> Markdown version of [/jobs/ext/1281713-rmf-security-engineer-active-secret-required](https://www.wearedevelopers.com/jobs/ext/1281713-rmf-security-engineer-active-secret-required). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF Security Engineer - ACTIVE SECRET Required - **Company:** Cornerstone Tech, Inc. - **Location:** Alexandria, VA, United States - **Experience:** Expert - **Salary:** $115,000.0 - $124,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Software Documentation, CompTIA Security+, Information Systems, Information Technology Operations, Security Content Automation Protocol, SC Clearance, Information Technology, 3-tier Architectures, Scap Compliance Checker, Plan of Action and Milestones - **Published:** July 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1e422e2794daf6bf ## About the Role * Active Secret Clearance (Tier 3) * 5+ years of experience in RMF / security engineering * Experience mapping, implementing, interpreting, and documenting RMF security controls * Experience managing the eMASS cybersecurity management tool * Experience developing and submitting at least six (6) ATO packages * Thorough understanding of the RMF Assessment and Authorization (A&A) process, including all phases of the RMF lifecycle * Proven experience managing POA&M, conducting ST&E, performing risk assessments, and ensuring NIST 800-53 compliance * Ability to generate and interpret ACAS scans and monitor remediation efforts * Working knowledge of manual STIGs, SCAP, and SCC * Working knowledge of A&A platforms such as eMASS, CSAM, and Xacta * CompTIA Security+ certification (or equivalent DoD 8570 IAT Level II) * Excellent communication and technical writing skills Preferred Qualifications * Previous experience in a technical role such as a system or network administrator * Strong communication skills, with experience working closely with highly technical administrators * Background supporting DMDC or other large-scale DoD IT operations programs * Familiarity with DoD privacy and financial control requirements ## Description Cornerstone Technology Enterprises is seeking an experienced RMF Security Engineer to support our government customer at DMDC. This hybrid role requires occasional on-site presence at the Mark Center and focuses on end-to-end Risk Management Framework (RMF) support, including Authority to Operate (ATO) packages, eMASS management, and DoD cybersecurity compliance. You will interpret risk and recommend approaches to meeting DoD compliance and cybersecurity requirements in accordance with the NIST Risk Management Framework (RMF) and DoD policy, working across the full RMF lifecycle from control mapping through continuous monitoring. Candidates with a background in RMF security engineering, A&A, or cybersecurity compliance within DoD environments are strongly encouraged to apply. This role is classified under a contract labor category as Network and Computer Systems Administrator - Journeyman. What You Will Do RMF Assessment & Authorization * Map, implement, interpret, and document RMF security controls across information systems * Manage the full RMF lifecycle from categorization through continuous monitoring * Develop and submit Authorization to Operate (ATO) packages * Manage and maintain system records in the eMASS cybersecurity management tool Risk & Compliance Management * Manage Plans of Action & Milestones (POA&M) * Develop and maintain system security documentation, including System Security Plans (SSPs), POA&Ms, and ST&Es * Conduct Security Test & Evaluations (ST&E) and create supporting system documentation * Perform risk assessments, threat assessments, and support third-party audits * Ensure compliance with NIST 800-53 standards and DoD policy Vulnerability & Technical Assessment * Generate and interpret ACAS scans to identify system vulnerabilities * Monitor remediation efforts and mitigation strategies * Implement and evaluate manual Security Technical Implementation Guides (STIGs) using SCAP and SCAP Compliance Checker (SCC) * Plan and monitor security control implementation for the protection of networks, enclaves, and information systems Documentation & Stakeholder Support * Partner closely with highly technical administrators to strengthen overall security measures * Communicate risk posture and compliance status clearly to technical and non-technical stakeholders * Maintain accurate documentation across A&A platforms such as eMASS, CSAM, and Xacta ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)