Назад
Company hidden
8 дней назад

RMF Validator (Cybersecurity)

156 285 - 234 370$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
RMF Validator (Cybersecurity): Conducting independent security control assessments and validating documentation for Navy and DoD information systems to support Assessment and Authorization with an accent on NIST, RMF, eMASS, and cybersecurity risk analysis. Focus on reviewing SSPs, SARs, and POA&Ms, testing implemented controls, identifying vulnerabilities, and developing prioritized remediation recommendations.

Location: Washington, District of Columbia, United States

Salary: $156,285.00–$234,370.00 annually; the range applies to the Washington, DC location.

Company

hirify.global’s Product and Technology Solutions Division develops rapid prototypes and advanced technology solutions for directed energy, electronic warfare, critical infrastructure protection, and security applications.

What you will do

  • Conduct independent security control assessments for information systems and networks according to NIST, Navy, and DoD standards.
  • Review RMF documentation, including SSPs, SARs, POA&Ms, security assessment plans, and security test reports.
  • Validate the implementation and effectiveness of security controls through vulnerability scanning, configuration assessments, and security testing.
  • Identify, categorize, and report cybersecurity risks, vulnerabilities, deficiencies, severity, likelihood, and potential impact.
  • Recommend prioritized remediation strategies and compensating controls.
  • Support annual security reviews and FSCA liaison activities, including reviewing assessments, grading findings, and drafting SAR executive summaries.

Requirements

  • Must be a U.S. citizen and possess or have previously possessed a DoD SECRET security clearance or higher.
  • Bachelor’s degree and 10+ years of directly related experience, or 8 additional years of related experience in lieu of a degree.
  • Professional cybersecurity experience with Risk Management Framework, Assessment and Authorization, and tools such as eMASS.
  • Experience with cybersecurity for cloud environments and knowledge of NIST Special Publications.
  • Ability to assess controls using NIST SP 800-53, CNSSI 1253, Navy RMF guidance, and applicable DoD cybersecurity frameworks.
  • Ability to analyze risks, validate security documentation, and support authorization decisions.

Nice to have

  • Experience with IT/OT systems.
  • DoD 8570.01-M IAM/IAT Level III certification or Security+ certification.
  • CAP, CISSP, or CASP certification.
  • Navy Qualified Validator certification.
  • Knowledge of DISA STIGs.

Culture & Benefits

  • 401(k) plan with company match may be available.
  • Medical, dental, vision, life insurance, AD&D, flexible spending, disability coverage, and paid time off may be available.
  • Flexible work schedule may be available.
  • Professional training and career development opportunities.
  • People First and Zero Harm culture focused on belonging, connection, and growth.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →