Cybersecurity Principal Specialist - GRC #542
Listed on 2026-08-14
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Target Hiring Range: $145,000 - $165,000
Department: Chief Information Officer Posting Date Range: 8/7/2026-8/21/2026 Pay Grade Range: $130469-$181570
Work
Hours: 8:30 a.m.
- 5:30 p.m.
FLSA Status: Exempt
Work Location Status: Hybrid
Hybrid
Schedule:
2-3 days a week onsite
All remote or hybrid work arrangements must be performed from within the continental United States, subject to Sergeant at Arms approval.
The Senate Sergeant at Arms does not pay for relocation expenses.
This vacancy announcement closes at 11:59pm EST. Late applications will not be accepted.
Job Overview
The Target Hiring Range for this position is: $145,000 - $165,000
Cybersecurity Principal Specialist – Cybersecurity Senior Risk Management Framework (RMF) Technical Lead
Department: Cybersecurity Information Assurance Branch, Governance Risk and Compliance Team
About Us
The Sergeant at Arms plays a crucial role in upholding the operational integrity of the Senate community. Our vision is to foster an environment of innovation, collaboration, and adaptability, ensuring uninterrupted legislative proceedings irrespective of time, place, or circumstance. The Cybersecurity department is responsible for protecting the systems and information used to create the legislation that underwrites our democracy. We create a resilient cybersecurity operation by pro-actively identifying, protecting, detecting, reacting, and recovering (IPDRR) the US Senate enterprise.
We combine people, processes, and technology into a state of the art, continuous risk-reduction practice that is flexible, innovative, and effective.
Role Overview
The Cybersecurity RMF Technical Lead will serve within the Governance, Risk, and Compliance team of the Information Assurance Branch. In this technical leadership role, you will guide the modernization and day-to-day execution of a Senate-specific Risk Management Framework program aligned with NIST guidance and tailored to the Senate mission environment.
You will provide technical direction to RMF and policy professionals, advise system owners and cybersecurity teams, improve assessment and authorization processes, and help translate complex security findings into clear, actionable risk decisions. This role is ideal for a hands-on RMF leader who can pair deep technical judgment with strong communication, process discipline, and a customer-focused approach.
Key Responsibilities
As Risk Management Framework Technical Lead, your role is crucial in protecting our organization’s digital assets and supporting our cybersecurity initiatives. Your key responsibilities include:
- Serve as the technical lead for the Senate RMF program, including assessment and authorization (A&A), security control assessment, risk determination, authorization support, and continuous monitoring activities.
- Serve as a technical resource and subject matter expert for RMF and policy staff, providing guidance, quality review, and mentorship without formal supervisory authority.
- Modernize and mature a Senate-tailored RMF program that aligns with NIST RMF principles, NIST SP 800-53 controls, Senate-specific requirements, and evolving cybersecurity priorities.
- Lead the development, review, and improvement of RMF artifacts, including system security plans, security assessment reports, plans of action and milestones (POA&Ms), risk registers, authorization packages, and continuous monitoring deliverables.
- Partner with system owners, technical teams, assessors, and leadership to identify risk, evaluate compensating controls, recommend mitigation strategies, and support risk acceptance decisions.
- Develop data-driven metrics, dashboards, workflows, and reporting methods that improve RMF visibility, support prioritization, and measure program effectiveness.
- Analyze threats, vulnerabilities, control gaps, and cyber hygiene trends to support proactive risk management across Senate systems and networks.
- Communicate non-compliance, risk findings, mitigation options, and RMF decisions clearly to technical and non-technical audiences, including senior leadership.
- Collaborate with internal and external experts to ensure RMF content, policy, assessment methods, and reporting practices…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).