certification tied to the cloud/security technology being deployed or maintained (e.g., AWS Certified Security Specialty, AWS Certified Solutions Architect Associate, Microsoft Certified Azure Administrator Associate, CISSP, or CAP), subject to program manager approval
Preferred:
  • Additional certifications beyond the one required above
  • Experience with compliance automation platforms and standards such as OSCAL, eMASS, Xacta, or CSAM
  • Experience automating control assessment, continuous monitoring (ConMon), and A&A documentation workflows
  • Excellent written and verbal communication, interpersonal, and collaborative skills
  • Experience documenting as-is environment states, performing gap analyses, and producing options/recommendation artifacts
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

RMF Security Automation Architect
RMF Security Automation Architect

Steampunk • Bloomington (IL)

On-site
USD 130,000 - 180,000
RMF Security Automation Architect
RMF Security Automation Architect

UNAVAILABLE • McLean (VA)

On-site
USD 120,000 - 160,000
Sr. Information Assurance Specialist
Sr. Information Assurance Specialist

NR Labs LLC • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
Cybersecurity RMF Analyst III
Cybersecurity RMF Analyst III

Modus21, LLC. • Louisiana (MO), Norfolk (VA), Tampa (FL)

On-site
USD 90,000 - 140,000
NIST Risk Management Framework SME
NIST Risk Management Framework SME

Boston Government Services, LLC (BGS) • United States

On-site
USD 90,000 - 120,000
Health Insurance
Dental Insurance
Vision Insurance
+3
RMF Security Control Assessor (Expert)
RMF Security Control Assessor (Expert)

Pueo Business Solutions LLC • McLean (VA)

On-site
USD 140,000 - 210,000
Security Control Assessor
Security Control Assessor

RMantra Solutions • Virginia (MN)

On-site
USD 100,000 - 130,000
RMF Cybersecurity Analyst II - 505767
RMF Cybersecurity Analyst II - 505767

Delaware Nation Industries • Bath Township (OH)

On-site
USD 70,000 - 100,000
Benefits coverage
401K match
Disability insurance
+3
RMF / Cybersecurity Compliance Specialist (Pipeline)
RMF / Cybersecurity Compliance Specialist (Pipeline)

Lucayan Technology Solutions LLC • United States

On-site
USD 120,000 - 170,000
Cyber Risk Management Specialist
Cyber Risk Management Specialist

UNAVAILABLE • McLean (VA)

On-site
USD 120,000 - 160,000