Principal Cyber RMF Engineer
SAIC · California, United States · Yesterday
Engineering$120k–$160k/yrFull-time
Key Responsibilities
- Lead the end-to-end RMF lifecycle for DoD IT systems, including categorization, control selection, implementation, assessment, and monitoring.
- Conduct and oversee system security risk assessments and recommend strategies to mitigate risks effectively.
- Develop, review, and maintain security documentation such as System Security Plans (SSPs), Security Assessment Reports (SARs), and Risk Assessment Reports (RARs).
- Serve as the Information System Security Officer (ISSO) or provide subject matter expertise to ISSOs.
Compliance and Policy Adherence
- Ensure compliance with DoD 8500.01, 8570.01, NIST 800-53, and other applicable cybersecurity regulations and standards.
- Provide guidance for achieving and maintaining Authority to Operate (ATO) and addressing Plan of Action and Milestones (POA&M) items.
Audit and Assessment
- Conduct security audits and vulnerability assessments, utilizing industry-standard tools to identify and mitigate risks.
- Facilitate independent verification and validation (IV&V) activities to ensure thorough system testing.
Collaboration and Stakeholder Engagement
- Collaborate with stakeholders, including system owners, process owners, and leadership, to ensure compliance with RMF requirements.
- Provide cybersecurity training, awareness, and mentorship to team members and stakeholders.
Incident Response & Continuous Monitoring
- Support the development and execution of incident response protocols.
- Establish and maintain continuous monitoring initiatives to detect and address emerging threats.
Qualifications
- Required Skills and Qualifications:
- Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related field (equivalent experience may be considered).
- Certifications: Must have a DoD 8570.01 certification at IAM Level II or III (e.g., CISSP, CISM, CAP, CISA, CASP+ CE, GSLC).
- Experience: Minimum 9 years of experience in cybersecurity, with at least 3 years of hands-on RMF implementation and oversight for a DoD system.
- Clearance: Active Secret Clearance required at the time of hire; ability to obtain Top Secret/SCI may be preferred.
- Technical Proficiency: Extensive experience with security tools (e.g., ACAS, eMASS, STIG/SRGs). Strong knowledge of cloud, system administration, and vulnerability analysis. Expertise in applying NIST 800-53 security controls to federal systems and addressing weaknesses.
- Skills: Strong analytical, problem-solving, and organizational skills. Excellent verbal and written communication skills.
- Preferred Qualifications:
- Master’s degree in a related field.
- Knowledge of cloud technologies and their associated cybersecurity risks.
- Familiarity with A&A tools and platforms used by the DoD for RMF processes.
Target salary range
$120,001 - $160,000.