{"schemaVersion":"jobsearcher.job.v1","id":"21c0097637cede83bb27fbe4","url":"https://jobsearcher.com/jobs/21c0097637cede83bb27fbe4","canonicalUrl":"https://jobsearcher.com/jobs/21c0097637cede83bb27fbe4","title":"RMF Process Lead (R-00177)","description":"True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.\nPosition Responsibilities\nRoles and Responsibilities\nOwn and manage the end-to-end RMF lifecycle, including system categorization, control selection, implementation, assessment, authorization, continuous monitoring, and system disposal.\nAssess and document current-state RMF processes, workflows, roles, data requirements, dependencies, pain points, and approval paths.\nDesign and implement standardized target-state RMF processes aligned with NIST, federal agency, and organizational requirements.\nTranslate existing RMF workflows, business rules, security documentation, control data, and authorization activities into the new GRC or RMF platform.\nServe as the primary functional subject matter expert for the new RMF solution, including its workflows, data model, configurations, reporting, and user capabilities.\nLead requirements-gathering sessions with system owners, ISSOs, ISSMs, security control assessors, authorizing officials, engineers, and compliance stakeholders.\nDefine functional requirements, user stories, acceptance criteria, workflow rules, role-based permissions, notifications, and approval processes.\nReview and validate the migration of system records, security controls, assessment results, POA&Ms, authorization packages, evidence, and supporting documentation.\nIdentify process gaps, data-quality issues, control-mapping inconsistencies, and configuration deficiencies, and coordinate corrective actions.\nEstablish RMF governance standards, operating procedures, templates, process guides, decision points, and quality-control requirements.\nCoordinate solution testing, user acceptance testing, process validation, defect resolution, and production-readiness activities.\nDevelop training materials and provide role-based training, demonstrations, and knowledge transfer for users of the new RMF solution.\nMonitor RMF process performance, authorization timelines, control-assessment status, POA&M remediation, and continuous-monitoring activities.\nProvide leadership with dashboards, status reports, risk summaries, implementation updates, and recommendations for process improvement.\nDrive user adoption and continuous improvement by incorporating stakeholder feedback, regulatory changes, lessons learned, and emerging cybersecurity requirements.\nPosition Qualifications\nBachelor’s degree in cybersecurity, information technology, information systems, engineering, business, or a related field.\nEight or more years of experience supporting cybersecurity governance, risk management, compliance, security authorization, or RMF programs.\nDemonstrated experience leading or owning end-to-end RMF processes within a federal government or highly regulated environment.\nExpert knowledge of NIST RMF, NIST SP 800-37, NIST SP 800-53, FIPS 199, FIPS 200, and continuous-monitoring requirements.\nExperience translating current-state business processes into standardized target-state workflows within a new technology platform.\nExperience implementing, configuring, migrating to, or supporting enterprise GRC or RMF platforms such as RegScale, ServiceNow GRC, RSA Archer, eMASS, Xacta, CSAM, or equivalent solutions.\nStrong understanding of authorization packages, System Security Plans, security controls, assessment procedures, POA&Ms, risk assessments, and authorization decisions.\nExperience facilitating process-mapping, requirements-gathering, solution-design, testing, and stakeholder-validation sessions.\nAbility to translate technical, regulatory, and operational requirements into clear system configurations, workflows, and user procedures.\nStrong analytical, documentation, presentation, communication, and stakeholder-management skills.\nExperience leading cross-functional teams and coordinating with system owners, cybersecurity personnel, assessors, engineers, program managers, and executive leadership.\nAbility to identify process risks, resolve competing requirements, and guide stakeholders toward standardized enterprise solutions.\nRole Summary\nThe RMF Process Lead will own and govern the organization’s Risk Management Framework processes and lead the transition from current-state RMF workflows to a modernized target-state solution. This role requires deep knowledge of federal cybersecurity requirements, security authorization processes, control implementation, and enterprise GRC platforms. The RMF Process Lead will serve as the functional subject matter expert for the new solution, translate existing processes and data into optimized workflows, and ensure consistent adoption across cybersecurity, system owner, assessor, and authorization teams.\nWe may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.","company":"True Zero Technologies","rawCompany":"true zero technologies","city":"Remote","state":"OR","isRemote":false,"isActive":false,"createdAt":"2026-08-04T19:26:45.114Z","occupations":[{"code":"11-3021.00","title":"Computer and Information Systems Managers","slug":"computer-and-information-systems-managers"},{"code":"15-1299.09","title":"Information Technology Project Managers","slug":"information-technology-project-managers"},{"code":"11-9121.00","title":"Natural Sciences Managers","slug":"natural-sciences-managers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541611","title":"Administrative Management and General Management Consulting Services","slug":"administrative-management-and-general-management-consulting-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"RMF Process Lead (R-00177)","description":"True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.\nPosition Responsibilities\nRoles and Responsibilities\nOwn and manage the end-to-end RMF lifecycle, including system categorization, control selection, implementation, assessment, authorization, continuous monitoring, and system disposal.\nAssess and document current-state RMF processes, workflows, roles, data requirements, dependencies, pain points, and approval paths.\nDesign and implement standardized target-state RMF processes aligned with NIST, federal agency, and organizational requirements.\nTranslate existing RMF workflows, business rules, security documentation, control data, and authorization activities into the new GRC or RMF platform.\nServe as the primary functional subject matter expert for the new RMF solution, including its workflows, data model, configurations, reporting, and user capabilities.\nLead requirements-gathering sessions with system owners, ISSOs, ISSMs, security control assessors, authorizing officials, engineers, and compliance stakeholders.\nDefine functional requirements, user stories, acceptance criteria, workflow rules, role-based permissions, notifications, and approval processes.\nReview and validate the migration of system records, security controls, assessment results, POA&Ms, authorization packages, evidence, and supporting documentation.\nIdentify process gaps, data-quality issues, control-mapping inconsistencies, and configuration deficiencies, and coordinate corrective actions.\nEstablish RMF governance standards, operating procedures, templates, process guides, decision points, and quality-control requirements.\nCoordinate solution testing, user acceptance testing, process validation, defect resolution, and production-readiness activities.\nDevelop training materials and provide role-based training, demonstrations, and knowledge transfer for users of the new RMF solution.\nMonitor RMF process performance, authorization timelines, control-assessment status, POA&M remediation, and continuous-monitoring activities.\nProvide leadership with dashboards, status reports, risk summaries, implementation updates, and recommendations for process improvement.\nDrive user adoption and continuous improvement by incorporating stakeholder feedback, regulatory changes, lessons learned, and emerging cybersecurity requirements.\nPosition Qualifications\nBachelor’s degree in cybersecurity, information technology, information systems, engineering, business, or a related field.\nEight or more years of experience supporting cybersecurity governance, risk management, compliance, security authorization, or RMF programs.\nDemonstrated experience leading or owning end-to-end RMF processes within a federal government or highly regulated environment.\nExpert knowledge of NIST RMF, NIST SP 800-37, NIST SP 800-53, FIPS 199, FIPS 200, and continuous-monitoring requirements.\nExperience translating current-state business processes into standardized target-state workflows within a new technology platform.\nExperience implementing, configuring, migrating to, or supporting enterprise GRC or RMF platforms such as RegScale, ServiceNow GRC, RSA Archer, eMASS, Xacta, CSAM, or equivalent solutions.\nStrong understanding of authorization packages, System Security Plans, security controls, assessment procedures, POA&Ms, risk assessments, and authorization decisions.\nExperience facilitating process-mapping, requirements-gathering, solution-design, testing, and stakeholder-validation sessions.\nAbility to translate technical, regulatory, and operational requirements into clear system configurations, workflows, and user procedures.\nStrong analytical, documentation, presentation, communication, and stakeholder-management skills.\nExperience leading cross-functional teams and coordinating with system owners, cybersecurity personnel, assessors, engineers, program managers, and executive leadership.\nAbility to identify process risks, resolve competing requirements, and guide stakeholders toward standardized enterprise solutions.\nRole Summary\nThe RMF Process Lead will own and govern the organization’s Risk Management Framework processes and lead the transition from current-state RMF workflows to a modernized target-state solution. This role requires deep knowledge of federal cybersecurity requirements, security authorization processes, control implementation, and enterprise GRC platforms. The RMF Process Lead will serve as the functional subject matter expert for the new solution, translate existing processes and data into optimized workflows, and ensure consistent adoption across cybersecurity, system owner, assessor, and authorization teams.\nWe may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.","datePosted":"2026-08-04T19:26:45.114Z","dateModified":"2026-08-04T19:26:45.114Z","hiringOrganization":{"@type":"Organization","name":"True Zero Technologies","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote","addressRegion":"OR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"21c0097637cede83bb27fbe4"},"url":"https://jobsearcher.com/jobs/21c0097637cede83bb27fbe4"}}