RMF Cybersecurity Engineer II
Listed on 2026-01-30
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security, Network Security
Overview
Data Intelligence, LLC (DI) is searching for a full time RMF Specialist to support a DoD Navy effort in Dam Neck, VA through RMF, cybersecurity engineering, and Assessment & Authorization activities. The role will support mission-critical systems and candidates must possess hands-on experience with RMF, vulnerability management, and continuous monitoring. This is an on-site position in Dam Neck, VA, and requires a current, active security clearance as well as an active IAM II (or higher) certification.
Responsibilities- Cybersecurity Engineering
- Perform technical planning and systems engineering to ensure information assurance (IA) compliance and strong cyber posture across confidentiality, integrity, availability, authentication, and non-repudiation
- Conduct ACAS vulnerability scans and STIG compliance assessments on standalone and networked systems
- Execute SCAP scans to support automated STIG validation and compliance reporting
- Apply operating system and application patches, perform software upgrades, and conduct regression testing to ensure system integrity
- Provide day-to-day cybersecurity operations and maintenance support, including server, network, and policy enforcement activities
- Deliver technical and analytical cybersecurity recommendations to engineering and program teams
- Identify and report cybersecurity policy violations to the ISSM and program leadership
- Track security baselines and participate in Configuration Control Board (CCB) meetings related to infrastructure and network changes
- Develop and maintain cybersecurity documentation supporting system operations, maintenance, and issue resolution
- Create, update, and manage POA&M entries based on ACAS, SCAP, and STIG artifacts to support continuous monitoring
- Cybersecurity Assessment & Authorization (A&A / RMF)
- Support RMF Assessment & Authorization activities in an ISSO/ISSE capacity in accordance with Department of the Navy policies and instructions
- Perform RMF Step 5 authorization support and RMF Step 6 continuous monitoring activities
- Support efforts for ATO package development and validation as applicable
- Conduct annual security reviews and annual security control testing
- Manage POA&M tracking, vulnerability remediation, and risk mitigation activities
- Plan and execute cybersecurity testing to assess and document security control effectiveness
- Evaluate the quality and completeness of security control implementations against RMF requirements
- Perform ongoing vulnerability and compliance scanning in support of continuous monitoring
- Test & Evaluation (T&E) Support
- Support Developmental Test & Evaluation (DT&E), Operational Test & Evaluation (OT&E), penetration testing, and tabletop exercises
- Assist with technical and management processes supporting operational verification, installation testing, and system readiness
- Provide cybersecurity support to test events and evaluation activities across the system lifecycle
Required Skills/
Experience:
- Minimum of five (5) years of full-time professional experience performing Risk Management Framework (RMF) activities
- Active, current security clearance that is at least secret level
- Demonstrated experience with:
- STIG assessments (manual and automated, including SCAP benchmarks)
- ACAS vulnerability scanning
- eMASS utilization and workflow execution
- POA&M development and management
- RMF Step 5 authorization activities in an ISSE capacity
- Bachelor’s Degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information Systems, Information Technology, Computer Engineering, Electrical or Electronics Engineering, Software Engineering, Computer Science, Mathematics with a concentration in Computer Science, or a closely related discipline
- Active IAM Level II (or higher) certification (CAP, Security
X [formerly CASP], CISM, CISSP, GSLC, CCISO, or HCISPP)
Salary Range
: $85,000/year-$90,000/year
Data Intelligence, LLC (DI) is a small business that provides Information Technology System Development (Agile, Dev Sec Ops , Cloud Platform support) Cybersecurity (RMF, Security Engineering, Cross Domain Solutions), Tactical Data Link Standards Development and Testing, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).