RMF Engineer

Innovatus Technology ConsultingSuffolk, VA
Hybrid

About The Position

Innovatus is seeking an experienced Risk Management Framework (RMF) Engineer to support Assessment & Authorization (A&A) activities for DoD systems in accordance with NIST and DoD RMF requirements. The role focuses on developing, maintaining, and managing RMF documentation and artifacts throughout the system lifecycle. This is a hybrid position that is mostly remote, with candidates based in the San Diego, CA or Norfolk/Suffolk, VA areas preferred to support occasional on-site collaboration, meetings, or program needs.

Requirements

  • Active DoD Secret security clearance (minimum).
  • U.S. citizenship.
  • 3+ years of hands-on experience supporting DoD RMF processes and A&A activities.
  • Proven experience developing RMF artifacts (SSPs, CPs, control evidence, test plans, POA&Ms, etc.).
  • Strong familiarity with NIST SP 800-53, RMF steps (per NIST SP 800-37 / DoDI 8510.01), and authorization workflows.
  • Experience with eMASS (or similar authorization management systems) for package management and artifact validation.
  • Ability to work independently in a mostly remote environment while collaborating effectively with distributed teams.
  • Strong written and verbal communication skills for technical documentation and stakeholder interaction.

Nice To Haves

  • Experience supporting Navy, NAVWAR, or other DoD component systems.
  • Familiarity with additional tools such as ACAS, Nessus, or STIG Viewer.
  • Relevant certifications (e.g., CAP, Security+, CISSP, CISM, or DoD 8570/8140 IAM Level I/II).
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).

Responsibilities

  • Support system categorization by identifying information types, system boundaries, and information flows.
  • Develop, update, and maintain RMF artifacts, including System Security Plans (SSPs), Contingency Plans (CPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Continuous Monitoring Strategies, and supporting diagrams.
  • Assess and evaluate implemented security controls; identify gaps and work with engineering and cybersecurity teams on remediation.
  • Manage and validate RMF packages in eMASS (or equivalent DoD tools), including uploading artifacts and tracking authorization status.
  • Support continuous monitoring, ATO package preparation, and authorization/renewal processes.
  • Collaborate with system engineers, ISSOs/ISSMs, Security Control Assessors, Authorizing Officials, and government stakeholders.
  • Provide guidance on NIST SP 800-53 controls, DoD cybersecurity policies, STIGs, and RMF best practices.
  • Contribute to risk assessments, vulnerability management coordination, and compliance documentation as needed.

Benefits

  • Competitive salary and benefits package.
  • Mostly remote hybrid flexibility with work-life balance.
  • Opportunity to support high-impact DoD missions.
  • Professional growth in a mission-driven, veteran-friendly SDVOSB environment.
  • Collaborative culture focused on ethics, expertise, and results.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service