About The Position

This position supports the NUWCDIVNPT in a Junior-Mid Risk Management Framework (RMF) Information Systems Security Engineer (ISSE) role. The primary focus is on performing tasks related to Assess and Authorize (A&A) to maintain Authorizations to Operate (ATOs) for systems, including applications, networks, and devices. The role involves providing a disciplined, structured, and flexible process for managing security and privacy risk, encompassing information security categorization, control selection, implementation, and assessment, system and common control authorizations, and continuous monitoring. The ISSE will become familiar with systems by reviewing Assessment and Authorization (A&A) System Security Plans, identifying issues, executing Security Assessment Plans, processing Security Test Reports, reviewing POA&Ms, and developing/performing Risk Assessment analysis. The role requires staying updated on Navy RMF policies and procedures and reviewing relevant DoD, DON, and NAVSEA CS-related documentation. The ISSE will conduct independent security control assessments according to NIST SP 800-53, 800-53A, CNSSI 1253, and the RMF framework in NIST SP 800-37. Clear articulation of requirements in written documentation such as Security Plans, Contingency Plans, Business Impact Analyses, etc., is essential. Guidance and training in eMASS will be provided to team members. Strong organizational and time-management skills, including multitasking, working individually and with a team, maintaining a positive attitude, being self-motivated, reliable, trustworthy, and possessing strong interpersonal and diplomatic skills, are crucial. The role also involves attending stakeholder meetings, capturing and tracking action items, and ensuring timely completion.

Requirements

  • BS 2-4, MS 0-2
  • Minimum 2+ years of professional cybersecurity experience and Risk Management Framework
  • Demonstrated expert-level experience with Risk Management Framework
  • Experience in RMF policy development, process improvement, and strategy implementation
  • Demonstrated efficiency and expert-level experience in RMF package development, including POA&Ms (mitigation statements), Security Plans, Risk Assessments, architecture diagrams, asset inventories, and system/site policies, procedures, and processes
  • Must have an 8570.01M IAM/IAT Level II Certificate (Security + at a minimum CAP or CASP /CISSP preferred)
  • Knowledge National Institute of Standards and Training Special Publications (NIST SPs) knowledge
  • Must be able to manage multiple projects at a time
  • Assessment and Authorization (A&A formerly C&A, i.e. RMF and DIACAP respectively)
  • Experience with ACAS, STIG OSS Manager, STIGViewer, eMASS
  • Knowledge and experience with practices and procedures for CMMI Software Development Level 3 or greater is a plus
  • Knowledge in Continuous Monitoring
  • Excellent customer service and organization skills
  • Excellent oral and written communication skills
  • Demonstrated expert-level experience with DISA STIGs and SRGs
  • Position requires U.S. Citizenship
  • Possess and Maintain an active Secret security clearance

Nice To Haves

  • CMMI Software Development Level 3 or greater

Responsibilities

  • Provide a disciplined, structured, and flexible process for managing security and privacy risk that includes information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring.
  • Become familiar with the system/site by reviewing the Assessment and Authorization (A&A) System Security Plan for existing systems; identify any issues with the Security Plan and Procedures; execute the Security Assessment Plan and process Security Test Report; review POA&Ms; develop/perform Risk Assessment analysis.
  • Keep abreast of and provide the team updated information on Navy RMF policies and procedures. Review DoD, DON, NAVSEA CS-related documentation (i.e., RMF Process Guide, Navy SCA Risk Assessment Guide, DoN Standard Operating Procedures, NAVSEA Business Rules).
  • Be comfortable conducting independent security control assessments in accordance with NIST SP 800-53, 800-53A, CNSSI 1253, and the Risk Management Framework (RMF) described in NIST SP 800-37.
  • Clearly articulate requirements and other information in written documentation such as Security Plan, Contingency Plan, Contingency Plan Test, Business Impact Analysis, etc.
  • Provide guidance and training in eMASS to team members.
  • Demonstrate strong organizational and time-management skills: multitasking, working individually and with a team, having a positive attitude, being self-motivated and reliable, being trustworthy, having strong interpersonal and diplomatic skills, and being able to handle stress in a professional manner.
  • Attend stakeholder meetings, capture and track action items, and follow up with stakeholders to ensure timely completion.

Benefits

  • Health Insurance
  • Life Insurance
  • Paid Time Off
  • Holiday Pay
  • Short Term and Long-Term Disability
  • Retirement and Savings
  • Learning and Development opportunities
  • wellness programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service