> Markdown version of [/jobs/ext/2297868-navsea-risk-management-frame-rmf-information-systems-security](https://www.wearedevelopers.com/jobs/ext/2297868-navsea-risk-management-frame-rmf-information-systems-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # NAVSEA Risk Management Frame (RMF) Information Systems Security - **Company:** Arcfield, Inc. - **Location:** Newport, RI, United States - **Experience:** Experienced - **Salary:** $70,124.0 - **Contract:** Permanent contract - **Skills:** Capability Maturity Model Integration, Cyber Security, Identity and Access Management, Package Development Process, Software Engineering, Information Security Management System, Navsea - **Published:** August 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9127645/navsea-risk-management-frame-rmf-information-systems-security ## About the Role * BS 2-4, MS 0-2 * Minimum 2+ years of professional cybersecurity experience and Risk Management Framework * Demonstrated expert-level experience with Risk Management Framework * Experience in RMF policy development, process improvement, and strategy implementation * Demonstrated efficiency and expert-level experience in RMF package development, including POA&Ms (mitigation statements), Security Plans, Risk Assessments, architecture diagrams, asset inventories, and system/site policies, procedures, and processes * Must have an 8570.01M IAM/IAT Level II Certificate (Security + at a minimum CAP or CASP /CISSP preferred) * Knowledge National Institute of Standards and Training Special Publications (NIST SPs) knowledge * Must be able to manage multiple projects at a time * Assessment and Authorization (A&A formerly C&A, i.e. RMF and DIACAP respectively) * Experience with ACAS, STIG OSS Manager, STIGViewer, eMASS * Knowledge and experience with practices and procedures for CMMI Software Development Level 3 or greater is a plus * Knowledge in Continuous Monitoring * Excellent customer service and organization skills * Excellent oral and written communication skills * Demonstrated expert-level experience with DISA STIGs and SRGs * Position requires U.S. Citizenship * Possess and Maintain an active Secret security clearance ## Description Support the NUWCDIVNPT in a Junior-Mid RMF ISSE Role and perform tasks related to Assess and Authorize (A&A) to maintain Authorizations to Operate (ATOs) systems (i.e., applications, networks, devices), and perform the following: * Provide a disciplined, structured, and flexible process for managing security and privacy risk that includes information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. * Become familiar with the system/site by reviewing the Assessment and Authorization (A&A) System Security Plan for existing systems; identify any issues with the Security Plan and Procedures; execute the Security Assessment Plan and process Security Test Report; review POA&Ms; develop/perform Risk Assessment analysis. * Keep abreast of and provide the team updated information on Navy RMF policies and procedures. Review DoD, DON, NAVSEA CS-related documentation (i.e., RMF Process Guide, Navy SCA Risk Assessment Guide, DoN Standard Operating Procedures, NAVSEA Business Rules). * Be comfortable conducting independent security control assessments in accordance with NIST SP 800-53, 800-53A, CNSSI 1253, and the Risk Management Framework (RMF) described in NIST SP 800-37. * Clearly articulate requirements and other information in written documentation such as Security Plan, Contingency Plan, Contingency Plan Test, Business Impact Analysis, etc. * Provide guidance and training in eMASS to team members. * Demonstrate strong organizational and time-management skills: multitasking, working individually and with a team, having a positive attitude, being self-motivated and reliable, being trustworthy, having strong interpersonal and diplomatic skills, and being able to handle stress in a professional manner. * Attend stakeholder meetings, capture and track action items, and follow up with stakeholders to ensure timely completion. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [The Avengers Initiative (Practical Ethics for Software Engineers)](https://www.wearedevelopers.com/videos/2070-the-avengers-initiative-practical-ethics-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Official Opening of WeAreDevelopers World Congress 2026](https://www.wearedevelopers.com/videos/100000-official-opening-of-wearedevelopers-world-congress-2026) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)