Lead and advise teams through the full NIST Risk Management Framework (RMF) lifecycle—Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor—embedding security and privacy into the system development life cycle (SDLC). Serve as the go-to Subject Matter Expert (SME) on RMF concepts, requirements, and agency-specific adaptations of RMF (e.g., organization RMF process guides), ensuring stakeholders understand expectations and decision points. Develop, review, and maintain RMF artifacts and authorization package documentation, including (as applicable): System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms), along with supporting evidence. Coordinate and/or perform security control assessment activities (management, operational, and technical controls), evaluate control effectiveness, document weaknesses, and recommend remediation actions aligned to assessment results. Partner with system owners, engineers, ISSOs/ISSMs, assessors, and governance stakeholders to define authorization boundaries, identify inheritable controls, and drive readiness for Authorization to Operate (ATO) decisions. Track remediation and risk posture over time, supporting continuous monitoring activities, ongoing updates to security documentation, and leadership reporting for risk-based decisions. Maintain RMF records in approved repositories and GRC tooling (e.g., eMASS) and ensure documentation quality, consistency, and audit readiness. Facilitate working sessions and communicate clearly with both technical and non-technical audiences—translating controls and compliance language into actionable engineering and operational steps.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
5,001-10,000 employees