Information Systems Security Engineer (RMF)
Core
Support Assessment and Authorization (A&A) activities and maintain Authorizations to Operate (ATOs) for Navy enterprise and RDT&E systems.
Role type
Information Systems Security Engineer (RMF)
Builds
RMF packages, security documentation, and compliance artifacts for DoD systems
Domain
Defense / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
RMF process execution, Security Plan development, Risk Assessment, POA&M management, NIST SP 800-37/53/53A compliance, eMASS/ACAS tool usage, STIG implementation, continuous monitoring, security control assessment
Preferred skills
Navy/NAVSEA program support, security control assessment leadership, RMF policy development, cybersecurity training and mentoring
Technologies
eMASS, ACAS, STIG Viewer, STIG OSS Manager, NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, CNSSI 1253
Responsibilities
Develop and maintain RMF package documentation including Security Plans and Risk Assessments, Perform security control assessments per NIST standards, Execute Security Assessment Plans and review Security Test Reports, Utilize cybersecurity tools to assess and monitor compliance, Provide guidance on Navy RMF policies and cybersecurity directives, Coordinate with government and contractor personnel for A&A outcomes
Seniority
Mid-level, hands-on IC