
Cybersecurity Lead, RMF
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in Kentucky.
• Oversee security authorization for a cloud-based maintenance management platform.
• Prepare and manage the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and control evidence in collaboration with the Mission Owner and Authorizing Official.
• Implement identity, access, and data controls, including CAC/PIV federation, role separation, audit records, and secrets management.
• Define operational technology (OT) segmentation for sensors, gateways, and building controllers.
• Conduct vulnerability management, continuous monitoring, and necessary incident reporting.
• Maintain evidence in accordance with NIST SP 800-171 and assist with CMMC assessments.
• Provide security awareness training for technicians and administrators.
• Schedule and execute vulnerability scans, ensuring remediation is tracked to completion.
• Review audit logs and security alerts, investigating any suspicious activities.
• Execute security impact analysis for proposed system modifications.
• Travel occasionally to Fort Campbell for authorization meetings and operational technology walkdowns.
• A minimum of 7 years of cybersecurity experience within the Department of Defense (DoD).
• At least 3 years of experience leading Risk Management Framework (RMF)/Authorization to Operate (ATO) packages (eMASS) through the authorization process.
• Experience in authoring ATO packages that received approval.
• Familiarity with Azure Government or similar cloud security tools.
• Bachelor's degree in Cybersecurity, Information Systems, or a related discipline.
• Possession of CISSP or CISM certification (DoD 8140 IAM Level II/III) is mandatory.
• CompTIA Security+ certification is required as a minimum.
• Must be capable of passing a background check and securing installation access.
• Experience with NIST SP 800-171 and CMMC assessments is preferred.
• Previous involvement with the Army authorization process is a plus.
• Experience in OT/IoT security (NIST SP 800-82) is preferred.
• Familiarity with ACAS/Nessus vulnerability scanning and DISA STIGs is desirable.
• Experience with Security Information and Event Management (SIEM) tools, such as Microsoft Sentinel or Splunk, is preferred.
• Experience with Department of Defense installations, contracts, or programs is advantageous.
• Must be able to lift up to 25 lbs.
• Ability to perform extended periods of desk and computer work.
• Occasional walking through buildings and mechanical spaces during on-site security walkdowns may be required.
• A drug-free workplace.
• Pre-employment drug screening.
• Random drug screenings during employment.
• Options for remote or office-based work arrangements.
• Availability of full-time and part-time positions.
• Standard Monday–Friday daytime hours.
OpenLoop
Funcional Health Tech
Salesforce
CNO Financial Group
Get handpicked remote jobs straight to your inbox weekly.