SonicJobs Logo
Left arrow iconBack to search

Risk Management Framework SME

Govcio LLC
Posted 3 months ago, valid for 16 days
Location

Seaford, VA 23696, US

Salary

$135,000 - $145,000 per year

Contract type

Full Time

Employee Assistance

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • GovCIO is hiring a Risk Management Framework Subject Matter Expert (SME) for a fully onsite position in Hampton, VA, at Joint Base Langley-Eustis.
  • The role requires a minimum of 9 years of experience in information system security management, particularly with hands-on experience using XACTA.
  • Key responsibilities include leading the DOD RMF process, ensuring compliance with security policies, and guiding system owners through the RMF lifecycle.
  • Candidates must hold a TS/SCI clearance and possess strong communication skills, with preferred qualifications including DOD 8140 IAM Level III certifications.
  • The posted salary range for this position is between $135,000 and $145,000 per year.

Overview

GovCIO is currently hiring for a Risk Management Framework SME to support modernization effort. This position will be located in Hampton, VA on Joint Base Langley-Eustis and will be a fully onsite position.

Responsibilities

We are seeking a highly skilled Risk Management Framework (RMF) Subject Matter Expert (SME) with a strong information system security manager (ISSM) background and hands-on experience with XACTA. You will guide system owners, engineering, teams and leadership through the full RMF lifecycle- ensuring compliance, managing documentation, and supporting secure system operations across classified and unclassified environments. This position is located at Langley Air Force Base, Hampton, Virginia.

 

Key Responsibilities

  • Lead and manage the full DOD RMF process for assigned systems
  • Provide ISSM-level oversight and guidance to ensure compliance with DOD, NIST and agency-specific security policies
  • Develop, maintain, and validate RMF documentation including System Security Plans, Security controls traceability matrices, POA&M, and systems categorization artifacts
  • Utilize XACTA for control implementation, evidence upload, package creation, workflow, management, and assessment preparation
  • Work closely with engineers, administrators, developers, and mission stakeholders to ensure secure design and architecture decisions
  • Lead assessment preparation activities and support independent audits, CCRI reviews, and Authorizing Official (AO) evaluations
  • Conduct vulnerability analysis, risk assessment and remediation planning
  • Guide continuous monitoring activities: STIG compliance, vulnerability scanning, patch management review, and incident documentation
  • Serve as a subject matter expert for cybersecurity policy interpretation, control inheritance, and risk acceptance recommendations
  • Provide training, mentoring and support to security analysts and program team members

Qualifications

High School with 9+ years (or commensurate experience)

Required Skills and Experience

Clearance: TS/SCI 

  • Proven experience supporting or performing duties as an ISSM or ISSO
  • Hands-on experience with XACTA for RMF package development
  • Experience with STIGs, ACAS, HBSS/Trellix, vulnerability management, and secure configuration baselines
  • Strong communication skills and the ability to brief leadership and stakeholders
  • DOD 8140 IAM Level III (CISSP, CISM, CCISO)

Preferred Skills and Experience 

  • Experience supporting complex, multi-system environments or programs of record
  • Experience supporting CCRI/ Command Cyber Readiness Inspections 
  • Experience with DOD networks (NIPR, SIPR, JWICS)

#DSG #NSS #MAVERICK #TM #TMK #mav002 

Posted Salary Range

USD $135,000.00 - USD $145,000.00 /Yr.



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.