{"schemaVersion":"jobsearcher.job.v1","id":"e2f43fb501ea88a4e711a759","url":"https://jobsearcher.com/jobs/e2f43fb501ea88a4e711a759","canonicalUrl":"https://jobsearcher.com/jobs/e2f43fb501ea88a4e711a759","title":"RMF Security SME","description":"Overview:\n\nWe are seeking an RMF Security SME to help modernize our security posture by shifting from manual compliance to automated control implementation and continuous monitoring. This role bridges deep knowledge of the Risk Management Framework (RMF) and security controls with hands-on cloud and DevSecOps engineering, working alongside engineers, data scientists, designers, and analysts to build secure, usable, and auditable systems.\n\nContributions:\nServe as the RMF subject matter expert, interpreting NIST SP 800-53 controls and mapping technical and operational requirements to automated implementation and continuous monitoring\nDesign and implement control automation pipelines that convert manual compliance activities (control implementation, evidence collection, continuous monitoring) into repeatable, automated processes using infrastructure as code and compliance-as-code approaches (e.g., OSCAL)\nIdentify and drive implementation of controls around secure cloud-based solutions, including zero-trust architecture components, identity and access management (IAM) policy, and data privacy controls\nPartner with stakeholders to balance security requirements with usability, translating RMF and compliance requirements into practical technical solutions\nReview infrastructure as code authored by others to assess control coverage, security risk, and compliance impact\nConduct risk assessments and control assessments to ensure systems meet NIST, FISMA, and other applicable compliance frameworks\nRecommend solutions for automating security processes such as vulnerability management, patch management, and control monitoring/reporting\nCollaborate with software developers and DevSecOps engineers to embed security controls and RMF requirements into the SDLC and CI/CD pipeline\nSupport control mapping design and implementation of data protection and encryption for data at rest and in transit\nDocument the as-is control environment, perform gap analyses against RMF/NIST baselines, and produce artifacts articulating remediation options and recommendations\nDrive automation for core RMF Processes & generation of A&A documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and control assessment artifacts.\nIdentify, analyze, and resolve infrastructure vulnerabilities and application deployment issues affecting control compliance\nEngineer solutions and recommend continuous improvements to control automation and security operations\nPresent regular status updates and provide cross-training to team members on RMF processes and control automation practices\nQualifications:\nAbility to obtain a U.S. government Security Clearance\nOne of the following, based on education level: no degree with 9 years of relevant experience, a Bachelor's degree with 5 years of relevant experience, or a Master's degree with 3 years of relevant experience\nExperience architecting, designing, developing, and implementing cloud solutions\nExperience with one or more cloud platforms (AWS, Azure, or GCP)\n5 years of experience conducting monitoring, risk assessment, threat modeling, and security testing in cloud environments\n5 years of experience applying the Risk Management Framework (RMF), including documenting POA&Ms, SSPs, and Assessment & Authorization (A&A) support documentation\nDemonstrated understanding of NIST 800-53 (or equivalent) security controls and experience translating control requirements into technical and operational implementations\nAt least one active, relevant professional certification tied to the cloud/security technology being deployed or maintained (e.g., AWS Certified Security Specialty, AWS Certified Solutions Architect Associate, Microsoft Certified Azure Administrator Associate, CISSP, or CAP), subject to program manager approval\n\nPreferred:\n\nAdditional certifications beyond the one required above\nExperience with compliance automation platforms and standards such as OSCAL, eMASS, Xacta, or CSAM\nExperience automating control assessment, continuous monitoring (ConMon), and A&A documentation workflows\nExcellent written and verbal communication, interpersonal, and collaborative skills\nExperience documenting as-is environment states, performing gap analyses, and producing options/recommendation artifacts\nAbout steampunk:\n\nSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $130,000 to $180,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here.\n\nIdentity Statement\n\nAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.\n\nSteampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit http://www.steampunk.com.\n\nWe are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program.","company":"Steampunk","rawCompany":"steampunk","city":"McLean","state":"VA","isRemote":false,"isActive":true,"createdAt":"2026-08-14T15:17:49.904Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"RMF Security SME","description":"Overview:\n\nWe are seeking an RMF Security SME to help modernize our security posture by shifting from manual compliance to automated control implementation and continuous monitoring. This role bridges deep knowledge of the Risk Management Framework (RMF) and security controls with hands-on cloud and DevSecOps engineering, working alongside engineers, data scientists, designers, and analysts to build secure, usable, and auditable systems.\n\nContributions:\nServe as the RMF subject matter expert, interpreting NIST SP 800-53 controls and mapping technical and operational requirements to automated implementation and continuous monitoring\nDesign and implement control automation pipelines that convert manual compliance activities (control implementation, evidence collection, continuous monitoring) into repeatable, automated processes using infrastructure as code and compliance-as-code approaches (e.g., OSCAL)\nIdentify and drive implementation of controls around secure cloud-based solutions, including zero-trust architecture components, identity and access management (IAM) policy, and data privacy controls\nPartner with stakeholders to balance security requirements with usability, translating RMF and compliance requirements into practical technical solutions\nReview infrastructure as code authored by others to assess control coverage, security risk, and compliance impact\nConduct risk assessments and control assessments to ensure systems meet NIST, FISMA, and other applicable compliance frameworks\nRecommend solutions for automating security processes such as vulnerability management, patch management, and control monitoring/reporting\nCollaborate with software developers and DevSecOps engineers to embed security controls and RMF requirements into the SDLC and CI/CD pipeline\nSupport control mapping design and implementation of data protection and encryption for data at rest and in transit\nDocument the as-is control environment, perform gap analyses against RMF/NIST baselines, and produce artifacts articulating remediation options and recommendations\nDrive automation for core RMF Processes & generation of A&A documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and control assessment artifacts.\nIdentify, analyze, and resolve infrastructure vulnerabilities and application deployment issues affecting control compliance\nEngineer solutions and recommend continuous improvements to control automation and security operations\nPresent regular status updates and provide cross-training to team members on RMF processes and control automation practices\nQualifications:\nAbility to obtain a U.S. government Security Clearance\nOne of the following, based on education level: no degree with 9 years of relevant experience, a Bachelor's degree with 5 years of relevant experience, or a Master's degree with 3 years of relevant experience\nExperience architecting, designing, developing, and implementing cloud solutions\nExperience with one or more cloud platforms (AWS, Azure, or GCP)\n5 years of experience conducting monitoring, risk assessment, threat modeling, and security testing in cloud environments\n5 years of experience applying the Risk Management Framework (RMF), including documenting POA&Ms, SSPs, and Assessment & Authorization (A&A) support documentation\nDemonstrated understanding of NIST 800-53 (or equivalent) security controls and experience translating control requirements into technical and operational implementations\nAt least one active, relevant professional certification tied to the cloud/security technology being deployed or maintained (e.g., AWS Certified Security Specialty, AWS Certified Solutions Architect Associate, Microsoft Certified Azure Administrator Associate, CISSP, or CAP), subject to program manager approval\n\nPreferred:\n\nAdditional certifications beyond the one required above\nExperience with compliance automation platforms and standards such as OSCAL, eMASS, Xacta, or CSAM\nExperience automating control assessment, continuous monitoring (ConMon), and A&A documentation workflows\nExcellent written and verbal communication, interpersonal, and collaborative skills\nExperience documenting as-is environment states, performing gap analyses, and producing options/recommendation artifacts\nAbout steampunk:\n\nSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $130,000 to $180,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here.\n\nIdentity Statement\n\nAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.\n\nSteampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit http://www.steampunk.com.\n\nWe are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program.","datePosted":"2026-08-14T15:17:49.904Z","dateModified":"2026-08-14T15:17:49.904Z","hiringOrganization":{"@type":"Organization","name":"Steampunk","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"McLean","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"e2f43fb501ea88a4e711a759"},"url":"https://jobsearcher.com/jobs/e2f43fb501ea88a4e711a759"}}