Cybersecurity Lead / RMF Team Lead

ORBIS INC.
San Diego, CA, United States
4 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Systems Engineering Cyber Security System Configuration Identity and Access Management Network Forensics Test Data Navsea Information Technology Operational Systems Plan of Action and Milestones Vulnerability Analysis

Job description

Position Overview ORBIS is seeking a Cybersecurity Lead / RMF Team Lead to serve as an independent, third-party assessor for the NSWC Corona CCAM contract. The NQV Level III is a critical oversight role responsible for evaluating the security posture of Navy systems and providing trusted recommendations to the Navy Security Control Assessor (SCA). The successful candidate will ensure that system security controls are implemented correctly and effectively to mitigate risk to Navy operations.

Validation & Assessment Responsibilities:

  • Execute independent, comprehensive assessments of complex IT, PIT, and Operational Technology (OT) systems against DoD, DON, and NAVSEA cybersecurity standards.
  • Maintain strict separation of duties, ensuring complete independence from the system engineering, ISSM, and ISSO functions during the validation process.
  • Act as a Trusted Agent to the Navy SCA and SCA Liaison (SCAL), providing objective, risk-based recommendations regarding system authorizations.
  • Perform detailed reviews of System Security Plans (SSPs), architecture diagrams, data flow diagrams, and hardware/software baselines for accuracy and completeness.
  • Validate the implementation of NIST 800-53 security controls by reviewing test evidence, interviewing personnel, and directly observing system configurations.
  • Analyze automated vulnerability scanning results (ACAS), STIG checklists, and manual test data to verify compliance and identify residual risks.
  • Generate and finalize the Security Assessment Report (SAR) and Risk Assessment Report (RAR), clearly articulating the operational impact of unmitigated vulnerabilities.
  • Review and validate the accuracy of Plan of Action and Milestones (POA&M) entries, ensuring proposed mitigations are technically sound and appropriately resourced.
  • Conduct extensive reviews within eMASS, updating the validation status of individual controls and the overall package prior to SCA submission.
  • Provide continuous feedback and mentorship to ISSMs and ISSOs regarding the quality of package artifacts and the proper interpretation of security controls.
  • Support continuous monitoring efforts by validating the closure of POA&M items, assessing the impact of system upgrades, and reviewing annual security control assessments.
  • Maintain active registration on the official Navy Qualified Validators registry and comply with all ongoing training and professional development requirements.

Requirements

  • Clearance: Must possess an active, TS/SCI and be a United States citizen.
  • Education: Bachelor’s degree in Computer Science, Information Assurance, Cybersecurity, or a related STEM field from an accredited institution.
  • Experience: A minimum of seven (7) years of experience in cybersecurity, with at least four (4) years directly involved in executing RMF assessments or validations for the DoD.
  • Certifications (NQV): Must hold a current, active Navy Qualified Validator (NQV) Level III certification and provide formal documentation/appointment letters.
  • Certifications (DoD 8570): Must maintain an active IAM Level II or Level III baseline certification (e.g., CAP, CASP+ CE, CISM, CISSP).
  • Deep technical expertise in interpreting vulnerability data, network traffic analysis, and cryptographic implementations.
  • Proven ability to write comprehensive, technically accurate, and highly detailed risk assessment reports for senior government consumption., * Active Top Secret clearance.
  • Prior experience validating tactical combat systems, weapons systems, or specialized hull, mechanical, and electrical (HM&E) systems.
  • Experience participating in Navy Cybersecurity Inspection and Certification Program (CSICP) or Command Cyber Readiness Inspections (CCRI).

Benefits & conditions

ORBIS offers an excellent benefits package and a competitive salary in a professional atmosphere.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:14 min

Establishing stable test environments and required test data

Augustin Gottlieb Augustin Gottlieb · World Congress 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:13 min

Reusing state configuration with the test data builder

Erick Wendel · World Congress 2023

Videos

See all

Related articles

See all