The Role
Lead implementation of RMF A&A activities, perform risk and vulnerability assessments, manage PKI/accounts/ACLs, ensure STIG and DoD cloud compliance, maintain classified material and clearance databases, produce security engineering artifacts, support eMASS and acquisition security, and deliver security training and stakeholder coordination to achieve authorization and continuous compliance.
Summary Generated by Built In
Expertise and Functions
- Assist in the development of security documentation including System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, and other required system security engineering artifacts.
- Support RMF Authorization and Accreditation (A&A) activities, ensuring compliance with DoD and Air Force cybersecurity policies.
- Manage system user accounts, ports/protocols, PKI requirements, and access control lists.
- Implement and track system security updates, configurations, and vulnerability remediation in accordance with DoD requirements.
- Conduct risk and vulnerability assessments; recommend security policies, contingency plans, and disaster recovery procedures.
- Participate in system/network design to ensure alignment with security policies.
- Provide leadership in analyzing and integrating cybersecurity requirements into system design and operations.
- Review and assess the implementation of RMF security controls across system architecture, documentation, and design artifacts.
- Collaborate with stakeholders to ensure RMF A&A approval by all Authorizing Officials.
- Maintain and audit databases for classified information, visits, and clearances.
- Support classified material handling, accountability, and compliance with security classification guides.
- Develop and deliver security awareness training and education programs.
- Prepare and review acquisition security documentation and ensure compliance with CDRLs.
- Plan and implement security-related surveys, assessments, and evaluations throughout the program life cycle.
- Other duties as assigned
RequirementsEducation/Training:
- Bachelor’s Degree preferred
- Security +
- 7+ years of experience in a related field required
- 3+ years working in the DoD sector
- Understanding of cybersecurity in DoD cloud infrastructure.
- Knowledge of Agile methodologies including CI/CD, DevSecOps, and DevOps.
- Experience with systems analysis and eMASS
- Strong ability to communicate technical topics effectively in both written and verbal forms
- STIG compliance
- Risk Management Framework (RMF) implementation and documentation.
- DoD cybersecurity policies and compliance.
- System Authorization and Accreditation (A&A) processes.
- DoD cloud infrastructure security.
- Agile development methods including CI/CD, DevSecOps, and DevOps.
- Security risk, vulnerability, and contingency planning.
- PKI management and access control.
- Classified material handling and accountability.
- Strong verbal and written communication skills for both technical and non-technical audiences.
- Ability to collaborate with government, contractor, and industry stakeholders.
- Effective problem-solving and analytical thinking.
- Ability to work independently and manage multiple priorities in a fast-paced environment.
- Adaptability to evolving program requirements and security challenges.
- Must be a US citizen
- Must have an active Secret clearance
- Able to occasionally reach with hands and arms
- Prolonged periods of computer screen use, while sitting or standing at a desk
- Adhere to safety protocols when in work areas requiring use of PPE (e.g. eyewear, gloves, masks, hearing protection, steel toed shoes, etc.)
- Able to safely lift and carry up to 20 pounds at a time
Benefits
- Health Care Plan (Medical, Dental & Vision)
- Retirement Plan (401k, IRA)
- Life Insurance (Basic, Voluntary & AD&D)
- Paid Time Off (Vacation, Sick & Public Holidays)
- Short Term & Long Term Disability
- Training & Development
- Wellness Resources
Salary:
The projected salary range for this position is $125,000 - $148,000. This is not a guarantee of compensation, rather actual salary will be based on experience, qualifications, and applicable certifications or degrees held. Offered salary may fall outside of this range.
Skills Required
- 7+ years of related experience
- 3+ years working in the DoD sector
- Active Secret security clearance
- Must be a US citizen
- Experience with RMF implementation and documentation
- Experience with eMASS
- STIG compliance experience
- Understanding of DoD cloud infrastructure security
- PKI management and access control expertise
- Experience conducting risk, vulnerability, and contingency planning
- Knowledge of System Authorization and Accreditation (A&A) processes
- Knowledge of DoD cybersecurity policies and compliance
- Knowledge of Agile methodologies including CI/CD, DevSecOps, and DevOps
- Experience with systems analysis
- Strong written and verbal communication skills
- Ability to collaborate with government, contractor, and industry stakeholders
- Ability to work independently and manage multiple priorities
- Adaptability to evolving program requirements and security challenges
- Security+ certification
- Bachelor's Degree
- Ability to lift and carry up to 20 pounds and adhere to PPE safety protocols
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
KIHOMAC is an aerospace and defense acquisition and technology company. Founded in 2003, KIHOMAC is a Veteran-Owned Small Business that provides system acquisition and life cycle management support to government agencies.







