RMF Validator

KBRColumbia, WA
Onsite

About The Position

KBR’s Product and Technology Solutions Division specializes in rapid prototyping and advanced technology solutions for directed energy, electronic warfare, and security applications. With expertise in electronic warfare systems, critical infrastructure protection, and product R&D, KBR delivers cutting-edge innovations to meet mission-critical needs. Backed by a global presence and a strong ethical framework, KBR collaborates closely with customers to develop secure, effective, and forward-thinking solutions. KBR is currently seeking multiple Validators who will provide support to the Naval Research Laboratory located in Washington, DC in accordance with the Navy RPG and NAVWAR Risk Assessment for the following activities: documentation, and artifacts in support of obtaining ATO from the appropriate AO.

Requirements

  • Must be a U.S. citizen.
  • Must possess or have previously possessed DoD SECRET security clearance or higher.
  • BS/BA degree.
  • 10+ (Ten) years of directly related experience.
  • In lieu of degree 8 years additional related work experience.
  • Experience with Risk Management Framework (RMF) and tools like eMASS (Enterprise Mission Assurance Support Service).
  • Prior professional cybersecurity experience.
  • Experience with cybersecurity for cloud environments.
  • General National Institute of Standards and Training Special Publications (NIST SPs) knowledge.
  • Assessment and Authorization (A&A formerly C&A, i.e. RMF and DIACAP respectively) knowledge.

Nice To Haves

  • Knowledge of the Defense Information Systems Agency's Security Technical Implementation Guides (STIGs) is beneficial.
  • Prior experience with IT/OT systems is preferred.
  • A DoD 8570.01-M IAM/IAT Level III certification
  • Security+ certification
  • Certified Authorization Professional (CAP)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Advanced Security Practitioner (CASP)
  • Navy Qualified Validator (NQV) certification a plus.

Responsibilities

  • Conduct independent security control assessments according to NIST standards.
  • Review all RMF documentation, including but not limited to the System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M) to ensure that documentation aligns with NRL, Navy, and DoD cybersecurity policies, procedures, and standards.
  • Validate the accuracy, completeness, and consistency of all system documentation.
  • Conduct independent validation of RMF controls for information systems and networks per the Navy RMF Process Guide.
  • Verify that all security controls have been correctly implemented and are functioning as intended.
  • Ensure the system's security posture is adequately documented, and all relevant artifacts are available for review by the Navy Authorizing Official (NAO)/Functional Authorizing Official (FAO) as appropriate.
  • Conduct thorough assessments of security controls based on criteria set forth in NIST SP 800-53, CNSSI 1253, and other applicable Navy and DoD cybersecurity frameworks.
  • Perform technical validation of implemented controls, including but not limited to vulnerability scanning, configuration assessments, and security testing.
  • Analyze findings to determine potential impacts and likelihoods, contributing to a risk-based decision-making process.
  • Identify, categorize, and document cybersecurity risks, vulnerabilities, and deficiencies discovered during the validation process.
  • Provide comprehensive risk assessments that include severity ratings, likelihood determinations, and potential impact assessments.
  • Recommend actionable and prioritized remediation strategies or compensating controls to address identified risks.
  • Support Annual Security Review (ASR) activities per the Navy SCA Risk Assessment Guide.
  • Validate and assess a subset of the security controls per the system’s approved System Level Continuous Monitoring (SLCM) Strategy.
  • Serve as Functional Security Control Assessor (FSCA) Liaison as needed to review validations and support the FSCA in their duties to include but not limited to reviewing Validator generated SARs, drafting SAR Executive summaries, and reviewing and grading Validator assessments.
  • Ensure all FSCA assessment documentation are aligned with Validator findings and the overall cybersecurity posture of the system.
  • Ensure that independent validation efforts adhere to the Navy SCA Risk Assessment Guide and assess the quality of assessment documentation to include but not limited to the SSP, SAP, Security Test Report and the SAR.
  • Provide subject matter expertise and support to the FSCA in conducting assessments, validating security controls, and addressing deficiencies or gaps identified during the RMF process.

Benefits

  • 401K plan with company match
  • medical
  • dental
  • vision
  • life insurance
  • AD&D
  • flexible spending account
  • disability
  • paid time off
  • flexible work schedule
  • professional training and development
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service