> Markdown version of [/jobs/ext/2572423-rmf-security-engineer](https://www.wearedevelopers.com/jobs/ext/2572423-rmf-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF Security Engineer - **Company:** Leidos, Inc. - **Location:** San Diego, CA, United States - **Experience:** Expert - **Salary:** $131,300.0 - $237,350.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Artificial Intelligence, Software System Penetration Testing, Bash Shell, Cyber Security, Information Systems, Python (Programming Language), Windows PowerShell, ArcSight SIEM Tool, Zero Trust Network Access, Security Content Automation Protocol, Security Information and Event Management, TypeScript, Rust (Programming Language), Information Technology, Nessus, Splunk, Plan of Action and Milestones, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 31, 2026 - **Apply:** https://www.dice.com/job-detail/5490aad6-d9a5-45c2-83bd-6b1bfe91a853 ## About the Role * Bachelor's degree in Cybersecurity, Information Assurance, Computer Science or related field. BS with 12+ years' experience or MS with 10+ years' experience. Will consider work experience in lieu of a degree. * DoD 8570 approved security certification (i.e., Security +) (Will be required 90 days after hire). * Position requires ship and an active Secret DoD security clearance. * RMF Compliance Expertise: Deep knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-171, FedRAMP, and DoD Instruction 8510.01 (DIARMF)., * At least one for automation: Python, Javascript, Typescript, Bash, Rust, PowerShell * Experience leveraging AI agentic workflows that incorporate with the NIST RMF to analyze one or more code bases to provide security compliance coverage and mitigate vulnerabilities per the applicable 800-53 STIG and SRG requirements. * Zero Trust Integration: Understanding NIST SP 800-207 (Zero Trust Architecture) and how it intersects with RMF. * CMMC 2.0. * COMSEC Understanding * CISSP Certification * Experience with log/SIEM and health monitoring tools (e.g., Splunk, ArcSight). Experience with High Assurance / Type 1 security evaluation processes If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares. ## Description Leidos is seeking a Sr. Risk Management Framework (RMF) Security Engineer to support a project at a Navy base in San Diego. This position will play a critical role in ensuring that information systems comply with federal cybersecurity standards, particularly within the U.S. Department of Defense (DoD) cyber community. The RMF Security Engineer will guide the project through the RMF lifecycle, which includes categorizing information systems based on risk, selecting and implementing appropriate security controls (per NIST SP 800-53 or DoD-specific requirements), and assessing those controls for effectiveness. The RMF Security Engineer will conduct continuous monitoring, identify vulnerabilities, address compliance gaps, recommend useful vulnerability mitigations, and ensure systems remain secure against evolving threats. The RMF Security Engineer will act as a technical advisor and problem solver, bridging the gap between cybersecurity policy and system implementation. Will perform risk assessments, analyze security test results, and recommend mitigation strategies to address findings, whether through configuration changes, tool updates, or process improvements. This position is 100% on site at the Navy base., * Experience preparing System Security Plans (SSP), Security Assessment Reports (SAR), and Plan of Action & Milestones (POA&M). * Conducting risk assessments, vulnerability scans, and penetration testing. * eMASS (Enterprise Mission Assurance Support Service) * SCAP tools (e.g., Nessus, Tenable.sc, OpenSCAP). * STIG compliance (DISA STIGs, SCAP benchmarks) * Find and address vulnerabilities in code base using: + SAST tools - identify and verify structural flaws + DAST tools - identify and verify runtime and environment misconfigurations with running code ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)