Source Job

US

  • Perform all 7 steps of the Risk Management Framework (RMF) per DoDI 8510.01, producing required deliverables at each step
  • Develop, maintain, and update RMF packages including System Security Plans (SSP), Security Assessment Reports (SAR), Risk Assessment Reports (RAR), and Plans of Action & Milestones (POA&M)
  • Ensure compliance with federal, DoD, and DLA cybersecurity requirements, policies, and standards

Cybersecurity RMF NIST

10 jobs similar to Cybersecurity Assessment/Authorization SME

Jobs ranked by similarity.

$70,000–$130,000/yr
US 2w PTO

  • Serves as a cybersecurity Subject Matter Expert (SME) regarding OT Authorization of information systems and all associated cybersecurity policies and procedures.
  • Performs a DOD cybersecurity process while either authorizing an information system or serving as a SME for an information system undergoing authorization.
  • Determines the applicable severity value for an identified vulnerability (e.g., non-compliant security control), and determines the possible ramifications on the system’s current or future authorization.

Amyx is an equal-opportunity employer and a VEVRAA federal contractor. They are committed to considering all qualified candidates regardless of race, color, religion, national origin, age, disability, sexual orientation, gender identity, status as a protected veteran, or any other characteristic protected by law.

Europe

  • Own the DoW product strategy and execution roadmap.
  • Ensure the platform aligns with compliance management under the Risk Management Framework (RMF).
  • Translate customer and mission needs into clear product requirements.

Jobgether uses an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Their system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company.

US

  • Lead the end-to-end Certification & Authorization (C&A) process for information systems.
  • Maintain and update System Security Plans (SSPs), POA&Ms, and other FedRAMP/GovRAMP/NIST documentation artifacts.
  • Oversee control gap analysis and drive remediation efforts across technical and administrative domains.

EBSCO Information Services (EBSCO) delivers a fully optimized research experience, seamlessly integrated with a powerful discovery platform to support the information needs of our end-users. Headquartered in Ipswich, MA, EBSCO employs more than 2,700 people worldwide, with most embracing hybrid or remote work models.

$220,000–$240,000/yr

  • Manage and develop staff members under Product Compliance.
  • Oversee and contribute to the vulnerability management lifecycle.
  • Assess and serve as a subject matter expert for regulatory and compliance requirements.

ExtraHop is a company that focuses on network detection and response (NDR) to help organizations stay ahead of emerging threats. They integrate network threat detection, network performance management, intrusion detection, and packet forensics into a single console.

US

  • Serve as the primary cybersecurity point of contact for assigned DoD Information Systems.
  • Collaborate with stakeholders to ensure system compliance and readiness.
  • Develop, maintain, and update all RMF authorization and GRC documentation.

LMI is a digital solutions provider dedicated to accelerating government impact with innovation. Investing in technology and prototypes ahead of need, it brings commercial-grade platforms and mission-ready AI to federal agencies at commercial speed, employing agile methodology and collaboration.

$123,250–$207,000/yr
US

  • Own and lead the FedRAMP High authorization program.
  • Serve as the primary point of accountability for government compliance programs.
  • Manage compliance roadmaps, milestones, dependencies, risks, and remediation efforts.

Commvault is the gold standard in cyber resilience. The company empowers customers to uncover, take action, and rapidly recover from cyberattacks – keeping data safe and businesses resilient. For over 25 years, more than 100,000 organizations and a vast partner ecosystem have relied on Commvault to reduce risks, improve governance, and do more with data.

US

  • Serve as the project manager for overall execution and delivery of cybersecurity requirements.
  • Coordinate with government leadership and stakeholders to facilitate effective communication.
  • Develop and maintain project management plans for the contract lifecycle.

Jobgether is a platform that uses AI-powered matching process to ensure candidate applications are reviewed quickly and fairly. They identify the top-fitting candidates for companies.

$122,400–$150,650/yr
US

  • Manages the 2ROPS accreditation process for small classified mobile systems.
  • Renews the current Authority to Operate (ATO).
  • Provides ongoing cybersecurity sustainment support.

GovCIO transforms government IT with innovative services and solutions. We are a team of passionate people making a positive impact. We are changing the face of government IT and building a workforce that fuels this mission.

US

  • Support ongoing FedRAMP authorization including SSP, POA&M, evidence, and 3PAO coordination.
  • Manage and oversee NIST SP 800-53 compliance.
  • Oversee continuous monitoring, vulnerabilities, incidents.

IFS is a billion-dollar revenue company with 7000+ employees on all continents. Their leading AI technology is the backbone of their award-winning enterprise software solutions, enabling customers to be their best when it really matters–at the Moment of Service™.

US

  • Develops and refines performance methodologies that support the cybersecurity requirements.
  • Oversee independent assessments and review Security Impact Analyses (SIA).
  • Incorporate compliance data into the Governance, Risk, and Compliance Tool (GRCT).

SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider. It is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development.