Cybersecurity Lead, RMF

Posted 5 days ago

This is a fully remote position, open to applicants in Kentucky.

📋 Description

• Oversee security authorization for a cloud-based maintenance management platform.

• Prepare and manage the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and control evidence in collaboration with the Mission Owner and Authorizing Official.

• Implement identity, access, and data controls, including CAC/PIV federation, role separation, audit records, and secrets management.

• Define operational technology (OT) segmentation for sensors, gateways, and building controllers.

• Conduct vulnerability management, continuous monitoring, and necessary incident reporting.

• Maintain evidence in accordance with NIST SP 800-171 and assist with CMMC assessments.

• Provide security awareness training for technicians and administrators.

• Schedule and execute vulnerability scans, ensuring remediation is tracked to completion.

• Review audit logs and security alerts, investigating any suspicious activities.

• Execute security impact analysis for proposed system modifications.

• Travel occasionally to Fort Campbell for authorization meetings and operational technology walkdowns.


⛳️ Requirements

• A minimum of 7 years of cybersecurity experience within the Department of Defense (DoD).

• At least 3 years of experience leading Risk Management Framework (RMF)/Authorization to Operate (ATO) packages (eMASS) through the authorization process.

• Experience in authoring ATO packages that received approval.

• Familiarity with Azure Government or similar cloud security tools.

• Bachelor's degree in Cybersecurity, Information Systems, or a related discipline.

• Possession of CISSP or CISM certification (DoD 8140 IAM Level II/III) is mandatory.

• CompTIA Security+ certification is required as a minimum.

• Must be capable of passing a background check and securing installation access.

• Experience with NIST SP 800-171 and CMMC assessments is preferred.

• Previous involvement with the Army authorization process is a plus.

• Experience in OT/IoT security (NIST SP 800-82) is preferred.

• Familiarity with ACAS/Nessus vulnerability scanning and DISA STIGs is desirable.

• Experience with Security Information and Event Management (SIEM) tools, such as Microsoft Sentinel or Splunk, is preferred.

• Experience with Department of Defense installations, contracts, or programs is advantageous.

• Must be able to lift up to 25 lbs.

• Ability to perform extended periods of desk and computer work.

• Occasional walking through buildings and mechanical spaces during on-site security walkdowns may be required.


🏝️ Benefits

• A drug-free workplace.

• Pre-employment drug screening.

• Random drug screenings during employment.

• Options for remote or office-based work arrangements.

• Availability of full-time and part-time positions.

• Standard Monday–Friday daytime hours.

People also viewed

OpenLoop11 hours ago

Staff Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Funcional Health Tech11 hours ago

Information Security Governance Analyst (Mid-Level)

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Salesforce11 hours ago

Security Architect Lead

US flagArizona, +13 more statesFull-timeCybersecurity / Security Engineer$150.1k – $227k/year
ApplyView job
CNO Financial Group11 hours ago

Lead IT Security Architect – SailPoint

US flagIllinois, +6 more statesFull-timeCybersecurity / Security Engineer$130.5k – $195.7k/year
ApplyView job
GuidePoint Security13 hours ago

Security Architect – AD/Entra ID

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Applied Research Solutions16 hours ago

Information System Security Engineer – ISSE

US flagOhio OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers