×
Register Here to Apply for Jobs or Post Jobs. X

Risk Management Framework​/Cybersecurity Specialist

Job in Woodlawn, Prince George's County, Maryland, USA
Listing for: 4A Consulting, LLC
Full Time position
Listed on 2026-07-29
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 110000 - 160000 USD Yearly USD 110000.00 160000.00 YEAR
Job Description & How to Apply Below
Position: Risk Management Framework / Cybersecurity Specialist

Company Overview

At 4A Consulting, we turn complexity into opportunity. Founded in 2014 and headquartered in Baltimore, MD, we are a women-owned, boutique consulting firm specializing in delivering innovative, data-driven solutions to both the Federal Government and Fortune 500 clients. Our team blends deep industry knowledge with advanced technologies to design tailored strategies that drive measurable and sustainable outcomes. We pride ourselves on an agile, collaborative approach that helps organizations navigate challenges and seize emerging opportunities in a rapidly evolving digital landscape.

At 4A, we don't just deliver projects, we build trusted partnerships that empower our clients to lead with confidence in the digital age.

Company Overview

At 4A Consulting, we turn complexity into opportunity. Founded in 2014 and headquartered in Baltimore, MD, we are a women-owned, boutique consulting firm specializing in delivering innovative, data-driven solutions to both the Federal Government and Fortune 500 clients. Our team blends deep industry knowledge with advanced technologies to design tailored strategies that drive measurable and sustainable outcomes. We pride ourselves on an agile, collaborative approach that helps organizations navigate challenges and seize emerging opportunities in a rapidly evolving digital landscape.

At 4A, we don't just deliver projects, we build trusted partnerships that empower our clients to lead with confidence in the digital age.

Position Overview

We are seeking a Risk Management Framework / Cybersecurity Specialist to provide end-to-end Risk Management Framework (RMF) documentation and Authorization to Operate (ATO) support. In this role, you will work closely with Information System Security Officers (ISSOs), technical teams, and agency stakeholders using automated Security Authorization & Assessment (SA&A) tools to guide information systems through all seven steps of the NIST RMF lifecycle.

Key Responsibilities
  • RMF & ATO Lifecycle Support
  • Assist in establishing the framework for RMF implementation, identifying key stakeholders, defining boundary scopes, and conducting operational guidance/training.
  • Guide stakeholders in classifying information systems and data types based on functionality, sensitivity, and organizational impact.
  • Help select baseline security controls from NIST SP 800-53 and establish appropriate common control inheritance tailored to system boundaries.
  • Support control implementation; assist ISSOs and stakeholders in establishing SI-2 (Flaw Remediation) and RA-5 (Vulnerability Monitoring and Scanning) reports for each system boundary.
  • Provide support during Targeted Control Assessments and Continuous Monitoring Assessments, aiding ISSOs and stakeholders in collecting, organizing, and validating assessment artifacts.
  • Review Security Assessment Reports (SARs), analyze residual risks, and recommend technical/operational mitigations to support executive ATO decisions.
  • Drive continuous monitoring efforts across system life cycles:
  • Facilitate Plan of Actions and Milestones (POA&M) remediation with technical teams to mitigate audit findings and vulnerabilities, while tracking and reporting status to supervisors and ISSOs.
  • Conduct semi-annual Quality Assurance (QA) reviews of assigned security boundaries and present findings to system leadership.
  • Documentation & Stakeholder Management
  • Independently author, review, and maintain System Security Plans (SSPs) and associated SA&A artifacts with minimal oversight.
  • Gather security requirements, evaluate incoming requests, and interface effectively across agency SMEs, customers, and leadership.
  • Lead stakeholder meetings, interviews, and working sessions independently.
Required Qualifications
  • Master's with 5+ years, Bachelor's 7+ years, or 13+ years of relevant experience.
  • Deep, practical knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 controls, with direct experience conducting Security Control Assessments.
  • Strong working knowledge of federal cybersecurity directives, including FISMA, FedRAMP, OMB Circulars, NIST standards, and HIPAA.
  • Hands-on experience navigating RMF-related Security Authorization & Assessment (SA&A) tools (e.g., Service Now, eMASS, CSAM, or equivalent GRC platforms).
  • Demonstrated track record of managing POA&Ms through remediation and working with vulnerability scanning/reporting datasets (SI-2/RA-5).
  • Proficient with Microsoft Office 365 applications (Word, Excel, PowerPoint, Teams, SharePoint).
  • Exceptional written and verbal communication skills with a proven ability to explain technical risk to diverse audiences and build consensus among stakeholders.
Preferred Qualifications
  • The ideal candidate brings deep technical knowledge of NIST SP 800-37 and 800-53, hands-on experience with vulnerability reporting and POA&M remediation, and the ability to operate independently with minimal oversight.

Applicants must be legally authorized to work in the United States.

Why Join 4A
  • Be part of a mission-driven, women-owned consulting…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary