Jobs · Florida

Risk Management Framework (RMF) Specialist

NV5 · Tampa, FL · 1 wk ago
HybridFull-time

Seeking a dedicated and experienced Risk Management Framework (RMF) Specialist to oversee and manage cybersecurity processes, ensuring compliance with DoD and Air Force policies. The RMF Specialist will play a critical role in safeguarding the Air Force’s information systems by identifying, assessing, and mitigating security risks.

About the Role

Work Environment: Location: Tampa, FL - Must be within commutable distance to MacDill AFB

Responsibilities

  • Lead the implementation of the Risk Management Framework (RMF) for Air Force information systems, ensuring compliance with DoD and Air Force cybersecurity policies.
  • Conduct security control assessments and validate the effectiveness of implemented controls for information systems.
  • Perform risk assessments to identify vulnerabilities, threats, and risks to information systems, and recommend appropriate mitigation strategies.
  • Prepare and maintain RMF documentation, including System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and Risk Assessment Reports.
  • Implement and manage continuous monitoring strategies to ensure ongoing assessment and authorization of information systems.
  • Work closely with system owners, developers, and other stakeholders to ensure security requirements are integrated throughout the system development lifecycle.
  • Support internal and external audits, reviews, and inspections related to information system security.
  • Ensure alignment with current Air Force cybersecurity policies, standards, and regulations, and recommend updates to cybersecurity policies as needed.

Requirements

  • Qualifications:
    • Education: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
    • Experience: Minimum of 5 years of experience in cybersecurity, with at least 3 years specializing in RMF processes and DoD information systems.
  • Certifications:
    • Must possess or be willing to obtain relevant cybersecurity certifications such as Certified Information Systems Security Professional (CISSP), Certified Authorization Professional (CAP), or equivalent.
  • Security Clearance:
    • Ability to obtain and maintain a Top Secret/SCI security clearance.
  • Technical Skills:
    • Proficiency in RMF tools and technologies, such as eMASS (Enterprise Mission Assurance Support Service) and vulnerability assessment tools (e.g., Nessus, ACAS, SCAP).
  • Knowledge:
    • In-depth knowledge of NIST Special Publications (SP) 800-37, 800-53, and 800-171, as well as DoD Instruction 8510.01 and related guidelines.
  • Communication:
    • Strong verbal and written communication skills, with the ability to effectively convey complex cybersecurity concepts to both technical and non-technical audiences.
  • Analytical Skills:
    • Excellent analytical and problem-solving skills, with a keen attention to detail and a proactive approach to identifying and addressing security risks.

Qualifications

  • Education: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
  • Experience: Minimum of 5 years of experience in cybersecurity, with at least 3 years specializing in RMF processes and DoD information systems.
  • Certifications: Must possess or be willing to obtain relevant cybersecurity certifications such as Certified Information Systems Security Professional (CISSP), Certified Authorization Professional (CAP), or equivalent.
  • Security Clearance: Ability to obtain and maintain a Top Secret/SCI security clearance.
  • Technical Skills: Proficiency in RMF tools and technologies, such as eMASS (Enterprise Mission Assurance Support Service) and vulnerability assessment tools (e.g., Nessus, ACAS, SCAP).
  • Knowledge: In-depth knowledge of NIST Special Publications (SP) 800-37, 800-53, and 800-171, as well as DoD Instruction 8510.01 and related guidelines.
  • Communication: Strong verbal and written communication skills, with the ability to effectively convey complex cybersecurity concepts to both technical and non-technical audiences.
  • Analytical Skills: Excellent analytical and problem-solving skills, with a keen attention to detail and a proactive approach to identifying and addressing security risks.

Benefits

NV5 offers a competitive compensation and benefits package including medical, dental, life insurance, FTO, 401(k) and professional development/advancement opportunities.

Pay

Compensation is competitive and based on experience and qualifications.

Schedule

Hybrid Schedule

EEO Statement

NV5 is an Equal Opportunity Employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, disability, veteran status, genetic information, or any other legally protected characteristic.

Similar jobs