Sr. RMF Security Engineer

Koitecc Solutions

San Diego (CA)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Leidos in San Diego seeks a Sr. RMF Security Engineer to guide a Navy base project through the RMF lifecycle, including categorization, control selection, and implementation.

You will perform risk assessments, analyze test results, and ensure compliance with DoD directives, SSP/SAR/POA&M, and continuous monitoring using tools like Nessus, OpenSCAP, eMASS.

Qualifications

  • Bachelor’s or Master’s degree with DoD-related emphasis; experience counts toward degree requirements.
  • DoD 8570 approved security certification required within 90 days of hire.
  • U.S. citizenship with active Secret DoD clearance.
  • Deep knowledge of NIST RMF, 800-37/800-53/800-171, FedRAMP, DoD 8510.01.
  • Experience documenting SSP, SAR, and POA&M.

Responsibilities

  • Guide RMF lifecycle: system categorization, control selection and implementation.
  • Perform continuous monitoring and risk assessments.
  • Identify and remediate vulnerabilities via configuration changes and tool updates.
  • Prepare SSP, SAR, and POA&M documents.
  • Conduct vulnerability scans, penetration testing, and security evaluations.
  • Collaborate with development and operations to integrate security into SDLC.

Skills

NIST RMF knowledge
Risk assessment
Vulnerability management
Security policy
Documentation

Education

Bachelor’s degree in Cybersecurity/Info Assurance/CS or related field
Master’s degree

Tools

eMASS
SCAP tools
Nessus
Tenable.sc
OpenSCAP
DISA STIGs
STIG benchmarks

Job description

Leidos is seeking a Sr. RMF Security Engineer to support a project at a Navy base in San Diego. This role will guide the project through the RMF lifecycle, including categorizing information systems, selecting and implementing security controls, assessing controls effectiveness, conducting continuous monitoring, identifying vulnerabilities, and ensuring systems remain secure against evolving threats.

The RMF Security Engineer will act as a technical advisor and problem solver, bridging the gap between cybersecurity policy and system implementation. Responsibilities include performing risk assessments, analyzing security test results, recommending mitigation strategies, and ensuring compliance with DoD directives.

Responsibilities
  • Guide the RMF lifecycle: system categorization, control selection, and implementation.
  • Conduct continuous monitoring and risk assessments.
  • Identify and remediate vulnerabilities through configuration changes, tool updates, or process improvements.
  • Prepare System Security Plans (SSP), Security Assessment Reports (SAR), and Plan of Action & Milestones (POA&M).
  • Perform vulnerability scans, penetration testing, and security evaluations.
  • Collaborate with development and operations teams to integrate security into software development life cycles.
Required Qualifications
  • Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, or related field (12+ years of experience) or Master’s degree (10+ years of experience). Work experience may be considered in lieu of a degree.
  • DoD 8570 approved security certification (e.g., Security+) required within 90 days of hire.
  • U.S. citizenship with an active Secret DoD security clearance.
  • Deep knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-171, FedRAMP, and DoD Instruction 8510.01.
  • Experience preparing SSP, SAR, and POA&M documents.
  • Proficiency with eMASS, SCAP tools (e.g., Nessus, Tenable.sc, OpenSCAP), and STIG compliance (DISA STIGs, SCAP benchmarks).
  • Experience identifying vulnerabilities in code using SAST and DAST tools.
  • Conducting risk assessments, vulnerability scans, and penetration testing.
Preferred Qualifications
  • Programming experience in Python, JavaScript, TypeScript, Bash, Rust, or PowerShell.
  • Experience with AI agentic workflows that incorporate the NIST RMF for code compliance and vulnerability mitigation.
  • Understanding NIST SP 800-207 (Zero Trust Architecture) and its intersection with RMF.
  • Knowledge of CMMC 2.0.
  • Experience with COMSEC concepts.
  • CISSP certification.
  • Experience with SIEM/log monitoring tools (e.g., Splunk, ArcSight) and high-assurance / Type 1 security evaluation processes.

Position is 100% on-site at the Navy base.

Equal Opportunity Statement

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. RMF Security Engineer
Sr. RMF Security Engineer

Leidos Inc • San Diego (CA)

On-site
USD 131,000 - 238,000
Sr. RMF Security Engineer
Sr. RMF Security Engineer

Leidos • San Diego (CA)

On-site
USD 131,000 - 237,000
Paid time off
11 paid holidays
401K with company match
+3
Senior RMF Security Engineer - On-Site DoD Cyber
Senior RMF Security Engineer - On-Site DoD Cyber

Leidos Inc • San Diego (CA)

On-site
USD 131,000 - 238,000
RMF Security Analyst
RMF Security Analyst

Via Logic LLC • Odenton (MD)

Hybrid
USD 69,000 - 126,000
Health and Wellness programs
Income Protection
Paid Leave
+1
RMF Security Analyst
RMF Security Analyst

Leidos Inc • Odenton (MD)

Hybrid
USD 69,000 - 126,000
Health and Wellness programs
Income Protection
Paid Leave
+1
RMF Security Analyst
RMF Security Analyst

Leidos • Odenton (MD)

Hybrid
USD 108,000 - 195,000
RMF Engineer
RMF Engineer

Innovatus Technology Consulting • San Diego (CA), Northern (KY)

Hybrid
USD 110,000 - 160,000
Mostly remote hybrid
Mission impact in DoD programs
SDVOSB veteran-friendly environment
+1
Cybersecurity Analyst
Cybersecurity Analyst

Leidos • Keyport (WA)

On-site
USD 73,000 - 133,000
Risk Management Framework (RMF) Test Engineer
Risk Management Framework (RMF) Test Engineer

General Dynamics Electric Boat • New London (CT)

On-site
USD 90,000 - 130,000
Cybersecurity Analyst
Cybersecurity Analyst

Leidos Inc • Keyport (WA)

On-site
USD 73,000 - 133,000