RMF Security Engineer

Mount Indie
Arlington, VA, United States
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Xacta Software Documentation Information Systems Security Content Automation Protocol SC Clearance Scap Compliance Checker Plan of Action and Milestones

Requirements

This position is for a RMF security engineer and requires 5 years of experience with RMF / Sec engineering. Provides end-to-end A&A support for DoD cybersecurity, privacy, and financial controls implementation, testing, monitoring, and enforcement. Interprets risks and recommends approaches to meeting DoD compliance and cybersecurity requirements in accordance with NIST Risk Management Framework (RMF) Controls and DoD Policy.

Preferred candidates must have:

  • Experience in mapping, implementing, interpreting, and documenting RMF security controls
  • Experienced managing the eMASS cybersecurity management tool
  • Experience developing and submitting at least six (6) ATO packages
  • Secret Clearance

Additional requirements include:

  • Thorough understanding of the Risk Management Framework (RMF) Assessment and Authorization (A&A) process within the federal government, including knowledge of all phases of the RMF lifecycle.
  • Proven experience in assisting client risk management tasks, such as managing POA&M, conducting Security Tests and Evaluations (ST&E), creating system documentation, performing authorizations, carrying out risk assessments, handling third-party audits, ensuring compliance with NIST 800-53 standards, and performing threat assessments according to the RMF lifecycle and processes.
  • Demonstrated proficiency to plan and monitor security control implementation for the protection of networks, enclaves, and information systems.
  • Strong communication abilities, including working closely with highly technical administrators to enhance overall security measures.
  • Ability to generate and interpret ACAS scans to identify system vulnerabilities and monitor remediation efforts or mitigation strategies.
  • Working knowledge and experience implementing and evaluating manual Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP), and SCAP Compliance Checker (SCC).
  • Working knowledge of common assessment & authorization (A&A) application platforms e.g. eMASS, CSAM, Xacta, etc.
  • Previous experience in a technical role such as a system or network administrator is a plus.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · WWC 2025

2:59 min

Why existing security and device management tools fail

Marcus Wermuth Marcus Wermuth · WWC Europe 2026

1:08 min

The inability to secure sensitive information in system prompts

Sebastian Schrittwieser · WWC 2023

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all