×
Register Here to Apply for Jobs or Post Jobs. X

RMF Security SME

Job in Bloomington, McLean County, Illinois, 61791, USA
Listing for: Steampunk
Full Time position
Listed on 2026-09-17
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Systems Engineer
Salary/Wage Range or Industry Benchmark: 130000 - 180000 USD Yearly USD 130000.00 180000.00 YEAR
Job Description & How to Apply Below

Overview

We are seeking an RMF Security SME to help modernize our security posture by shifting from manual compliance to automated control implementation and continuous monitoring. This role bridges deep knowledge of the Risk Management Framework (RMF) and security controls with hands-on cloud and Dev Sec Ops  engineering, working alongside engineers, data scientists, designers, and analysts to build secure, usable, and auditable systems.

Contributions
  • Serve as the RMF subject matter expert, interpreting NIST SP 800-53 controls and mapping technical and operational requirements to automated implementation and continuous monitoring
  • Design and implement control automation pipelines that convert manual compliance activities (control implementation, evidence collection, continuous monitoring) into repeatable, automated processes using infrastructure as code and compliance-as-code approaches (e.g., OSCAL)
  • Identify and drive implementation of controls around secure cloud-based solutions, including zero-trust architecture components, identity and access management (IAM) policy, and data privacy controls
  • Partner with stakeholders to balance security requirements with usability, translating RMF and compliance requirements into practical technical solutions
  • Review infrastructure as code authored by others to assess control coverage, security risk, and compliance impact
  • Conduct risk assessments and control assessments to ensure systems meet NIST, FISMA, and other applicable compliance frameworks
  • Recommend solutions for automating security processes such as vulnerability management, patch management, and control monitoring/reporting
  • Collaborate with software developers and Dev Sec Ops  engineers to embed security controls and RMF requirements into the SDLC and CI/CD pipeline
  • Support control mapping design and implementation of data protection and encryption for data at rest and in transit
  • Document the as-is control environment, perform gap analyses against RMF/NIST baselines, and produce artifacts articulating remediation options and recommendations
  • Drive automation for core RMF Processes & generation of A&A documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and control assessment artifacts.
  • Identify, analyze, and resolve infrastructure vulnerabilities and application deployment issues affecting control compliance
  • Engineer solutions and recommend continuous improvements to control automation and security operations
  • Present regular status updates and provide cross-training to team members on RMF processes and control automation practices
Qualifications
  • Ability to obtain a U.S. government Security Clearance
  • One of the following, based on education level: no degree with 9 years of relevant experience, a Bachelor's degree with 5 years of relevant experience, or a Master's degree with 3 years of relevant experience
  • Experience architecting, designing, developing, and implementing cloud solutions
  • Experience with one or more cloud platforms (AWS, Azure, or GCP)
  • 5 years of experience conducting monitoring, risk assessment, threat modeling, and security testing in cloud environments
  • 5 years of experience applying the Risk Management Framework (RMF), including documenting POA&Ms, SSPs, and Assessment & Authorization (A&A) support documentation
  • Demonstrated understanding of NIST 800-53 (or equivalent) security controls and experience translating control requirements into technical and operational implementations
  • At least one active, relevant professional certification tied to the cloud/security technology being deployed or maintained (e.g., AWS Certified Security Specialty, AWS Certified Solutions Architect Associate, Microsoft Certified Azure Administrator Associate, CISSP, or CAP), subject to program manager approval

Preferred:

  • Additional certifications beyond the one required above
  • Experience with compliance automation platforms and standards such as OSCAL, eMASS, Xacta, or CSAM
  • Experience automating control assessment, continuous monitoring (Con Mon), and A&A documentation workflows
  • Excellent written and verbal communication, interpersonal, and collaborative skills
  • Experience documenting as-is environment states, performing gap analyses, and producing options/recommendation artifacts
About steampunk

Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary