Risk Management Framework (RMF) Specialist

Posted 10 Days Ago
Be an Early Applicant
5 Locations
In-Office
Senior level
Information Technology • Security
The Role
Oversee RMF implementation and cybersecurity compliance for Air Force information systems. Conduct security control assessments, risk analyses, continuous monitoring, audits, and vulnerability assessments. Prepare SSPs, POA&Ms, and risk reports while collaborating with system owners, developers, and stakeholders. Ensure alignment with DoD, Air Force, and NIST policies, standards, and regulations. The role requires DoD RMF experience, relevant cybersecurity certifications, proficiency with eMASS and vulnerability assessment tools, and eligibility for a Top Secret/SCI clearance.
Summary Generated by Built In
Overview

Seeking a dedicated and experienced Risk Management Framework (RMF) Specialist to oversee and manage cybersecurity processes, ensuring compliance with DoD and Air Force policies. The RMF Specialist will play a critical role in safeguarding the Air Force’s information systems by identifying, assessing, and mitigating security risks. This position requires a deep understanding of the RMF lifecycle and its application in a military context.


Work Environment:

  • Location:  Scott Air Force Base - Belleville, IL (This is not a remote position)
  • Security Clearance: Must possess or be able to obtain and maintain a Top Secret/SCI clearance.
  • Travel < 20% of the time

NV5 is a global technology solutions and consulting services company with a workforce of over 4,500 professionals in more than 100 offices worldwide.  NV5’s continued growth has been spurred through strategic investments in firms with unique capabilities to help current and future customers solve the world’s toughest problems.  The NV5 family brings together talent across a wide range of markets and fields, including Professional Engineers, Professional Land Surveyors, Architects, Photogrammetrists, GIS Professionals, Software Developers, IT, Project Management Professionals, and more.


At NV5 Geospatial, we are a collaboration of intelligent, innovative thinkers who care for each other, our communities, and the environment.  We value both heart and head, the diversity of our people, and their experiences because that is how we continue to grow as a leader in our industry and expand our individual and collective potential.

Responsibilities
  • RMF Implementation: Lead the implementation of the Risk Management Framework (RMF) for Air Force information systems, ensuring compliance with DoD and Air Force cybersecurity policies.
  • Security Control Assessment: Conduct security control assessments and validate the effectiveness of implemented controls for information systems.
  • Risk Analysis: Perform risk assessments to identify vulnerabilities, threats, and risks to information systems, and recommend appropriate mitigation strategies.
  • Documentation: Prepare and maintain RMF documentation, including System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and Risk Assessment Reports.
  • Continuous Monitoring: Implement and manage continuous monitoring strategies to ensure ongoing assessment and authorization of information systems.
  • Collaboration: Work closely with system owners, developers, and other stakeholders to ensure security requirements are integrated throughout the system development lifecycle.
  • Audit Support: Support internal and external audits, reviews, and inspections related to information system security.
  • Policy and Compliance: Ensure alignment with current Air Force cybersecurity policies, standards, and regulations, and recommend updates to cybersecurity policies as needed.
Qualifications

Requirements

  • Education: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
  • Experience: Minimum of 5 years of experience in cybersecurity, with at least 3 years specializing in RMF processes and DoD information systems.
  • Certifications: Must possess or be willing to obtain relevant cybersecurity certifications such as Certified Information Systems Security Professional (CISSP), Certified Authorization Professional (CAP), or equivalent.
  • Security Clearance: Ability to obtain and maintain a Top Secret/SCI security clearance.
  • Technical Skills: Proficiency in RMF tools and technologies, such as eMASS (Enterprise Mission Assurance Support Service) and vulnerability assessment tools (e.g., Nessus, ACAS, SCAP).
  • Knowledge: In-depth knowledge of NIST Special Publications (SP) 800-37, 800-53, and 800-171, as well as DoD Instruction 8510.01 and related guidelines.
  • Communication: Strong verbal and written communication skills, with the ability to effectively convey complex cybersecurity concepts to both technical and non-technical audiences.
  • Analytical Skills: Excellent analytical and problem-solving skills, with a keen attention to detail and a proactive approach to identifying and addressing security risks.

Competencies & Skills

  • Strong problem-solving skills and the ability to troubleshoot database issues effectively.
  • Excellent communication and collaboration skills for cross-team efforts.

Employment is contingent upon successful completion of a background check and drug screening.


NV5 offers a competitive compensation and benefits package including medical, dental, life insurance, FTO, 401(k) and professional development/advancement opportunities.


NV5 provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. NV5 complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.


#LI-Onsite

#LI-JG1



Skills Required

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field
  • At least 5 years of cybersecurity experience
  • At least 3 years specializing in RMF processes and DoD information systems
  • Possess or be willing to obtain CISSP, CAP, or an equivalent cybersecurity certification
  • Ability to obtain and maintain a Top Secret/SCI security clearance
  • Proficiency with RMF tools such as eMASS and vulnerability assessment tools including Nessus, ACAS, or SCAP
  • In-depth knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-171, and DoD Instruction 8510.01
  • Strong verbal and written communication skills
  • Excellent analytical and problem-solving skills with attention to detail
  • Ability to troubleshoot database issues effectively
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Pittsburgh, PA
1,800 Employees

What We Do

The Sextant Group is an information technology company providing AV, IT, security, and acoustics solutions.

Similar Jobs

STR Logo STR

Chief Strategist (TL1)

Machine Learning • Security • Software • Analytics • Defense
Easy Apply
In-Office
Melbourne, FL, USA
800 Employees
250K-350K Annually

ServiceNow Logo ServiceNow

Director, TA Infrastructure

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
West Palm Beach, FL, USA
29000 Employees

Agero Logo Agero

Product Manager

Automotive • Big Data • Insurance • Software • Transportation
Easy Apply
Remote or Hybrid
14 Locations
1600 Employees
80K-108K Annually

Samsara Logo Samsara

Scientist

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
179K-319K Annually

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account