> Markdown version of [/jobs/ext/3550592-cybersecurity-lead-rmf-team-lead](https://www.wearedevelopers.com/jobs/ext/3550592-cybersecurity-lead-rmf-team-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Lead / RMF Team Lead - **Company:** ORBIS INC. - **Location:** San Diego, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Systems Engineering, Cyber Security, System Configuration, Identity and Access Management, Network Forensics, Test Data, Navsea, Information Technology, Operational Systems, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 30, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9205343/cybersecurity-lead-rmf-team-lead ## About the Role * Clearance: Must possess an active, TS/SCI and be a United States citizen. * Education: Bachelor's degree in Computer Science, Information Assurance, Cybersecurity, or a related STEM field from an accredited institution. * Experience: A minimum of seven (7) years of experience in cybersecurity, with at least four (4) years directly involved in executing RMF assessments or validations for the DoD. * Certifications (NQV): Must hold a current, active Navy Qualified Validator (NQV) Level III certification and provide formal documentation/appointment letters. * Certifications (DoD 8570): Must maintain an active IAM Level II or Level III baseline certification (e.g., CAP, CASP+ CE, CISM, CISSP). * Deep technical expertise in interpreting vulnerability data, network traffic analysis, and cryptographic implementations. * Proven ability to write comprehensive, technically accurate, and highly detailed risk assessment reports for senior government consumption., * Active Top Secret clearance. * Prior experience validating tactical combat systems, weapons systems, or specialized hull, mechanical, and electrical (HM&E) systems. * Experience participating in Navy Cybersecurity Inspection and Certification Program (CSICP) or Command Cyber Readiness Inspections (CCRI). ## Description Position Overview ORBIS is seeking a Cybersecurity Lead / RMF Team Lead to serve as an independent, third-party assessor for the NSWC Corona CCAM contract. The NQV Level III is a critical oversight role responsible for evaluating the security posture of Navy systems and providing trusted recommendations to the Navy Security Control Assessor (SCA). The successful candidate will ensure that system security controls are implemented correctly and effectively to mitigate risk to Navy operations. Validation & Assessment Responsibilities: * Execute independent, comprehensive assessments of complex IT, PIT, and Operational Technology (OT) systems against DoD, DON, and NAVSEA cybersecurity standards. * Maintain strict separation of duties, ensuring complete independence from the system engineering, ISSM, and ISSO functions during the validation process. * Act as a Trusted Agent to the Navy SCA and SCA Liaison (SCAL), providing objective, risk-based recommendations regarding system authorizations. * Perform detailed reviews of System Security Plans (SSPs), architecture diagrams, data flow diagrams, and hardware/software baselines for accuracy and completeness. * Validate the implementation of NIST 800-53 security controls by reviewing test evidence, interviewing personnel, and directly observing system configurations. * Analyze automated vulnerability scanning results (ACAS), STIG checklists, and manual test data to verify compliance and identify residual risks. * Generate and finalize the Security Assessment Report (SAR) and Risk Assessment Report (RAR), clearly articulating the operational impact of unmitigated vulnerabilities. * Review and validate the accuracy of Plan of Action and Milestones (POA&M) entries, ensuring proposed mitigations are technically sound and appropriately resourced. * Conduct extensive reviews within eMASS, updating the validation status of individual controls and the overall package prior to SCA submission. * Provide continuous feedback and mentorship to ISSMs and ISSOs regarding the quality of package artifacts and the proper interpretation of security controls. * Support continuous monitoring efforts by validating the closure of POA&M items, assessing the impact of system upgrades, and reviewing annual security control assessments. * Maintain active registration on the official Navy Qualified Validators registry and comply with all ongoing training and professional development requirements. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Dirty Tests And How To Clean Them](https://www.wearedevelopers.com/videos/515-dirty-tests-and-how-to-clean-them) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Stop Guessing, Start Measuring: Evaluating RAG Systems with Synthetic Test Data](https://www.wearedevelopers.com/videos/1982-stop-guessing-start-measuring-evaluating-rag-systems-with-synthetic-test-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)