RMF & ISSM Support Specialist - JOMIS
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Sentar is proud to be an employee-owned company, fostering a culture of empowerment, collaboration, and innovation. Sentar is dedicated to developing the critical talent that the connected world demands to create solutions to address the convergence of cybersecurity, intelligence, analytics, and systems engineering. We invite you to join the team where you can build, innovate, and secure your career.
Sentar is seeking a RMF & ISSM Support Specialist that sits REMOTELY!
Role DescriptionThe Defense Health Agency (DHA) supports the delivery of integrated, affordable, and high- quality health services to Military Health System (MHS) beneficiaries and is responsible for driving greater integration of clinical and business processes across the MHS. Our DHA teams make a difference daily by ensuring the security of the health records of active duty and retired military and their families!
The Defense Health Cyber Risk Management Team requires a RMF & ISSM Support Specialist to provide key services to a government client. This individual will be responsible for assigned Information Systems Security Manager (ISSM) efforts to complete RMF packages (Security Plans, Annual Security Reviews, Authorizations, POA&Ms, etc.), conduct continuous monitoring of assigned systems, and provide relevant cyber security expertise to ongoing programmatic lines of effort.
This position for JOMIS Cyber Support, Risk Management Executive Division (RMED) supported by the Defense Health Agency (DHA). The RMF & ISSM Support SME navigates and coordinates workflow, activity, and documentation necessary to achieve successful RMF objectives for DHA medical devices and systems.
DutiesCloud & Application Security Engineering
- Architect and implement secure, zero trust, defense-in-depth solutions across infrastructure, platform, and application layers for cloud-hosted and DDIL environments;
- Develop and enforce cloud security baselines and automated policy guardrails using IaC tools (Terraform, Ansible, AWS Config Rules, Azure Policy);
- Engineer IAM solutions including RBAC, ABAC, MFA, least-privilege, and PAM across cloud and application environments;
- Secure containerized workloads (Kubernetes/Open Shift) including pod security policies, network policies, secrets management, and runtime threat detection (Falco, Prisma Cloud/Twistlock);
- Embed security into CI/CD pipelines per the DoD Dev Sec Ops Reference Design, automating SAST, DAST, SCA, container image scanning, and STIG compliance validation;
- Integrate application security across the SDLC including secure code review, SAST, DAST, SCA, and API security testing;
- Design and implement cloud-native SIEM/monitoring capabilities (AWS Security Hub, Cloud Trail, Azure Sentinel) supporting continuous monitoring and RMF compliance;
- Implement data protection strategies including encryption at rest/in transit and cryptographic key management (AWS KMS, Azure Key Vault);
- Lead threat modeling and security architecture reviews for new and evolving JOMIS capabilities;
- Evaluate and harden DDIL/edge security configurations for disconnected and bandwidth-constrained operational environments;
- Execute end-to-end RMF authorization activities including SSP development, SCAs, POA&M management, and ATO package maintenance in eMASS, CMRS, COAMS, and Phoenix;
- Apply NIST SP 800-53 controls, DISA STIGs/SRGs, and DoD/DHA IA requirements to assess, document, and remediate system security posture;
- Conduct vulnerability analysis using ACAS/Nessus, STIG Viewer, and SCAP; analyze HBSS/ESS output and configurations; perform root cause analysis on cybersecurity shortfalls;
- Review and validate authorization boundary diagrams, architecture/data flow diagrams, hardware/software inventories, IP/subnet assignments, and Med-COI Zone taxonomy artifacts;
- Serve as senior technical security advisor to program leadership, IPTs, and government stakeholders through engineering review boards and architecture working groups;
- Coordinate with ISSMs, system/network administrators, software engineers, and CIOs to validate and document control implementation;
- Submit Weekly Status Reports (WSRs) and lead/attend stakeholder meetings on RMF and security engineering status;
- 6-8+ years of hands-on cybersecurity engineering experience in DoD or Federal environments, with demonstrated depth across RMF.
- RMF/Compliance:
Hands-on eMASS experience; proven ability to develop and manage ATO packages, SSPs, SCAs, and POA&Ms;…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).