Cybersecurity RMF & Compliance Specialist
Akhiok-Kaguyak, Inc. Washington, District of Columbia, United States · $100K–$135K/yr
Defense & Space · 51-200 employees
About the role
The specialist supports the implementation of the NIST Risk Management Framework and maintains system authorization through continuous monitoring and compliance activities. They coordinate with stakeholders to manage security documentation, vulnerability tracking, and remediation efforts across federal information systems.
What they look for
Requirements
Candidates must have at least 5 years of cybersecurity experience, with a minimum of 3 years specifically in federal government RMF and A&A activities. A bachelor's degree in a technical field is preferred, and relevant certifications such as CISSP, CGRC, or CISM are highly desired.
Full description
Position Summary
The Cybersecurity RMF & Compliance Specialist provides technical and programmatic cybersecurity support for federal information systems. The position supports Risk Management Framework (RMF) implementation, Assessment and Authorization (A&A), continuous monitoring, security assessments, cloud security, FedRAMP, and federal cybersecurity compliance activities. The specialist works with system owners, ISSOs/ISSMs, security assessors, technical teams, and government stakeholders to maintain system authorization and compliance with applicable NIST and agency cybersecurity requirements.
Key Responsibilities
- Support implementation and execution of the NIST Risk Management Framework throughout the system development and authorization lifecycle.
- Develop, maintain, and update A&A documentation, including System Security Plans (SSPs), Security Assessment Plans/Reports, POA&Ms, risk assessments, control implementation statements, and supporting artifacts.
- Apply NIST cybersecurity standards and guidance, including NIST SP 800-37, 800-53, 800-53A, and related publications.
- Maintain cybersecurity documentation and compliance information within JCAM, eMASS, CSAM, or comparable Governance, Risk, and Compliance (GRC) platforms.
- Support continuous monitoring activities, including vulnerability tracking, security-control monitoring, POA&M management, artifact updates, and compliance reporting.
- Assist with security control assessments, evidence collection, control validation, remediation tracking, and preparation for independent assessments.
- Develop clear, technically accurate cybersecurity policies, procedures, plans, reports, and other technical documentation.
- Support cloud security assessments and authorization activities for federal cloud environments.
- Support FedRAMP authorization and compliance activities, including security documentation, control implementation, continuous monitoring, and remediation.
- Monitor federal cybersecurity requirements and assist systems and programs in maintaining compliance with FISMA, NIST, FedRAMP, agency policies, and other applicable requirements.
- Coordinate with government cybersecurity personnel, system administrators, engineers, cloud providers, and other stakeholders to resolve security and compliance issues.
Required Experience
Minimum of 5 years of progressively responsible cybersecurity experience, including at least 3 years supporting federal government cybersecurity, RMF, A&A, or information-system compliance activities. Candidates should demonstrate experience in several of the following areas:
Education
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related technical discipline is preferred. Four additional years of directly relevant cybersecurity experience may be substituted for a bachelor's degree.
Certifications
At least one current, relevant cybersecurity certification is preferred or required depending on the labor category. Appropriate certifications include CISSP, CGRC (formerly CAP), CISM, CompTIA Security+, or relevant AWS, Microsoft Azure, Google Cloud, or other recognized cloud security certifications.
Knowledge, Skills & Abilities
Strong knowledge of federal cybersecurity requirements and NIST security controls is required, along with the ability to translate technical security information into clear compliance documentation. The candidate should be capable of independently evaluating security-control evidence, identifying compliance gaps, tracking remediation activities, preparing authorization documentation, and communicating cybersecurity risks to both technical and non-technical stakeholders.
Physical Demands and Work Environment:
The work environment and physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
While performing the duties of this job, the employee is regularly required to talk or hear. The employee is frequently required, sometimes for extended periods, to walk, stand, or sit. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets, and fax machines. The employee is occasionally required to climb ladders or stairs; use hands to type, finger, handle, or feel; reach with hands and arms; balance, stoop, kneel, crouch, or crawl; and get in and out of vehicles. The employee must occasionally lift and/or move small or large objects up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, color vision, depth perception, and ability to adjust focus. While performing the outdoor field duties of this job, the employee will also be exposed to outside weather conditions and other conditions such as loud noises, fumes, odors, dust, etc. This position may require travel.
Note: This job description in no way states or implies that these are the only duties to be performed by the employee. He or she will be required to follow any other instructions and to perform any other duties requested by his or her supervisor. The statements herein are intended to describe the general nature and level of work being performed by the employee in this position. They are not to be constructed as an exhaustive list of responsibilities, duties, and skills required of a person in this position. Furthermore, they do not establish a contract for employment and are subject to change at the direction of Akhiok-Kaguyak, Inc.
Akhiok-Kaguyak, Inc is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, disability, or protected veteran status.
Akhiok-Kaguyak offers preference to qualified Akhiok-Kaguyak Native Corporation Shareholders and their descendants and spouses and to shareholders of other corporations created pursuant to the Alaska Native Claims Settlement Act, in accordance with Public Law 100-241 and Title 43 U.S. Code 1626(g) and Title 42 U.S. Code 2003-2(i).
Similar roles
-
Staff Security Engineer, Abuse Control
Stripe London, England, United Kingdom
-
Senior Infrastructure and Cloud Security Engineer (m/f/d)
ICE Services London, England, United Kingdom
-
Lead - Product Security Engineer
Rocketlane Chennai, Tamil Nadu, India
-
Lead Manager, IT Security Engineer
Make-A-Wish America $70K–$84K/yr
-
Staff Cloud Security Engineer
Xometry Quinte West, Ontario, Canada · $205K–$233K/yr
-
Fire Security Engineer
Allsaved Ltd Glasgow, Scotland, United Kingdom · £38K–£45K/yr