RMF Security Engineer - ACTIVE SECRET Required

Cornerstone Tech, Inc.
Alexandria, VA, United States
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$115,000.0 - $124,000.0
Working hours
Regular working hours
Job source

Tech stack

Xacta Software Documentation CompTIA Security+ Information Systems Information Technology Operations Security Content Automation Protocol SC Clearance Information Technology 3-tier Architectures Scap Compliance Checker Plan of Action and Milestones

Job description

Cornerstone Technology Enterprises is seeking an experienced RMF Security Engineer to support our government customer at DMDC. This hybrid role requires occasional on-site presence at the Mark Center and focuses on end-to-end Risk Management Framework (RMF) support, including Authority to Operate (ATO) packages, eMASS management, and DoD cybersecurity compliance.

You will interpret risk and recommend approaches to meeting DoD compliance and cybersecurity requirements in accordance with the NIST Risk Management Framework (RMF) and DoD policy, working across the full RMF lifecycle from control mapping through continuous monitoring.

Candidates with a background in RMF security engineering, A&A, or cybersecurity compliance within DoD environments are strongly encouraged to apply. This role is classified under a contract labor category as Network and Computer Systems Administrator - Journeyman.

What You Will Do

RMF Assessment & Authorization

  • Map, implement, interpret, and document RMF security controls across information systems
  • Manage the full RMF lifecycle from categorization through continuous monitoring
  • Develop and submit Authorization to Operate (ATO) packages
  • Manage and maintain system records in the eMASS cybersecurity management tool

Risk & Compliance Management

  • Manage Plans of Action & Milestones (POA&M)
  • Develop and maintain system security documentation, including System Security Plans (SSPs), POA&Ms, and ST&Es
  • Conduct Security Test & Evaluations (ST&E) and create supporting system documentation
  • Perform risk assessments, threat assessments, and support third-party audits
  • Ensure compliance with NIST 800-53 standards and DoD policy

Vulnerability & Technical Assessment

  • Generate and interpret ACAS scans to identify system vulnerabilities
  • Monitor remediation efforts and mitigation strategies
  • Implement and evaluate manual Security Technical Implementation Guides (STIGs) using SCAP and SCAP Compliance Checker (SCC)
  • Plan and monitor security control implementation for the protection of networks, enclaves, and information systems

Documentation & Stakeholder Support

  • Partner closely with highly technical administrators to strengthen overall security measures
  • Communicate risk posture and compliance status clearly to technical and non-technical stakeholders
  • Maintain accurate documentation across A&A platforms such as eMASS, CSAM, and Xacta

Requirements

  • Active Secret Clearance (Tier 3)
  • 5+ years of experience in RMF / security engineering
  • Experience mapping, implementing, interpreting, and documenting RMF security controls
  • Experience managing the eMASS cybersecurity management tool
  • Experience developing and submitting at least six (6) ATO packages
  • Thorough understanding of the RMF Assessment and Authorization (A&A) process, including all phases of the RMF lifecycle
  • Proven experience managing POA&M, conducting ST&E, performing risk assessments, and ensuring NIST 800-53 compliance
  • Ability to generate and interpret ACAS scans and monitor remediation efforts
  • Working knowledge of manual STIGs, SCAP, and SCC
  • Working knowledge of A&A platforms such as eMASS, CSAM, and Xacta
  • CompTIA Security+ certification (or equivalent DoD 8570 IAT Level II)
  • Excellent communication and technical writing skills

Preferred Qualifications

  • Previous experience in a technical role such as a system or network administrator
  • Strong communication skills, with experience working closely with highly technical administrators
  • Background supporting DMDC or other large-scale DoD IT operations programs
  • Familiarity with DoD privacy and financial control requirements

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Retirement plan
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Health savings account, * 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Health savings account
  • Life insurance
  • Paid time off
  • Retirement plan
  • Vision insurance

License/Certification:

  • CompTIA Security+ (Required)

Security clearance:

  • Secret (Required)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

6:03 min

Engaging software developers deeply in secure engineering practices

Tanya Janca · WWC 2021

Videos

See all

Related articles

See all