TDI is seeking a Risk Management Framework (RMF) subject matter experts as Information Systems Security Managers to support cloud-based and Artificial Intelligence (AI) integrated systems. We are looking for candidates who have demonstrated experience building and maintaining RMF packages from development and through sustainment, are technically sharp, and ready to work in a fast-paced environment on some of the nations most advanced systems. We need experts who can support ATO efforts and turn DoW Component RMF, NIST 800-53, and Cloud SRG guidance into clear, defensible deliverables. These roles require in-depth knowledge of DoW requirements and the ability to independently lead and support complex systems integrating cloud IaaS/SaaS, custom applications and AI. if you’re eager to build credibility fast, experience cutting edge technology, leading artificial intelligence models, and make a visible impact on mission systems—including cloud-native, containerized workloads—you’ll fit right in.
We have multiple openings supporting U.S. Navy and U.S. Marine Corps programs in the Northern Virginia area. Opportunities are available for both fully onsite and remote work, depending on skill set and security clearance level. Candidates must possess an active Secret or Top-Secret security clearance.
- Lead and support RMF execution and customer coordination.
- Provide expert guidance on DoW cloud security policies, NIST SP 800-53 controls, CNSS policies, and DoW-specific frameworks such as Cloud Computing SRG and AI-specific guidance.
- Conduct security architecture reviews and security engineering analysis for cloud-native and containerized workloads.
- Evaluate security controls associated with Kubernetes, Docker, and container orchestration platforms within cloud infrastructure.
- Assess security risks related to generative AI components, including large language models (LLMs) and AI/ML workloads, ensuring responsible and compliant use.
- Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action and Milestones (POA&Ms), and related RMF documentation.
- Perform threat modeling, vulnerability assessments, and risk analysis tailored to cloud environments and AI technologies.
- Interface with system architects, developers, and DevSecOps teams to integrate security throughout the Software Development Lifecycle (SDLC).
- Support security control assessments (SCAs) and coordinate with third-party assessors.
- Monitor, track, and report on security compliance posture through Continuous Monitoring (ConMon) processes.
- Minimal travel will be required.
- Active Secret or Top-secret security clearance.
- Bachelor’s degree in Cybersecurity, Computer Science, or Information Technology, and 8+ years of cybersecurity experience, including demonstrated experience supporting Risk Management Framework (RMF) activities for Department of War (DoW) systems.
- Security certifications such as Certified Information System Security Professional (CISSP) and/or Certified Information System Manager (CISM).
- Practical knowledge and application of concepts with cloud platforms. Experience with AWS, Azure and/or Google Cloud Platform (GCP), including IAM, VPC, Kubernetes, and security-related services are preferable.
- Strong knowledge of containerized environments (e.g., Docker, Kubernetes) and container security best practices.
- Familiarity with Generative AI technologies, including LLMs and AI/ML security considerations.
- Deep understanding of NIST SP 800-53, DoD RMF, FedRAMP, and other relevant cybersecurity frameworks.
- Experience with security risk assessments in DoW environments.
The anticipated salary range for this position is $150,000 - $200,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range.
Skills Required
- Active Secret or Top-Secret security clearance
- Bachelor's degree in Cybersecurity, Computer Science, or Information Technology
- 8+ years of cybersecurity experience including RMF activities for DoD systems
- Experience building and maintaining RMF packages and supporting ATO efforts
- CISSP or CISM security certification
- Deep understanding of NIST SP 800-53, DoD RMF, FedRAMP, and Cloud SRG
- Strong knowledge of containerized environments and container security best practices (Docker, Kubernetes)
- Practical knowledge of cloud platforms (AWS, Azure, GCP) including IAM, VPC, Kubernetes and security services
- Familiarity with Generative AI technologies, LLMs and AI/ML security considerations
- Experience performing security risk assessments in DoD environments
What We Do
For over 20 years, TDI’s one and only passion has been delivering cybersecurity solutions to effectively manage the business of cyber. At the global vanguard of innovation, we created Cybersecurity Performance Management (CPM) and the industry-leading CPM platform, CnSight®. Combining CnSight® with our remarkable historical experience and our exceptional capabilities of cyber operations and compliance, we offer Managed Cybersecurity Performance, a first of its kind managed CPM offering. TDI’s CPM solutions mitigate risk, reduce ransomware, provide continuous compliance, improve cyber-ROI, and provide comprehensive instantaneous visibility into how an organization is performing against its cyber strategy, particularly for Boards of Directors. CnSight® is the industry-leading Cybersecurity Performance Management (CPM) platform which mitigates risk, reduces ransomware, provides continuous compliance, improves cyber-ROI, and provides comprehensive instantaneous visibility into how an organization is performing against its cyber strategy, so executives and Boards may effectively manage the business of cybersecurity– the result: reduced stress, better performance, less cost, and a true understanding of cyber investment. With CnSight® at its core, TDI’s Managed Cybersecurity Performance offering ensures strategic cyber goals are met to protect an organization’s investments, assets and reputation by reducing the risk of ransomware, lowering cyber insurance premiums, improving ROI, reducing legal and fiduciary liability, delivering actionable reporting to the Board and C-Suite, providing on-call advice, ensuring continuous compliance and providing subject matter expertise on the organization’s behalf in meeting with the C-Suite and the Board, dealing with auditors, and supporting budget decisions – the result: reduced stress, better performance, less cost, and a true understanding of cyber investment.









