RMF Security Engineer - ACTIVE SECRET Required
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Cornerstone Technology Enterprises is seeking an experienced RMF Security Engineer to support our government customer at DMDC. This hybrid role requires occasional on-site presence at the Mark Center and focuses on end-to-end Risk Management Framework (RMF) support, including Authority to Operate (ATO) packages, eMASS management, and DoD cybersecurity compliance.
You will interpret risk and recommend approaches to meeting DoD compliance and cybersecurity requirements in accordance with the NIST Risk Management Framework (RMF) and DoD policy, working across the full RMF lifecycle from control mapping through continuous monitoring.
Candidates with a background in RMF security engineering, A&A, or cybersecurity compliance within DoD environments are strongly encouraged to apply. This role is classified under a contract labor category as Network and Computer Systems Administrator - Journeyman.
What You Will Do
RMF Assessment & Authorization
- Map, implement, interpret, and document RMF security controls across information systems
- Manage the full RMF lifecycle from categorization through continuous monitoring
- Develop and submit Authorization to Operate (ATO) packages
- Manage and maintain system records in the eMASS cybersecurity management tool
Risk & Compliance Management
- Manage Plans of Action & Milestones (POA&M)
- Develop and maintain system security documentation, including System Security Plans (SSPs), POA&Ms, and ST&Es
- Conduct Security Test & Evaluations (ST&E) and create supporting system documentation
- Perform risk assessments, threat assessments, and support third-party audits
- Ensure compliance with NIST 800-53 standards and DoD policy
Vulnerability & Technical Assessment
- Generate and interpret ACAS scans to identify system vulnerabilities
- Monitor remediation efforts and mitigation strategies
- Implement and evaluate manual Security Technical Implementation Guides (STIGs) using SCAP and SCAP Compliance Checker (SCC)
- Plan and monitor security control implementation for the protection of networks, enclaves, and information systems
Documentation & Stakeholder Support
- Partner closely with highly technical administrators to strengthen overall security measures
- Communicate risk posture and compliance status clearly to technical and non-technical stakeholders
- Maintain accurate documentation across A&A platforms such as eMASS, CSAM, and Xacta
Requirements
- Active Secret Clearance (Tier 3)
- 5+ years of experience in RMF / security engineering
- Experience mapping, implementing, interpreting, and documenting RMF security controls
- Experience managing the eMASS cybersecurity management tool
- Experience developing and submitting at least six (6) ATO packages
- Thorough understanding of the RMF Assessment and Authorization (A&A) process, including all phases of the RMF lifecycle
- Proven experience managing POA&M, conducting ST&E, performing risk assessments, and ensuring NIST 800-53 compliance
- Ability to generate and interpret ACAS scans and monitor remediation efforts
- Working knowledge of manual STIGs, SCAP, and SCC
- Working knowledge of A&A platforms such as eMASS, CSAM, and Xacta
- CompTIA Security+ certification (or equivalent DoD 8570 IAT Level II)
- Excellent communication and technical writing skills
Preferred Qualifications
- Previous experience in a technical role such as a system or network administrator
- Strong communication skills, with experience working closely with highly technical administrators
- Background supporting DMDC or other large-scale DoD IT operations programs
- Familiarity with DoD privacy and financial control requirements
Benefits & conditions
Pulled from the full job description
- 401(k)
- Health insurance
- Retirement plan
- 401(k) matching
- Paid time off
- Vision insurance
- Health savings account, * 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Retirement plan
- Vision insurance
License/Certification:
- CompTIA Security+ (Required)
Security clearance:
- Secret (Required)
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
The Overflow: Security and Privacy
Understanding and Mitigating Common Web Vulnerabilities
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents