Senior Cybersecurity / Risk Management Framework (RMF) Engineer

Capella Partners LLC

Alexandria (VA)

Hybrid

USD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Capella Partners LLC is seeking a Senior Cybersecurity / RMF Engineer to support multiple DoD programs. You will lead RMF lifecycle activities, develop SSPs and SAPs, and work hands-on with eMASS to maintain security packages and authorization documentation.

You will review system designs against DoD requirements, translate STIGs into remediation actions, and coordinate with government stakeholders to keep authorizations on schedule. A DoD clearance is required or obtainable.

Qualifications

  • Bachelor’s degree in cybersecurity, information technology, computer science, or related field.
  • 5+ years of experience in DoD cybersecurity, RMF, or information assurance.
  • Hands-on with DoD RMF process; familiarity with NIST SP 800-37/800-53.
  • Experience maintaining RMF packages and eMASS.
  • Able to obtain/maintain required security clearance.
  • Preferred: DoD 8570/8140-aligned certs (e.g., Security+, CISSP).
  • Preferred: vuln management, Nessus/Tenable, ACAS, HBSS/EDR, or DoD DevSecOps experience.

Responsibilities

  • Lead RMF activities across multiple DoD systems from preparation to continuous monitoring.
  • Develop and maintain RMF artifacts (SSPs, SAPs/SARs, POA&Ms).
  • Work with eMASS to manage system security packages and authorization docs.
  • Review architectures and configurations to ensure proper security controls.
  • Translate cybersecurity requirements into actionable tasks for engineers.
  • Coordinate with ISSOs/ISSMs and government stakeholders to resolve findings.
  • Track risks, POA&Ms, and remediation actions for leadership.

Skills

RMF process
eMASS
DoD security policies
Security documentation
Technical writing
STIGs knowledge
Vulnerability management
Communication
DevSecOps

Education

Bachelor’s degree in cybersecurity or related field

Tools

eMASS
Nessus/Tenable
ACAS
HBSS/EDR

Job description

Capella Partners is hiring a Senior Cybersecurity / Risk Management Framework (RMF) Engineer to support multiple enterprise DoD programs of record. You’ll help lead the RMF lifecycle from system documentation and security control implementation through assessment and authorization, working closely with program leadership, system engineers, developers, ISSOs/ISSMs, and government stakeholders to keep mission-critical systems secure, compliant, and moving forward.

What you’ll do
  • Lead and support RMF activities across multiple DoD systems and programs of record, from preparation and categorization through assessment, authorization, and continuous monitoring.

  • Develop, review, and maintain RMF security documentation, including System Security Plans (SSPs), Security Assessment Plans/Reports (SAPs/SARs), Plans of Action & Milestones (POA&Ms), control implementation statements, security procedures, and supporting evidence.

  • Work hands-on with eMASS to create, maintain, update, and track system security packages, controls, artifacts, POA&Ms, and authorization documentation.

  • Review system architectures, designs, configurations, and technical documentation to identify cybersecurity requirements and ensure appropriate security controls are addressed.

  • Analyze Security Technical Implementation Guides (STIGs), DoD security requirements, and applicable cybersecurity policies to identify required configurations, implementation gaps, and remediation actions.

  • Partner with developers, system engineers, infrastructure teams, and technical leads to translate cybersecurity requirements into practical engineering and development tasks.

  • Guide engineering teams on security control implementation, vulnerability remediation, configuration requirements, and the evidence needed to demonstrate compliance.

  • Review technical and security artifacts for completeness, accuracy, traceability, and alignment with applicable RMF controls and DoD requirements.

  • Coordinate with ISSOs, ISSMs, security assessors, system owners, and government stakeholders to resolve findings and keep authorization activities on schedule.

  • Track cybersecurity risks, vulnerabilities, POA&Ms, and remediation activities while communicating status, dependencies, and risks to program leadership.

  • Support security assessments, vulnerability management activities, and continuous monitoring by coordinating evidence collection and responding to assessor requests.

  • Help identify opportunities to streamline RMF processes, improve documentation quality, and make cybersecurity requirements easier for development and engineering teams to execute.

  • Stay current on DoD cybersecurity policies, RMF guidance, STIGs, vulnerability management practices, and changes affecting supported programs.

What you bring
  • Bachelor’s degree in cybersecurity, information technology, computer science, systems engineering, or a related field.

  • 5+ years of experience supporting cybersecurity, RMF, information assurance, or security engineering activities in a DoD or federal environment.

  • Hands‑on experience with the DoD RMF process and familiarity with NIST SP 800-37, NIST SP 800-53, and applicable DoD cybersecurity policies and guidance.

  • Experience working with eMASS and maintaining RMF packages through the authorization lifecycle.

  • Strong understanding of DoD STIGs and experience translating STIG and security control requirements into actionable remediation guidance for technical teams.

  • Experience reviewing system and software documentation and working directly with developers, system engineers, infrastructure teams, and other technical stakeholders.

  • Ability to interpret cybersecurity requirements and explain them clearly to both technical and non-technical audiences.

  • Strong technical writing, documentation, organization, and communication skills.

  • Ability to manage multiple systems, authorization packages, deadlines, and competing priorities with limited supervision.

  • Proficiency with Microsoft Office (Word, Excel, PowerPoint, Outlook, Teams).

  • Ability to obtain and maintain the required security clearance and access credentials.

  • Preferred: DoD 8570/8140-aligned certification such as Security+, CISSP, CAP, CASP+/SecurityX, or equivalent.

  • Preferred: Experience with vulnerability management, Nessus/Tenable, ACAS, HBSS/EDR, vulnerability remediation, security assessments, or continuous monitoring.

  • Preferred: Experience supporting software development, DevSecOps, cloud environments, or enterprise IT systems within a DoD environment.

Why Capella
  • We invest in our people — reflected in a 99.9% retention rate — on mission-critical work that supports national defense, with small-business agility that makes your impact visible from day one.

Capella Partners LLC is an equal‑opportunity employer and welcomes applicants of all backgrounds. Employment decisions are made without regard to any status protected by applicable law, and reasonable accommodations are available throughout the hiring process.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DoD RMF Engineer — Cybersecurity Lead
Senior DoD RMF Engineer — Cybersecurity Lead

Capella Partners LLC • Alexandria (VA)

Hybrid
USD 120,000 - 180,000
RMF Cybersecurity Analyst
RMF Cybersecurity Analyst

Cybersecurity Jobs • Rockaway Township (NJ)

On-site
USD 87,000 - 182,000
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

P3S CORPORATION • Dayton (OH)

On-site
USD 95,000 - 120,000
RMF Cybersecurity Analyst II - 505767
RMF Cybersecurity Analyst II - 505767

Delaware Nation Industries • Bath Township (OH)

On-site
USD 70,000 - 100,000
Benefits coverage
401K match
Disability insurance
+3
RMF / Cybersecurity Compliance Specialist (Pipeline)
RMF / Cybersecurity Compliance Specialist (Pipeline)

Rippling, Inc. • United States

Remote
USD 120,000 - 170,000
Cybersecurity RMF Analyst III
Cybersecurity RMF Analyst III

HRsmart • Louisiana (MO), Norfolk (VA), Tampa (FL)

On-site
USD 90,000 - 140,000
Cybersecurity / RMF Engineer
Cybersecurity / RMF Engineer

Integral Federal, Inc. • Fort Meade (MD), Northern (KY)

On-site
USD 110,000 - 140,000
Cyber Technical Engineer
Cyber Technical Engineer

Technomics, Inc. • Arlington (VA)

On-site
USD 80,000 - 100,000
RMF Cybersecurity Analyst II - 505767
RMF Cybersecurity Analyst II - 505767

DNI (Delaware Nation Industries) • Patterson Township (OH)

On-site
USD 90,000 - 120,000
Matching 401K
Parking and Transit Benefits
Professional Development/Education Re−
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Cybersecurity Jobs • Colorado Springs (CO)

On-site
USD 90,000 - 190,000
Healthcare and wellness
Financial and retirement
Family support
+3