About The Position

This role supports the NUWCDIVNPT in a Mid-Senior Risk Management Framework (RMF) Information Systems Security Engineer (ISSE) capacity. The primary focus is on performing tasks related to Assess and Authorize (A&A) processes to maintain Authorizations to Operate (ATOs) for various systems, including applications, networks, and devices. The position requires a disciplined, structured, and flexible approach to managing security and privacy risks, encompassing information security categorization, control selection, implementation, assessment, system and common control authorizations, and continuous monitoring. The ISSE will become familiar with existing systems by reviewing Assessment and Authorization (A&A) System Security Plans, identifying issues, executing Security Assessment Plans, processing Security Test Reports, reviewing Plans of Action and Milestones (POA&Ms), and performing Risk Assessment analysis. Staying updated on Navy RMF policies and procedures, as well as reviewing relevant DoD, DON, and NAVSEA documentation, is crucial. The role involves conducting independent security control assessments according to NIST SP 800-53, 800-53A, CNSSI 1253, and the RMF framework in NIST SP 800-37. Clear articulation of requirements and information in written documentation such as Security Plans, Contingency Plans, Contingency Plan Tests, and Business Impact Analyses is expected. The ISSE will also provide guidance and training in eMASS to team members and demonstrate strong organizational and time-management skills, including multitasking, working individually and with a team, maintaining a positive attitude, being self-motivated, reliable, trustworthy, and possessing strong interpersonal and diplomatic skills to handle stress professionally. Attending stakeholder meetings, capturing and tracking action items, and following up with stakeholders for timely completion are also key responsibilities.

Requirements

  • Possess and Maintain a Secret Clearance
  • Minimum 6+ years of professional cybersecurity experience and Risk Management Framework
  • Demonstrated expert-level experience with Risk Management Framework
  • Experience in RMF policy development, process improvement, and strategy implementation
  • Demonstrated efficiency and expert-level experience in RMF package development, including POA&Ms (mitigation statements), Security Plans, Risk Assessments, architecture diagrams, asset inventories, and system/site policies, procedures, and processes
  • Must have an 8570.01M IAM/IAT Level II Certificate (Security + at a minimum CAP or CASP /CISSP preferred)
  • Strong National Institute of Standards and Training Special Publications (NIST SPs) knowledge
  • Must be able to manage multiple projects at a time
  • Assessment and Authorization (A&A formerly C&A, i.e. RMF and DIACAP respectively)
  • Experience with ACAS, STIG OSS Manager, STIGViewer, eMASS
  • Knowledge and experience with practices and procedures for CMMI Software Development Level 3 or greater is a plus
  • Knowledge in Continuous Monitoring
  • Excellent customer service and organization skills
  • Excellent oral and written communication skills
  • Demonstrated expert-level experience with DISA STIGs and SRGs

Nice To Haves

  • BS 5-7, MS 3-5, PhD 0-2

Responsibilities

  • Support the NUWCDIVNPT in a Mid-Senior RMF ISSE Role and perform tasks related to Assess and Authorize (A&A) to maintain Authorizations to Operate (ATOs) systems (i.e., applications, networks, devices).
  • Provide a disciplined, structured, and flexible process for managing security and privacy risk that includes information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring.
  • Become familiar with the system/site by reviewing the Assessment and Authorization (A&A) System Security Plan for existing systems; identify any issues with the Security Plan and Procedures; execute the Security Assessment Plan and process Security Test Report; review POA&Ms; develop/perform Risk Assessment analysis.
  • Keep abreast of and provide the team with updated information on Navy RMF policies and procedures. Review DoD, DON, NAVSEA CS-related documentation (i.e., RMF Process Guide, Navy SCA Risk Assessment Guide, DoN Standard Operating Procedures, NAVSEA Business Rules).
  • Be comfortable conducting independent security control assessments in accordance with NIST SP 800-53, 800-53A, CNSSI 1253, and the Risk Management Framework (RMF) described in NIST SP 800-37.
  • Clearly articulate requirements and other information in written documentation such as Security Plan, Contingency Plan, Contingency Plan Test, Business Impact Analysis, etc.
  • Provide guidance and training in eMASS to team members.
  • Demonstrate strong organizational and time-management skills: multitasking, working individually and with a team, having a positive attitude, being self-motivated and reliable, being trustworthy, having strong interpersonal and diplomatic skills, and being able to handle stress in a professional manner.
  • Attend stakeholder meetings, capture and track action items, and follow up with stakeholders to ensure timely completion.

Benefits

  • Health Insurance
  • Life Insurance
  • Paid Time Off
  • Holiday Pay
  • Short Term and Long-Term Disability
  • Retirement and Savings
  • Learning and Development opportunities
  • wellness programs
  • other optional benefit elections
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service