> Markdown version of [/jobs/ext/2283639-cybersecurity-rmf-engineer](https://www.wearedevelopers.com/jobs/ext/2283639-cybersecurity-rmf-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity / RMF Engineer - **Company:** Integral Consulting Services - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Salary:** $110,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Agile Methodology, Cyber Security, Integrated Development Environments, Fortify (Software), Security Content Automation Protocol, Software Engineering, Kubernetes, Devsecops, Plan of Action and Milestones, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 28, 2026 - **Apply:** https://www.jofdav.com/jobs/59438601-cybersecurity-rmf-engineer ## About the Role * BA/ BS in an engineering discipline. Additional four years of experience in lieu of degree is acceptable. * 4+ years cybersecurity/RMF experience. * DoD RMF and NIST 800-53 experience. * STIG and vulnerability-assessment experience. * POA&M and security-evidence experience. * Ability to work effectively with software developers, DevSecOps engineers, and system administrators. * U.S. citizenship and required Secret eligibility Preferred: * DISA experience. * eMASS. * ACAS/SCAP. * Fortify, SAST/DAST, or other application-security tools. * Java/software-development environment experience. * Kubernetes/container or classified-cloud familiarity. ## Description Integral Federal is seeking a Cybersecurity / RMF Engineer to provide hands-on cybersecurity and RMF support to the JPES/JCRM Agile/DevSecOps team. The engineer works closely with developers, DevSecOps personnel, cloud/infrastructure engineers, testers, and the IA Lead to identify, remediate, validate, and document security findings throughout the software lifecycle., * Support RMF and continuous-monitoring activities. * Perform and analyze ACAS, STIG, SCAP, and application-security assessments. * Analyze vulnerabilities and security findings. * Maintain POA&M and eMASS evidence. * Work directly with developers and technical teams to remediate findings. * Validate remediation and finding closure. * Support SSP/control evidence and assessment readiness. * Support release-security reviews. * Integrate security findings into Agile/DevSecOps workflows. * Support ATO sustainment and cybersecurity taskings. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)