Back to the Career Market

Information Systems Security Engineer (RMF)

Saalex

Newport, Rhode Island, United States

About the role

Saalex is seeking a Information Systems Security Engineer (RMF) in Newport, RI to support the Naval Undersea Warfare Center Division Newport (NUWCDIVNPT). The selected candidate will support Assessment and Authorization (A&A) activities and assist in maintaining Authorizations to Operate (ATOs) for enterprise and Research, Development, Test & Evaluation (RDT&E) systems and networks. Position Type: Full-Time Salary: $60k-$70k annually (depending on experience) Work Location: Full-time onsite Essential Functions: - Support Assessment and Authorization (A&A) activities to maintain Authorizations to Operate (ATOs) in accordance with DoD and Department of the Navy RMF requirements. - Support cybersecurity compliance, security assessments, continuous monitoring activities, and information assurance efforts across Navy enterprise and RDT&E systems and networks. - Develop, review, and maintain RMF package documentation, including Security Plans, Risk Assessments, POA&Ms, architecture diagrams, asset inventories, and system/site policies and procedures. - Perform security control assessments in accordance with NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, CNSSI 1253, and applicable Navy cybersecurity guidance. - Execute Security Assessment Plans, review Security Test Reports, identify security deficiencies, and support risk mitigation activities. - Utilize cybersecurity tools including eMASS, ACAS, STIG Viewer, and STIG OSS Manager to assess, document, and monitor compliance. - Develop and maintain cybersecurity documentation including Contingency Plans, Contingency Plan Tests, Business Impact Analyses, and other required security artifacts. - Provide guidance on Navy RMF policies, DoD cybersecurity directives, NAVSEA business rules, and cybersecurity compliance requirements while supporting process improvement initiatives. - Provide RMF and eMASS guidance to team members and stakeholders and support cybersecurity training efforts as needed. - Attend stakeholder meetings, track action items, coordinate follow-up activities, and collaborate with government and contractor personnel to support successful A&A outcomes. - Other duties as assigned or required. Requirements Required: - Minimum of two (2) years of cybersecurity experience supporting RMF and Assessment & Authorization (A&A) activities. - Experience developing and maintaining RMF packages, including Security Plans, Risk Assessments, POA&Ms, and supporting documentation. - Experience with eMASS, ACAS, STIG Viewer, and cybersecurity compliance activities. - Working knowledge of NIST standards, RMF, DISA STIGs, and continuous monitoring requirements. - Ability to manage multiple priorities and communicate effectively with technical and non-technical stakeholders. - CompTIA Security+ or other DoD 8570/8140 IAM or IAT Level II certification required. Desired: - Experience supporting Navy, NAVSEA, or other DoD cybersecurity programs. - Experience conducting security control assessments and supporting ATO efforts. - Familiarity with cybersecurity process improvement initiatives and RMF policy development. - Experience providing cybersecurity training, mentoring, or technical guidance. - CAP, CASP+, CISSP, or other advanced cybersecurity certification. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related field preferred. Equivalent combination of education, certifications, military experience, and professional cybersecurity experience may be considered. Security Clearance: Active Secret clearance required. Requirements to obtain a clearance include US Citizenship, security investigation, etc. Benefits - Health Care Plan (Medical, Dental & Vision) - Retirement Plan (401k, IRA) - Life Insurance (Basic, Voluntary & AD&D) - Paid Time Off (Vacation, Sick & Public Holidays) - Short Term & Long Term Disability - Training & Development - Wellness Resources - Stock Option Plan