Senior RMF Lead, Cybersecurity Architect
Responsibilities
- Provides senior-level technical and governance support for the program, security architecture activities, control implementation, authorization boundary definition, cyber risk analysis, and secure architecture modernization.
- Bridges RMF execution, architecture design, Zero Trust alignment, and system authorization support to help our client maintain a mature and defensible security posture.
- Supports RMF lifecycle activities including categorization, control selection, tailoring, implementation guidance, assessment preparation, authorization package review, and continuous monitoring.
- Advise system owners, ISSOs, engineers, and stakeholders on security controls, authorization boundaries, inheritance, overlays, and risk management.
- Support development and review of SSPs, architecture diagrams, authorization boundary diagrams, risk documentation, control evidence, POA&Ms, and related RMF artifacts.
- Identify architecture gaps and recommend improvements to enhance visibility, compliance, resilience, and risk reduction.
- Support Zero Trust architecture implementation, privileged access control design, and cloud/on-premise security patterns.
- Provide technical thought leadership, risk mitigation recommendations, and architecture briefings.
Requirements
- Bachelor’s degree or equivalent.
- Experience supporting RMF, A&A, security architecture, or federal cybersecurity engineering programs.
- Knowledge of NIST SP 800-53 Rev. 5, FISMA, FedRAMP, cloud security, Zero Trust, identity, privileged access, and continuous monitoring.
- Ability to translate technical system details into authorization-ready documentation and risk-based recommendations.
- Experience working with system owners, ISSOs, security engineers, privacy stakeholders, and authorizing officials.
- Strong technical writing and architecture documentation skills.
- Must be a U.S. citizen.
- Successful drug screening.
- Must be eligible to obtain and maintain a security or clearance badge.
Preferred Qualifications
- CISSP, ISSAP, ISSEP, CCSP, CISM, CAP/CGRC, Security+
- AWS/Azure security certifications, or equivalent.
Location/Work Arrangement
Schedule is full-time, Monday – Friday 40-hour week, 4/10’s, or 9/80’s and may require on call or overnight shifts depending on contract needs. This position may be fully onsite or hybrid/remote depending on the needs of the specific contract.
Benefits
- Health, Dental, Vision, Life Insurance
- Paid Vacation
- 401K
- Long and Short-Term Disability
Starting Compensation
Typical salary ranges between $157,213 – $184,956 annually is commensurate with experience relative to the position and may vary based on candidate geographical location.
EEO
BGS is an Equal Opportunity/Affirmative Action employer. All qualified applicants are encouraged to apply and will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.
Exclusive Agreement Disclaimer
BGS has standing contracts with federal agencies throughout the United States. We require an affirmative exclusive agreement to represent all candidates to our clients. By submitting this application, you are consenting to allow BGS to represent you as a candidate for the role in which you are applying.