> Markdown version of [/jobs/ext/1218071-rmf-a-a-lead-nih-hhs-experience](https://www.wearedevelopers.com/jobs/ext/1218071-rmf-a-a-lead-nih-hhs-experience). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF / A&A Lead (NIH/HHS Experience) - **Company:** Greenbrier Government Solutions Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $158,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Amazon Web Services, Microsoft Azure, Border Gateway Protocol, Cisco PIX, Cisco Routers, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Dynamic Host Configuration Protocol, Disaster Recovery, Domain Name System (DNS), Enhanced Interior Gateway Routing Protocol, Federal Information Processing Standards (FIPS), Identity and Access Management, Network Security, Lightweight Directory Access Protocols (LDAP), Networking Basics, Routing, Network Protocols, Open Shortest Path First (OSPF), Open Source Technology, Public Key Infrastructure, Role-Based Access Control, Software Systems, TCP/IP, Software Vulnerability Management, Transport Layer Security, Identity Services Engine, Load Balancing, Cloud Platform System, System Availability, Firewalls (Computer Science), Information Technology, Nessus, ISO/IEC 27002, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ee6eb2a1611b53ac ## About the Role We are seeking a highly motivated and experienced RMF / A&A Lead with extensive NIH (National Institutes of Health) and HHS (Health and Human Services) experience to join our dynamic cybersecurity team. In this pivotal role, you will lead the Risk Management Framework (RMF) and Authorization & Accreditation (A&A) processes, ensuring our IT systems meet rigorous government security standards. Your expertise will drive the development, implementation, and continuous improvement of security policies, system security plans, and compliance programs. Education / Experience: Bachelor's Degree + 8+ years RMF/A&A and ISSO experience across large federal portfolios (50+ systems strongly preferred) Required Certifications: CISSP or CAP Preferred: eMASS/CSAM/JCAM or equivalent; NIST SP 800-37/53/53A mastery; POA&M program management; C-SCRM/SBOM (EO 14028); FedRAMP reviews; OIG/GAO audit support; experience directing automated A&A artifact production, * 8+ years RMF/A&A and ISSO experience across large federal portfolios (50+ systems strongly preferred) * Prior leadership of automation-assisted A&A at portfolio scale is necessary in this role. * Deep understanding of system security plans, NIST standards (including SP 800-53), ISO 27000 series, FIPS compliance requirements. * Extensive experience with computer networking concepts such as LAN/WAN architecture, routing protocols (OSPF/EIGRP/BGP), network protocols (TCP/IP/SSL), load balancing, DNS/DHCP services. * Proficiency in managing network security devices including Cisco routers/switches, Cisco ASA firewalls, Palo Alto firewalls; familiarity with Cisco ISE for identity management. * Strong knowledge of cloud computing platforms like AWS and Azure; experience with cloud infrastructure security best practices including FedRAMP compliance. * Expertise in IT risk management frameworks such as COBIT or DIACAP; ability to perform vulnerability assessments using tools like Nessus or open-source equivalents. * Skilled in implementing identity & access management solutions such as LDAP/Active Directory/RBAC; experience with encryption technologies including PKI and FIPS standards. * Ability to develop and enforce security policies related to system hardening, incident management, disaster recovery planning, high availability configurations, and threat intelligence analysis. ## Description * Responsible for leading the largest task team on the Federal program across ~165 FISMA systems. * Will directs a 7 FTE RMF team plus ISSO support * Responsible for the full authorization package production (SSP, BIA, PTA/PIA, CP/IRP), annual CP/IRP testing, POA&M and waiver management, C-SCRM, with independent QA of every package before AO submission. * Prior leadership of automation-assisted A&A at portfolio scale is essential. * Lead the development and maintenance of comprehensive system security plans aligned with NIST standards and federal regulatory frameworks such as FISMA, FedRAMP, and DIACAP. * Conduct thorough security risk assessments and investigations to identify vulnerabilities within IT infrastructure, including network security, system hardening, and vulnerability management. * Oversee the implementation of security controls based on NIST SP 800-53, ISO 27000 series, ISO 27002 standards, and other applicable frameworks to ensure compliance across all systems. * Manage the accreditation process for government systems by coordinating with stakeholders to prepare documentation, perform security assessments, and obtain necessary authorizations. * Support incident response activities by investigating security incidents, conducting threat detection & response analyses, and facilitating incident recovery efforts. * Maintain awareness of evolving cybersecurity threats and regulatory requirements to proactively enhance security posture through governance, risk management (GRC) software solutions, and continuous monitoring. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [A Technical Introduction to Bitcoin's 2nd Layer- The Lightning Network](https://www.wearedevelopers.com/videos/15-a-technical-introduction-to-bitcoin-s-2nd-layer-the-lightning-network) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023)