
RMF Assessment & Quality Assurance Lead
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in United States.
• Oversee quality assurance efforts that support the comprehensive Risk Management Framework (RMF) lifecycle.
• Evaluate System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), control implementations, and related authorization documentation for quality, completeness, and consistency.
• Confirm assessment evidence to ensure that security controls are accurately documented and substantiated prior to reviews by Government or independent assessors.
• Facilitate assessment readiness activities among RMF analysts, ISSOs, system owners, security engineers, and technical stakeholders.
• Create and sustain quality review checklists, documentation standards, and procedures for reviewing authorization packages.
• Detect documentation deficiencies, gaps in control implementations, and opportunities for process enhancements ahead of formal assessments.
• Assist in collaboration with independent assessors during Security Control Assessments (SCAs), annual evaluations, and authorization processes.
• Ensure that remediation activities, updates to POA&Ms, and corrective actions are accurately represented within authorization packages.
• Monitor assessment readiness metrics and suggest process improvements that enhance authorization quality and minimize package rework.
• Aid in continuous monitoring by validating ongoing updates to authorization documentation and security evidence.
• Coach RMF analysts and ISSOs on documentation quality, evidence standards, and best practices for authorization.
• Uphold separation of duties by ensuring that personnel involved in package development remain independent from formal assessment activities when necessary.
• Contribute to cybersecurity governance and RMF activities for enterprise information systems at NIH.
• Oversee daily RMF operations, maintain security documentation, support continuous monitoring, track remediation efforts, and ensure compliance with Federal requirements.
• Collaborate with System Owners, engineers, cybersecurity operations personnel, and Government stakeholders to sustain security posture and readiness for authorization.
• Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related field.
• Five or more years of experience in supporting Federal RMF, Assessment and Authorization (A&A), or cybersecurity governance programs.
• Proven experience in reviewing authorization packages for quality, completeness, and adherence to Federal cybersecurity standards.
• In-depth knowledge of NIST RMF, NIST SP 800-37, NIST SP 800-53 Rev. 5, NIST SP 800-53A, and FISMA.
• Experience in supporting Security Control Assessments (SCAs), annual evaluations, continuous monitoring, and ongoing authorization processes.
• Background in coordinating with ISSOs, System Owners, Security Control Assessors, and Authorizing Officials.
• Exceptional analytical, organizational, technical writing, and communication abilities.
• Preferred: Experience supporting NIH, HHS, or other Federal civilian agencies.
• Preferred: Familiarity with using JCAM, eMASS, ServiceNow GRC, or similar governance and compliance platforms.
• Preferred: Experience with High Value Assets (HVAs), cloud authorizations, or enterprise RMF initiatives.
• Preferred: Understanding of FedRAMP, common control inheritance, continuous monitoring, and Federal audit support.
• Preferred: Experience in developing authorization quality standards, review checklists, and documentation templates.
• Preferred certifications: CGRC, CISSP, CAP, CISM, Security+, or PMP.
• Competitive salary, paid bi-monthly.
• Top-tier medical coverage.
• 100% of medical premiums covered by True Zero.
• Company-wide new business incentive programs.
• Contribution Incentives (e.g., white papers, blog posts, internal webinars, etc.).
• 3 weeks of PTO to start, plus 11 paid holidays annually.
• 401k Program with a 100% company match on the first 4%.
• Monthly reimbursement for cell phone and home internet expenses.
• Paternity/Maternity Leave.
• Investment in training and certifications to enhance and deepen your technical skills.
Abhyaz
Commence
Isenberg & Hewitt, P.C.
CCR GROUP
Get handpicked remote jobs straight to your inbox weekly.