Principal Cyber RMF Engineer

SAICNew York, NY

About The Position

Make a meaningful impact on national security by supporting the Space Development Agency (SDA) in delivering the Battle Management Command, Control, and Communications (BMC3) software development and hosting environment for the National Defense Space Architecture (NDSA). These systems accelerate the secure development, testing, and deployment of mission critical space applications that enable Joint All Domain Command and Control (JADC2).

Requirements

  • Experience with RMF process implementation
  • Experience with system security risk assessments
  • Experience developing and maintaining security documentation (SSPs, SARs, RARs)
  • Experience serving as an ISSO or providing ISSO expertise
  • Knowledge of DoD 8500.01, 8570.01, NIST 800-53
  • Experience with achieving and maintaining Authority to Operate (ATO)
  • Experience addressing Plan of Action and Milestones (POA&M) items
  • Experience conducting security audits and vulnerability assessments
  • Experience with industry-standard security tools
  • Experience facilitating independent verification and validation (IV&V)
  • Experience collaborating with stakeholders
  • Experience providing cybersecurity training and awareness
  • Experience supporting incident response protocols
  • Experience establishing and maintaining continuous monitoring initiatives

Responsibilities

  • Lead the end-to-end RMF lifecycle for DoD IT systems, including categorization, control selection, implementation, assessment, and monitoring.
  • Conduct and oversee system security risk assessments and recommend strategies to mitigate risks effectively.
  • Develop, review, and maintain security documentation such as System Security Plans (SSPs), Security Assessment Reports (SARs), and Risk Assessment Reports (RARs).
  • Serve as the Information System Security Officer (ISSO) or provide subject matter expertise to ISSOs.
  • Ensure compliance with DoD 8500.01, 8570.01, NIST 800-53, and other applicable cybersecurity regulations and standards.
  • Provide guidance for achieving and maintaining Authority to Operate (ATO) and addressing Plan of Action and Milestones (POA&M) items.
  • Conduct security audits and vulnerability assessments, utilizing industry-standard tools to identify and mitigate risks.
  • Facilitate independent verification and validation (IV&V) activities to ensure thorough system testing.
  • Collaborate with stakeholders, including system owners, process owners, and leadership, to ensure compliance with RMF requirements.
  • Provide cybersecurity training, awareness, and mentorship to team members and stakeholders.
  • Support the development and execution of incident response protocols.
  • Establish and maintain continuous monitoring initiatives to detect and address emerging threats.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service