Risk Management Framework Engineer
Occupations:
Information Security AnalystsInformation Security EngineersSecurity Management SpecialistsComputer Systems Engineers/ArchitectsNetwork and Computer Systems AdministratorsIndustries:
Investigation and Security ServicesProfessional and Commercial Equipment and Supplies Merchant WholesalersComputer Systems Design and Related ServicesBusiness Schools and Computer and Management TrainingFacilities Support ServicesAltamira Technologies has a long and successful history providing innovative solutions throughout the U.S. National Security community. Headquartered in McLean, Virginia, Altamira serves the defense, intelligence and homeland security communities worldwide by focusing on creating innovative solutions leveraging common standards in architecture, data and security. Altamira believes that our people and the culture of our company differentiate us from other companies.Position Location: Chantilly, VA/McLean, VA.Position Description:We are seeking a Risk Management Framework engineer responsible for a critical operational network. This role ensures systems are securely authorized to operate (ATO) by documenting compliance, and coordinating with technical and security stakeholders throughout the system lifecycle.Responsibilities:Lead and support all phases of the Risk Management Framework (RMF) process in accordance with NIST SP 800-37, NIST SP 800-53 Security and Privacy Controls and related standards.Develop, maintain, and update RMF documentation including:System Security Plans (SSPs)Security Assessment Reports (SARs)Plans of Action and Milestones (POA&Ms)Coordinate security authorization packages for ATO decisions.Collaboration & Stakeholder EngagementWork closely with system engineers, network administrators, program managers, and security leadership.Participate in security working groups, technical reviews, and compliance audits.Communicate security posture and risk status to technical and non-technical stakeholders.Knowledge Base:Risk Management Framework (RMF) lifecycle experience: all or most phases, including POA&M and continuous monitoring.ATO Process expertise: system support authorization, reauthorization and continuous compliance.Security control implementation based on NIST SP 800-53Experience with using ServiceNOWEducation and Experience:Bachelor's in computer science, Cybersecurity, or information technology, or a related fieldAt least 3-5 years of experienceActive TS/SCI with a current CI PolygraphBS in Computer Science, Cyber Security, or related field.Demonstrated hands-on experience executing the RMF lifecycle (all or most phases).Familiarity with federal cybersecurity compliance environmentsOne of more of the following active security certifications such as:CompTIA Security+,CISSP (Certified Information Systems Security Professional),CISM (Certified Information Security Manager),CIAM (Certified Identity and Access Manager).Abilities and Competencies:Ability to operate independently and contribute immediately upon assignment.Self-motivated and eager to work intently to satisfy mission requirementsAdaptable and has the desire to maintain our company cultureStrong communication and coordination skills with technical and non-technical stakeholdersExperience in security working groups, technical reviews, and compliance auditsAbility to multitask and adjust priorities as neededNice to have:* Familiarity with current Information Assurance (IA) and cybersecurity tools such as vulnerability management and scanning tools* Experience with assessing security requirements and evaluating systems for gaps in security requirements.