> Markdown version of [/jobs/ext/2553545-cybersecurity-rmf-specialist](https://www.wearedevelopers.com/jobs/ext/2553545-cybersecurity-rmf-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity RMF Specialist - **Company:** Science Applications International Corporation - **Location:** Huntsville, AL, United States - **Contract:** Permanent contract - **Skills:** Collaborative Software, CompTIA Security+, Cyber Security, Linux, Red Hat Enterprise Linux, Software Engineering, Technical Data Management Systems, Software Vulnerability Management, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 21, 2026 - **Apply:** https://dejobs.org/x/x/2C0AB2D851D04D5CA3F6CC5BC5F394D0/job/ ## About the Role * Bachelors and nine (9) years or more experience; Additional six (6) years' experience can be considered in lieu of degree (per contract vehicle). Clearance Requirements: * Must possess an active Secret security clearance; US Citizenship required., * Security Clearance: Must possess an active Secret (or higher) U.S. Government security clearance and be eligible for a SIPRNET account. * Citizenship: Must be a U.S. Citizen. * Certification: Minimum of CompTIA Security+ CE or higher certification compliant with DoD 8570 IAT Level II. * Communication: Excellent written and verbal communication skills, with proficiency in professional correspondence via email and collaboration tools like MS Teams., * Experience: Direct experience with the RMF process and maintaining packages in eMASS. * Technical Skills: Strong familiarity with Linux operating systems (preferably RHEL). * Tools: Hands-on experience with STIGs, STIG Viewers, and ACAS. * Documentation: Proven ability to author and maintain a POA&M and other RMF related artifacts. * Environment: Experience working in a DoD or U.S. Army program environment. ## Description SAIC is seeking a detail-oriented and proactive Cybersecurity Specialist to join our Flight Mission Simulator Digital (FMS/D) program in Huntsville, AL . The successful candidate will be a key contributor to our cybersecurity and compliance efforts, focusing on the documentation and maintenance required to achieve and uphold the system's Authority to Operate (ATO) under the US Army's Risk Management Framework (RMF) process. This role requires close collaboration with technical team members and government cybersecurity officials., Create, maintain, and manage all necessary RMF artifacts. You will be responsible for the continuous upkeep of the system's accreditation package within the Enterprise Mission Assurance Support Service (eMASS) on the SIPRNET. STIG Compliance Complete and maintain Security Technical Implementation Guide (STIG) checklists for both the operating system (OS) and application development. Collaborate with System Administrators and technical leads to document findings and write justifications for risk acceptance on open items. Technical Collaboration Work directly with software developers and system administrators to gather technical data, configurations, and evidence required for the RMF package and STIG compliance. Vulnerability Management Perform regular vulnerability scans of our Red Hat Enterprise Linux (RHEL) based Secure Baseline Operating System Image using the Assured Compliance Assessment Solution (ACAS). Documentation Develop and manage critical cybersecurity documents, including the Plan of Action & Milestones (POA&M), to track and report on vulnerability remediation efforts. Liaison Serve as a key point of contact, providing documentation and status updates upon request to higher-level cybersecurity personnel at the AvMC Systems Simulation, Software and Integration (S3I) directorate. Proactive Support In a dynamic "hurry up and wait" environment, the ideal candidate will identify and address other program needs, proactively taking on tasks to support the broader team during periods of downtime. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)