Source Job

US 3w PTO

  • Lead quality assurance for RMF authorization packages to ensure completeness and readiness for government review.
  • Coordinate with RMF analysts, ISSOs, system owners, and technical stakeholders to validate security documentation and evidence.
  • Mentor team members on documentation standards and best practices while tracking assessment readiness metrics to reduce rework.

Cybersecurity Risk Management Framework Quality Assurance Vulnerability Management

19 jobs similar to RMF Assessment & Quality Assurance Lead

Jobs ranked by similarity.

US

  • Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
  • Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
  • Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.

US

  • Serves as a cybersecurity SME for Assessment and Authorization (A&A) of information systems, applying NIST 800-53 security controls and the Risk Management Framework (RMF) process.
  • Possesses five years of relevant RMF, NIST, and A&A experience, including assessing security controls for large, complex organizations like DLA.
  • Briefs senior management on authorization progress and understands cybersecurity in emerging technology areas such as Cloud and Industrial Control Systems.

Horizon Industries Limited is a dynamic IT and Management Consulting firm based in the Washington, DC area, providing full-cycle IT consulting and management support to both private and public sectors. Founded in 1996, the company prides itself on a diverse, employee- and family-centric culture with a focus on professional growth.

$105,000–$155,000/yr
US

  • Provide expert guidance on cybersecurity policies, Risk Management Framework (RMF) processes, and security control implementation.
  • Conduct vulnerability assessments, penetration testing, and Cybersecurity Compliance and Readiness Inspections (CCRI).
  • Prepare detailed technical reports and briefings for senior leadership on cybersecurity findings and progress.

The company is a partner organization focused on cybersecurity and mission-critical IT environments. They offer a remote work culture and support complex security initiatives for government and enterprise clients.

US

  • Provide RMF security artifacts for ARTRANS programs to inherit NIST 800-53 controls.
  • Maintain STIG/SRG checklists and monthly status reports.
  • Evaluate risk assessments and develop plans for full inheritance from DevSecOps pipeline.

DecisionPoint Corporation provides IT and cloud services, specializing in DevSecOps platforms and security compliance. They are a mid-sized company with a focus on supporting government programs through robust security practices.

US

  • Lead RMF authorization activities, including SSP, SAP, SAR, and POA&M development.
  • Conduct vulnerability assessments and enforce secure configurations using CIS Benchmarks and DISA STIGs.
  • Support cloud security initiatives in AWS GovCloud and advise on AI-enabled system security.

This company provides cybersecurity solutions for federal government systems. They are a mid-sized organization with a collaborative culture focused on security and compliance.

US Unlimited PTO

  • Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
  • Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
  • Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.

OpenTeams builds AI that empowers, focusing on energy-efficient, cost-effective models that give users full ownership of their data. As a small company, they value freedom, teamwork, accountability, and reinvest 3% of profits into the open-source community.

US

  • Lead end-to-end service delivery operations for cybersecurity and cloud security professional services engagements.
  • Own the delivery lifecycle for FedRAMP advisory, implementation, continuous monitoring, and related security programs.
  • Develop operational strategies and governance models ensuring compliance with NIST 800-53, FedRAMP, and DoD frameworks.

This company specializes in cybersecurity and cloud service delivery for federal agencies, managing mission-critical environments with strict compliance requirements. They are a mid-sized organization focused on scalable operations and measurable outcomes.

India

  • Lead GRC activities including risk management framework, security assessments, and continuous monitoring for assigned systems.
  • Collaborate with engineering and security teams to integrate GRC principles into system lifecycles and DevSecOps practices.
  • Develop and maintain security documentation, support ATO processes, and provide risk briefings to leadership.

The partner company helps organizations strengthen cybersecurity programs through modern GRC practices and engineering expertise. It is a fully remote organization with a collaborative culture focused on technical excellence and professional growth.

US

  • Design and implement cybersecurity architectures, controls, and technologies for secure government systems.
  • Manage Authority to Operate (ATO) activities, including security documentation, compliance tracking, and continuous monitoring.
  • Apply NIST SP 800 security controls and support Risk Management Framework (RMF) implementation.

The partner organization provides advanced cybersecurity solutions for critical government technology environments. They operate in a mission-driven, collaborative culture with a focus on protecting federal systems.

US 3w PTO

  • Design, develop, and maintain automated workflows for RMF, A&A, and continuous monitoring.
  • Develop integrations between GRC platforms, security tools, and reporting solutions.
  • Automate evidence collection, control validation, and compliance activities to improve efficiency.

True Zero Technologies is a veteran-owned small business that enables people and technology to deliver top-tier cybersecurity services. With a people-first approach, the company has been recognized as a Best Places to Work honoree and made the Inc. 5000 list, reflecting a culture of driven and passionate individuals.

$117,500–$166,250/yr
US

  • Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis.
  • Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements.
  • Develop and own System Security Plans (SSPs), control narratives, and compliance documentation.

Riveron helps organizations implement leading governance, risk and compliance practices with a hands-on approach. The company fosters an entrepreneurial culture with collaboration and diverse perspectives, offering flexible work and progressive benefits.

US

  • Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
  • Oversee preparation and execution of external compliance audits, including facilitating security assessments.
  • Support mapping of compliance requirements to security control implementation using agile development processes.

Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.

US

  • Provide advanced cybersecurity expertise to support secure system operations and compliance initiatives.
  • Analyze system designs and architectures to ensure appropriate security controls and protection mechanisms.
  • Collaborate with technical teams and security organizations to align priorities and security objectives.

The partner company is a mission-driven organization that strengthens cybersecurity capabilities for critical information systems. It offers a collaborative culture with opportunities for professional growth and impactful work.

$110,000–$145,000/yr
US

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.

Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.

$70,000–$77,000/yr
US

  • Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
  • Develop and execute security awareness programs including training and phishing simulations.
  • Support governance and control management by maintaining policies and control libraries.

Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.

$175,000–$265,000/yr
US Unlimited PTO

  • Develop and execute cybersecurity strategy, roadmap, and governance to protect Voyager's information systems and mission-critical environments.
  • Lead security operations, incident response, vulnerability management, and compliance with government regulations like CMMC and NIST.
  • Oversee security architecture, risk management, and team leadership to enable secure innovation in aerospace and defense.

Voyager is an innovative space, defense, and national security technology company delivering transformative, mission-critical solutions. It fosters a culture where innovation thrives, curiosity is rewarded, and impact is real, with a team of doers, thinkers, and builders united by purpose.

US

  • Serve as the Information Systems Security Officer for assigned systems, maintaining security documentation and supporting authorization activities.
  • Coordinate security control implementation with Engineering, DevOps, and IT teams, managing Plans of Action and Milestones.
  • Support continuous monitoring, vulnerability management, and incident response for FedRAMP and GovRAMP environments.

Keeper Security is a cybersecurity software company that protects organizations and individuals globally with zero-trust and zero-knowledge solutions. It is a fast-growing company with FedRAMP and GovRAMP high authorizations, recognized in the Gartner Magic Quadrant for PAM.

US 3w PTO

  • Analyze enterprise vulnerability data to identify the highest priority cyber exposures across the NIH environment.
  • Correlate vulnerability findings with threat intelligence, exploit availability, and operational risk to improve remediation prioritization.
  • Collaborate with incident responders, penetration testers, and security engineers to refine enterprise risk prioritization.

True Zero Technologies is a veteran-owned small business founded on the principle that enabling people and technology drives quality outcomes. We are a people-first company recognized as a Best Place to Work and on the Inc. 5000 list of fastest-growing companies.

US 24w maternity 24w paternity

  • Own FedRAMP and GovRAMP certifications and roadmaps, including package management and compliance timelines.
  • Manage 3PAO relationships and assessments, coordinating scoping, evidence, and results validation.
  • Lead continuous monitoring, POA&M processes, and drive compliance automation and efficiency.

Smartsheet empowers teams to manage work seamlessly and scale solutions smarter, now uniting human teams with AI agents. It is an equal opportunity employer committed to fostering an inclusive environment with the best employees.