Risk Management Framework (RMF) Support/Senior
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Smyrna, GA, USA
Job DescriptionKoniag IT Systems, LLC, a Koniag Government Services company, is seeking a Risk Management Framework (RMF) Support/Senior with a Secret security clearance to support KITS and our government customer in Smyrna, GA. This position is for a Future New Business Opportunity.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
Koniag IT Systems, a Koniag Government Services company, is seeking an experienced Risk Management Framework (RMF) Support/Senior professional to serve as the RMF Lead supporting our government customer. The ideal candidate is a seasoned cybersecurity professional with deep expertise in the RMF process, security control assessments, and risk management within federal government environments. The successful candidate will perform dual functions as both a Team Lead and Senior Functional Expert, serving as the single point of contact for government stakeholders on all RMF-related activities.
An active ADP-II/Secret clearance is required for this position.
The RMF Support/Senior will serve as the RMF Lead, integrating security and risk management activities into the system development life cycle while applying a risk-based approach to security control selection and specification.
Principal responsibilities will include but are not limited to:
- Serve as the RMF Lead and primary single point of contact for the Government Task Monitor (GTM) and the Assessment & Authorization (A&A) government lead.
- Perform dual functions as Team Lead and Senior Functional Expert, providing guidance, oversight, and expertise to team members supporting RMF activities.
- Conduct and oversee all activities that integrate security and risk management into the system development life cycle (SDLC), ensuring alignment with applicable laws, directives, Executive Orders, policies, standards, and regulations.
- Apply a risk-based approach to security control selection and specification, considering effectiveness, efficiency, and applicable constraints.
- Lead and perform security control assessments and residual risk determinations across all steps of the RMF process.
- Oversee the preparation, review, and maintenance of A&A documentation packages, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports.
- Coordinate with system owners, information system security officers (ISSOs), and other stakeholders to ensure continuous monitoring and compliance with security requirements.
- Provide expert guidance on RMF process steps including Categorize, Select, Implement, Assess, Authorize, and Monitor.
- Identify and communicate security risks, recommend mitigation strategies, and support the development of risk acceptance decisions.
- Ensure compliance with most current DoW guidance and other applicable federal cybersecurity frameworks and directives.
- Mentor and provide technical direction to junior team members engaged in RMF and A&A activities.
Education and Experience :
Required:
- Bachelor's Degree with an emphasis in Information Technology Security, Cybersecurity, or a related field from an accredited college or university. Extensive experience in the required discipline may serve as a substitution for the Bachelor's Degree requirement.
- Minimum of 7 years of experience in the certification and accreditation process of Information Systems within the U.S. Federal Government.
- Without a Bachelor's Degree, a minimum of 10+ years of experience in the certification and accreditation process of Information Systems within the U.S. Federal Government is required.
- Certified in accordance with most current DoW guidance as an IAM Level III.
Required Skills and
Competencies:
- Exceptional communication skills in English – both written and oral – with the ability to effectively communicate complex security and risk concepts to both technical and non-technical stakeholders.
- In-depth knowledge and expertise across all steps of the RMF process as defined by NIST SP 800-37 and related publications.
- Extensive experience conducting security control assessments and residual risk determinations.
- Strong knowledge of NIST Special Publications, including SP 800-53, SP 800-53A, SP 800-30, and SP 800-137.
- Experience preparing and reviewing A&A documentation packages including SSPs, SARs, POA&Ms, and Risk Assessment…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).