Cybersecurity/RMF Specialist – Secret Clearance | Remote
Introduction
Cambridge International Systems, Inc. is a dynamic global team united by shared values: commitment, integrity, and perseverance. We are seeking a Cybersecurity/RMF Specialist to support our team.
Job Summary
This is a full-time, CONUS position requiring an active DoD Secret clearance. The role focuses on supporting system security throughout the development lifecycle in alignment with DoD/DoN RMF guidance.
Responsibilities
- Design, implement, and maintain system security controls across the RMF lifecycle, with emphasis on Stage 4 – Implementation
- Assess management, operational, and technical controls to evaluate compliance and risk posture
- Develop and maintain RMF documentation (SSPs, POA&Ms, SARs, SOPs, contingency plans, privacy impact assessments)
- Manage updates in eMASS and maintain system records in DADMS
- Perform STIG validations, vulnerability assessments, and annual RMF reviews
- Support audits, configuration management, and Configuration Control Board (CCB) activities
- Maintain inventories of authorized software, ports, protocols, and system components
- Provide cybersecurity reports, risk recommendations, and ATO strategy guidance to stakeholders
- Lead or support contingency planning, disaster recovery reviews, and tabletop exercises
Requirements
Qualifications
- Education & Experience: Bachelors preferred but not required, 5 to 7 years of experience in cybersecurity with focus on RMF, system security engineering, or A&A efforts
- Technical Expertise: Strong experience in experience across the 7 RMF lifecycle stages, especially Stage 4 (Implementation)
- Hands on experience with RMF documentation and DoD /DoN accreditation processes
- Familiarity with eMASS, DADMS, STIGs, GIAP/SNAP, and DoDI 8510 series
- Working knowledge of NIST SP 800-series and DoD cybersecurity policies
- Certifications: At least one of the following certifications is required
Similar jobs
Showing 10 jobs
Manager, Cyber Security
Application Security Engineer
Senior Director of Cyber Security Architecture and Engineering Services
Security Engineer
Network Security Engineer II
Security Engineer – Threat & Vulnerability Management
Security Engineer - GRC (Governance, Risk & Compliance)
Software Security Engineer - Corporate Platforms
Virtual CISO & Cybersecurity Practice Lead
Senior Product Security Engineer
