
Information Assurance, RMF Compliance Specialist
Posted Aug 8

Posted Aug 8
This is a fully remote position, open to applicants in United States.
• Create, revise, and uphold AMASS Information Assurance policies and Standard Operating Procedures that align with RMF and DoD/Federal mandates.
• Revise and sustain the AMASS System Security Plan and Implementation Plan within eMASS.
• Maintain RMF compliance documentation, including inventories, PPSM Bulk Upload files, STIG checklists, network diagrams, and other necessary materials.
• Assist with DoD RMF continuous monitoring and update annual testing results in eMASS.
• Aid in IA compliance status reporting to government stakeholders.
• Help migrate the myAuth RMF control baseline from NIST SP 800-63 Rev. 4 to Rev. 5.
• Support alignment with new IA requirements, including FedRAMP where relevant.
• Assist with the myAuth cyber hardening application release approval process using Fortify Software Security Center to generate and monitor POA&Ms and findings.
• Work collaboratively with cross-functional teams to ensure consistent application of IA and cybersecurity standards.
• A minimum of 8 years of experience with a BS/BA; at least 6 years with an MS/MA; or a minimum of 3 years with a PhD.
• Current IT3 background investigation required.
• Secret clearance necessary.
• U.S. Citizenship is mandatory.
• Possession of at least one certification: CISSP, SSCP, CySA+, or CASP+.
• Proven technical writing experience with strong skills in technical documentation.
• Hands-on experience with eMASS, including artifact management and Implementation Plans.
• Experience in performing RMF requirements analysis.
• Familiarity with applying STIGs to web applications, databases, operating systems, and network devices.
• Experience in supporting incident response processes.
• Background in supporting cloud security compliance within a DoD setting.
• Strong comprehension of information system and network design principles.
• Solid understanding of DoD application cyber hardening processes and static code analysis concepts.
• Preferred: experience supporting DMDC or similar DoD enterprise systems.
• Preferred: knowledge of large-scale identity and access management environments.
• Preferred: experience with POA&M Management, Security Assessment Reports, and Continuous Authorization (cATO).
• Preferred: involvement with FedRAMP compliance activities.
• Fully remote position.
• Employees may qualify for overtime pay.
• Employees may be eligible for shift differentials.
• Employees may receive a discretionary bonus in addition to their base salary.
• Equal opportunity employer, including individuals with disabilities and protected veterans.
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.