Lead and support all phases of the Risk Management Framework (RMF) process in accordance with NIST SP 800-37 and related standards.
Develop, maintain, and update RMF documentation including: System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Continuous Monitoring Strategies.
Coordinate security authorization packages for Authorization to Operate (ATO) decisions.
Apply and validate security controls based on NIST SP 800-53 and organizational overlays.
Conduct control assessments and support independent security assessments and audits.
Identify security gaps and recommend remediation actions.
Support continuous monitoring programs to ensure ongoing compliance with security controls.
Track vulnerabilities, risks, and mitigation progress through POA&M management.
Communicate security posture and risk status to technical and non-technical stakeholders.
Requirements
Active TS/SCI with a current CI Polgraph (preferrably from this client).
BS in Computer Science, Cyber Security, or related field.
Demonstrated hands-on experience executing the RMF lifecycle (all or most phases).
Current, active security certification such as: CompTIA Security+, CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CIAM (Certified Identity and Access Manager).
Familiarity with federal cybersecurity compliance environments.
Ability to operate independently and contribute immediately upon assignment.
Master's Degree in Computer Science or Cyber Security (desired).