Risk Management Framework Specialist

INFORMATION TECHNOLOGY STRATEGIES INCRemote, US,

About The Position

Information Technology Strategies, Inc. is a government IT solutions provider servicing commercial and government initiative in various parts of the United States. We are currently seeking a Risk Management Framework Specialist to work for our company. The client agency is the Defense Logistics Agency. This role serves as a cybersecurity Subject Matter Expert (SME) with regards to Assessment and Authorization (A&A) of information systems and all associated cybersecurity policies and procedures. The specialist will perform a DOD cybersecurity process while either authorizing an information system or serving as a SME for an information system undergoing authorization. A strong understanding of how the security controls identified in the NIST 800-53 apply to the process of assessing and authorizing a large organization’s IT infrastructure such as DLA’s, in which there is a compilation of large and small enclaves, AIS applications and outsourced IT processes, is required. The role involves determining the applicable severity value for an identified vulnerability (e.g., non-compliant security control) and its possible ramifications on the system’s current or future authorization. The specialist will also brief senior management on the progress or results of an information system undergoing the Risk Management Framework (RMF) process.

Requirements

  • Must possess IT-II security clearance or have a current National Agency Check with Local Agency Check and Credit Check (NACLC). (Basic Federal Clearance requirements are U.S. Citizenship, clear criminal history check, no recent or pending bankruptcies)
  • Five (5) years of relevant Risk Management Framework (RMF) and NIST A&A
  • Must have DOD cybersecurity experience
  • Experience in assessing security controls and conducting authorization reviews for large, complex organizations.
  • Experienced in the general tenets supporting the overall DOD implementation of its authorization process, to include supporting cybersecurity policy, procedures, and processes.
  • Knowledgeable in the cybersecurity of emerging technology areas such as Cloud and Industrial Control Systems (ICSs), warehouse execution systems and Operational Technology (OT) infrastructures.
  • Excellent oral and written communication skills.

Nice To Haves

  • Possess an understanding of how the security controls identified in the NIST 800-53 apply to the process of assessing and authorizing a large organization’s IT infrastructure such as DLA’s, in which there is a compilation of large and small enclaves, AIS applications and outsourced IT processes.

Responsibilities

  • Serves as a cybersecurity Subject Matter Expert (SME) with regards to Assessment and Authorization (A&A) of information systems and all associated cybersecurity policies and procedures.
  • Performs a DOD cybersecurity process while either authorizing an information system or serving as a SME for an information system undergoing authorization.
  • Determines the applicable severity value for an identified vulnerability (e.g., non-compliant security control), and determines the possible ramifications on the system’s current or future authorization.
  • Briefs senior management on the progress or results of an information system undergoing the Risk Management Framework (RMF) process.

Benefits

  • Four Medical/Vision options including an HSA plan
  • Dental and Orthodontia plan
  • Vision Materials plan
  • Paid Life, Short-Term Disability, and Long-Term Disability
  • 401K Retirement Program with company contribution
  • Paid Vacation, Holidays, Sick Leave, Floating Holidays, Bereavement Leave
  • Semi-monthly pay cycle
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service