Senior Information Systems Security Engineer - RMF

WIDER SECURITY, LLC
Newport, RI, United States
23 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$80,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Security Management Network Diagrams Package Development Process Security Content Automation Protocol Software Vulnerability Management Information Technology Operational Systems

Job description

  • Lead RMF cybersecurity engineering efforts for Navy combat systems and combat system trainers
  • Develop, update, and maintain RMF packages in support of system authorization and sustainment activities
  • Interpret and apply DoD and Department of the Navy cybersecurity policies, guidance, and control requirements to system environments
  • Support the implementation, inheritance, assessment, and documentation of security controls in accordance with NIST 800-53, DoD policy, and Navy-specific requirements
  • Coordinate with system engineers, program offices, ISSMs, ISSOs, validators, and government stakeholders to support authorization decisions and package development
  • Prepare and maintain cybersecurity documentation including system descriptions, control implementation statements, network diagrams, hardware and software inventories, architecture artifacts, POA&Ms, and supporting evidence
  • Support vulnerability management efforts, including identification, tracking, remediation coordination, and risk documentation
  • Review system configurations, technical baselines, and architecture details to ensure alignment with cybersecurity and RMF requirements
  • Assist with security testing, control validation, assessment support, and remediation planning
  • Provide expert guidance on cybersecurity requirements for Platform IT and mission-focused Navy systems
  • Support package submission and maintenance activities in eMASS or other applicable Navy RMF tracking tools
  • Provide clear written and verbal communication to customers and internal leadership regarding compliance status, risks, and recommended actions
  • Mentor junior cybersecurity personnel and contribute to the overall technical quality of RMF efforts

Requirements

Wider Security is seeking an experienced Senior RMF Information System Security Engineer (ISSE) to support cybersecurity efforts for U.S. Navy combat systems and combat system trainers. This role is ideal for a senior-level cybersecurity professional with strong experience applying the Risk Management Framework (RMF) in Navy environments, particularly in support of operational technologies, mission systems, and Platform IT.

The Senior RMF ISSE will provide subject matter expertise in the development, maintenance, and assessment of RMF packages for complex Navy systems. The position requires close coordination with government stakeholders, system engineers, cybersecurity personnel, and technical teams to ensure systems are authorized, compliant, and aligned with Navy cybersecurity requirements throughout the system lifecycle.

The ideal candidate will have deep knowledge of Navy cybersecurity processes, hands-on experience supporting combat systems or training systems, and the ability to work effectively in highly technical and compliance-driven environments. This role is well suited for someone who can operate independently, lead cybersecurity efforts, and provide trusted guidance to both customers and internal teams., * Active Secret security clearance or higher

  • Significant professional experience in RMF, cybersecurity engineering, or information system security engineering
  • Familiarity with eMASS, STIGs, SCAP, ACAS, and Navy cybersecurity workflows
  • Experience supporting U.S. Navy systems, ideally including combat systems, combat system trainers, or other mission-critical operational systems
  • Strong working knowledge of the DoD Risk Management Framework (RMF) and associated cybersecurity documentation requirements
  • Experience developing, reviewing, or maintaining RMF packages for complex systems
  • Familiarity with NIST SP 800-53, DoDI 8510.01, and related DoD cybersecurity guidance
  • Experience working with technical teams to assess architectures, identify compliance gaps, and support remediation
  • Strong understanding of system security principles, vulnerability management, and compliance documentation
  • Excellent written and verbal communication skills
  • Ability to work independently in customer-facing environments and support multiple priorities

Preferred

  • Experience with Navy RMF processes for Platform IT systems
  • Knowledge of Navy acquisition, engineering, or lifecycle support environments
  • Relevant certifications such as CISSP, CASP+, Security+, CISM, GSLC, or similar cybersecurity credentials

What we’re looking for

  • A senior professional with strong judgment and the ability to lead cybersecurity efforts with minimal oversight
  • Someone who can translate technical system details into clear RMF documentation and actionable compliance guidance
  • A detail-oriented and highly organized individual who thrives in structured, high-accountability environments
  • A collaborative team member who can work effectively with engineers, program stakeholders, and government customers
  • A mission-focused cybersecurity professional committed to high-quality execution in support of Navy operational readiness

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

41 sec

Introducing the blockchain operating system as a platform layer

Andrej Šarić · World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:13 min

Differentiating standalone automotive operating systems from projected mobile experiences

Stephan Schuster · World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all