×
Register Here to Apply for Jobs or Post Jobs. X

Risk Management Framework (RMF) Specialist

Job in Huntsville, Madison County, Alabama, 35801, USA
Listing for: PeopleTec
Full Time position
Listed on 2026-08-21
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below

Risk Management Framework (RMF) Specialist

People Tec, Inc. is seeking a highly experienced and motivated RMF Specialist to assist with the development, implementation, assessment, and sustainment of RMF packages supporting digital engineering and digital ecosystem initiatives. A successful candidate will provide cybersecurity and RMF expertise, ensure compliance with Department of Defense (DoD) cybersecurity requirements, and lead efforts to achieve and maintain Authority to Operate (ATO) for complex, distributed digital engineering environments.

This position will serve as a cybersecurity advisor to program leadership, engineering teams, system owners, and other stakeholders, providing guidance throughout the RMF lifecycle and helping organizations identify, assess, and mitigate cybersecurity risks. The RMF Specialist will be responsible for coordinating RMF activities across multiple stakeholders and systems while ensuring cybersecurity requirements are effectively incorporated into acquisition, development, testing, and operational activities.

The successful candidate will also provide technical and functional mentorship to junior RMF personnel and contribute to the development and improvement of RMF processes, procedures, and cybersecurity practices across the organization.

Duties:

  • Lead the development, maintenance, review, and delivery of comprehensive RMF documentation, including System Security Plans (SSP), Security Assessment Reports (SAR), Risk Assessment Reports (RAR), Plans of Action and Milestones (POA&M), Policies and Procedures, and associated authorization artifacts.
  • Lead systems through all phases of the RMF lifecycle, from system categorization and control selection through assessment, authorization, continuous monitoring, and reauthorization.
  • Advise system owners, program managers, engineers, cybersecurity personnel, and other stakeholders on the implementation of DoD cybersecurity requirements and RMF best practices.
  • Develop and execute strategies to address security control deficiencies, vulnerabilities, POA&M items, and other cybersecurity risks.
  • Review and analyze vulnerability scan results, STIG assessments, security control assessments, and other cybersecurity assessment data to identify systemic risks and develop appropriate mitigation strategies.
  • Provide oversight of vulnerability management activities, including ACAS/Nessus scanning, STIG compliance, remediation tracking, and security assessment activities.
  • Ensure compliance with applicable DoD cybersecurity policies, including DoDI 8510.01, NIST SP 800-37, NIST SP 800-53, CNSSI guidance, applicable STIGs, and other cybersecurity requirements.
  • Assess cybersecurity risks associated with digital engineering systems, cloud environments, distributed architectures, and developmental and testing environments.
  • Provide cybersecurity guidance during system design, development, integration, acquisition, testing, deployment, and operational activities.
  • Lead the development and validation of risk mitigation strategies and provide recommendations to program leadership regarding residual cybersecurity risk.
  • Identify opportunities to improve RMF processes, standardize documentation, and increase the efficiency and effectiveness of cybersecurity activities across programs.
  • Mentor and provide technical guidance to junior RMF personnel.
  • Represent the cybersecurity/RMF team in technical interchange meetings, program reviews, security assessments, and other stakeholder engagements.
  • Communicate cybersecurity risks, requirements, findings, and recommendations effectively to both technical and non-technical stakeholders.
  • Support cybersecurity continuous monitoring activities and ensure ongoing compliance with authorization requirements.
  • Perform other cybersecurity and RMF-related duties as required.
  • Travel as required (estimated 10%).
Qualifications

Required Skills/Experience:

  • 8-10 years of experience
  • Significant experience developing, implementing, assessing, and maintaining RMF packages within the DoD or federal government environment.
  • Demonstrated experience leading systems through the DoD RMF lifecycle and supporting successful ATO or authorization…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary