Source Job

US

  • Own and manage the end-to-end RMF lifecycle, including system categorization, control selection, and continuous monitoring.
  • Assess current-state RMF processes and design standardized target-state workflows aligned with NIST and federal requirements.
  • Serve as the primary functional subject matter expert for the new RMF solution, leading requirements gathering, testing, and training.

RMF NIST GRC Platforms Cybersecurity Process Management

18 jobs similar to RMF Process Lead

Jobs ranked by similarity.

US 3w PTO

  • Lead quality assurance for RMF authorization packages to ensure completeness and readiness for government review.
  • Coordinate with RMF analysts, ISSOs, system owners, and technical stakeholders to validate security documentation and evidence.
  • Mentor team members on documentation standards and best practices while tracking assessment readiness metrics to reduce rework.

True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. The company has been named a Best Place to Work multiple times and made the Inc. 5000 list of fastest-growing companies, reflecting its people-first culture and commitment to excellence.

US

  • Execute NIST SP 800-53 control mappings and implement security baselines.
  • Develop and maintain SSPs, POA&Ms, and authorization documentation.
  • Support continuous monitoring and gap assessments for ATO and FedRAMP.

This company provides cybersecurity and compliance consulting services, supporting defense contractors and federal organizations with NIST and FedRAMP requirements. It is an early-stage, remote-first company with a collaborative culture focused on federal cybersecurity.

India

  • Lead GRC activities including risk management framework, security assessments, and continuous monitoring for assigned systems.
  • Collaborate with engineering and security teams to integrate GRC principles into system lifecycles and DevSecOps practices.
  • Develop and maintain security documentation, support ATO processes, and provide risk briefings to leadership.

The partner company helps organizations strengthen cybersecurity programs through modern GRC practices and engineering expertise. It is a fully remote organization with a collaborative culture focused on technical excellence and professional growth.

US

  • Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
  • Build and manage the control environment, including policies, procedures, and evidence collection systems.
  • Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT.

Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019 and valued at over $2 billion, the company is a distributed team of builders from military, operational, and technology backgrounds.

$117,500–$166,250/yr
US

  • Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis.
  • Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements.
  • Develop and own System Security Plans (SSPs), control narratives, and compliance documentation.

Riveron helps organizations implement leading governance, risk and compliance practices with a hands-on approach. The company fosters an entrepreneurial culture with collaboration and diverse perspectives, offering flexible work and progressive benefits.

US

  • Support enterprise cybersecurity governance, compliance, and risk management programs.
  • Conduct security control assessments, audit readiness, and policy development.
  • Coordinate with technical teams and executive leadership to drive cybersecurity modernization.

ERP International is a nationally respected provider of health, science, and technology solutions supporting government and commercial clients. The company has been named a Top Workplace by WTOP News for 7 years and offers a culture of employee recognition, community outreach, and professional development.

US Unlimited PTO

  • Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
  • Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
  • Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.

OpenTeams builds AI that empowers, focusing on energy-efficient, cost-effective models that give users full ownership of their data. As a small company, they value freedom, teamwork, accountability, and reinvest 3% of profits into the open-source community.

United States 3w PTO

  • Design and maintain automated workflows for Risk Management Framework and compliance operations.
  • Build integrations between GRC platforms, security tools, and reporting solutions.
  • Develop scripts, APIs, and dashboards to improve cybersecurity visibility and efficiency.

This is a partner company role managed by Jobgether, focusing on cybersecurity governance through automation. The company uses AI-powered matching to connect candidates with roles and emphasizes data privacy and fair hiring processes.

$230,000–$270,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Own and manage federal compliance frameworks including FedRAMP, NIST, CMMC, DFARS, and StateRAMP.
  • Translate regulatory controls into automated tests and machine-readable specifications for continuous authorization.
  • Collaborate with Engineering, Product, and Design to shape product capabilities and influence strategy.

Our partner company is a technology organization focused on federal compliance automation, serving organizations from emerging companies to large enterprises. They operate with a remote-first culture and value autonomy, accuracy, and scalability.

US

  • Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
  • Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
  • Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.

USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.

$105,000–$155,000/yr
US

  • Provide expert guidance on cybersecurity policies, Risk Management Framework (RMF) processes, and security control implementation.
  • Conduct vulnerability assessments, penetration testing, and Cybersecurity Compliance and Readiness Inspections (CCRI).
  • Prepare detailed technical reports and briefings for senior leadership on cybersecurity findings and progress.

The company is a partner organization focused on cybersecurity and mission-critical IT environments. They offer a remote work culture and support complex security initiatives for government and enterprise clients.

US

  • Provide RMF security artifacts for ARTRANS programs to inherit NIST 800-53 controls.
  • Maintain STIG/SRG checklists and monthly status reports.
  • Evaluate risk assessments and develop plans for full inheritance from DevSecOps pipeline.

DecisionPoint Corporation provides IT and cloud services, specializing in DevSecOps platforms and security compliance. They are a mid-sized company with a focus on supporting government programs through robust security practices.

US Unlimited PTO 16w maternity 16w paternity

  • Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
  • Interpret controls at the mechanics level and author precise technical guidance.
  • Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.

Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.

$147,050–$220,800/yr
US

  • Lead IT governance and risk management, including executive reporting and risk register maintenance.
  • Develop KPI and KRI dashboards to translate complex data into actionable insights for senior leadership.
  • Oversee ITSM governance, ServiceNow optimization, and vendor risk management.

Our partner is a global organization operating in a sophisticated Governance, Risk & Compliance environment, connecting technology, cybersecurity, privacy, and operational risk. It fosters a collaborative culture with a focus on work-life balance and professional development.

US Unlimited PTO

  • Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
  • Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.

Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.

United States Unlimited PTO

  • Own and strengthen the controls environment, ensuring compliance requirements are effectively implemented and maintained.
  • Support and mature the GRC program, including SOC 2 operations and alignment with frameworks such as NIST.
  • Manage vendor risk assessments, regulatory licensing, and security issue lifecycle across jurisdictions.

Mesh enables consumers to pay and be paid with any asset, bridging crypto payments into everyday commerce. Backed by investors like PayPal Ventures and Paradigm, the company is building infrastructure for the global economy with a small, fast-moving team.

US

  • Lead the end-to-end authorization process for FedRAMP High, while driving alignment with CMMC and MARS-E.
  • Manage ongoing FedRAMP continuous monitoring, including monthly deliverables and vulnerability management.
  • Collaborate with engineering, security, and operations teams to develop a 'comply once, satisfy many' strategy.

Amwell provides a technology-enabled care platform for healthcare organizations, offering services across the care continuum. With a team passionate about transforming care delivery, they have served large healthcare organizations for nearly two decades.

US

  • Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
  • Oversee preparation and execution of external compliance audits, including facilitating security assessments.
  • Support mapping of compliance requirements to security control implementation using agile development processes.

Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.