← Back to results

risk-management-framework-rmf jobs in San Diego

$96,600 – $96,600 · Posted 4 days ago

The Cyber Security Analyst develops and maintains assessment documentation, performs ongoing compliance assessments using tools like ACAS, SCAP, and Trellix, and conducts security audits and Site Based Security Assessments (SBSAs) of NCS Family of Systems. The role requires 5–8 years of cybersecurity experience, current DoD 8140-compliant IAT II certification (Security+ with appropriate CE/OS), and expertise in Risk Management Framework (RMF) v3/v5, System Security Plans (SSPs), POA&Ms, STIG remediation, and eMASS.… Responsibilities include patching verification, configuration and change management compliance, incident reporting, continuous monitoring, and potential appointment as Information System Security Officer (ISSO) within 6 months.

San DiegoLast seen 2 days ago
Posted 6 days ago

Serve as an independent, third-party cybersecurity assessor and RMF (Risk Management Framework) team lead for Navy systems under the NSWC Corona CCAM contract. Execute comprehensive security assessments of IT, PIT, and OT systems against DoD and NAVSEA standards; validate NIST 800-53 control implementations; analyze vulnerability data and STIG compliance; generate Security Assessment Reports and Risk Assessment Reports; and provide mentorship to ISSMs and ISSOs.… Requires NQV Level III certification, active TS/SCI clearance, seven years of cybersecurity experience with four years in RMF assessments, and DoD 8570 IAM Level II/III baseline certification.

San DiegoLast seen 4 days ago
Posted 6 days ago

Lead cybersecurity operations for Naval Surface Warfare Center Corona enclaves and Platform IT systems, owning the complete Risk Management Framework (RMF) Authorization to Operate process under DoD Instruction 8510.01. Oversee ISSOs and System Administrators, develop and maintain System Security Plans, Security Assessment Reports, and Risk Assessment Reports, and manage eMASS records for continuous compliance monitoring.… Direct incident response, enforce configuration management policies through Change Control Boards, and conduct STIG/ACAS/SCAP compliance reviews. Requires TS/SCI clearance, Master's in Computer Science/Cybersecurity or equivalent, 8+ years cybersecurity experience, and current DoD 8140/8570 Level III certification (CISSP, CISM, CASP+, or equivalent).

San DiegoLast seen 4 days ago
$110,000 – $135,000 · Posted 7 days ago

As an Information System Security Officer (ISSO), you will support Information Assurance and cybersecurity activities for cloud-based and classified DoD systems, with primary focus on Risk Management Framework (RMF) and Assessment & Authorization (A&A) processes to achieve Authority to Operate (ATO) approvals. You will prepare and maintain cybersecurity documentation, evaluate security solutions for compliance with DoD requirements, support security control implementation and assessment, and monitor operational security posture.… You will collaborate across engineering, cybersecurity, test & evaluation, and customer teams to resolve security issues and maintain authorization requirements. The role requires 3+ years of industry experience, working knowledge of RMF/DIACAP, IAT/IAM Level I certification (such as Security+), and an active DoD Secret Clearance with ability to obtain TS/SCI.

San DiegoLast seen 5 days ago
$93,535 – $155,892 · Posted 10 days ago

Network Engineer supporting Navy AT/FP systems will engineer, configure, and sustain Juniper, Aruba, and Cisco network equipment across NIWC Pacific and Naval installations worldwide. The role encompasses end-to-end system lifecycle management—staging, integration, testing, fielding, and sustainment—with emphasis on secure network architectures aligned with RMF and STIGs, system hardening, and compliance validation.… Requires hands-on expertise in Juniper (EX/QFX/SRX), Aruba (switching and wireless), Cisco (Catalyst, ISR, ASA), routing protocols (OSPF, BGP), VLANs, VPNs, and firewalls. Must hold an active interim Secret clearance with ability to obtain fully adjudicated Secret clearance, DoD 8570/8140 baseline certification (Security+, JNCIA, or CCNA minimum), and 5+ years experience with a bachelor's degree or 8+ years with HS diploma.

San DiegoLast seen 8 days ago
$80,000 – $104,000 · Posted 13 days ago

The Security Control Assessor – Representative will perform risk-based reviews and evaluations of system security plans (SSPs) for classified systems under the Risk Management Framework (RMF), making authorization recommendations. The role requires expert knowledge of NIST 800-53 security controls, DoD/DCSA policies, and the NISP eMASS platform to assess compliance artifacts, document findings, and provide defensible security authorization decisions.… The candidate must hold an IAT Level II certification (Security+, CCNA Security, CSA+, GICSP, GSEC, or SSCP) and an active Secret clearance to evaluate classified system packages against government technical standards.

San DiegoLast seen 11 days ago
$77,571 – $129,285 · Posted 14 days ago

Prepare, develop, and maintain Risk Management Framework (RMF) artifacts and packages to support system authorization and compliance with DoD standards. Perform risk and vulnerability assessments across networks, systems, and applications, and coordinate cybersecurity operations with technical leads to identify threats and develop mitigation strategies.… Implement security controls, execute compliance testing using industry tools like eMASS and ACAS, and deliver security briefings to stakeholders incorporating NIST controls analysis. Work independently to devise solutions, communicate technical findings to mixed audiences, and lead projects from inception through completion.

San DiegoLast seen 12 days ago
$107,900 – $195,050 · Posted 19 days ago

Lead cybersecurity and compliance activities for classified DoD and Special Access Program Information Systems. Manage Risk Management Framework (RMF) authorization packages, security control assessments, and continuous monitoring.… Coordinate with Security Control Assessors, Authorizing Officials, and Program Security Officers to achieve and maintain authorization to operate (ATO). Evaluate vulnerabilities, security deficiencies, and risks while developing mitigation strategies in a fast-paced, regulated environment.

San DiegoLast seen 17 days ago
Posted 22 days ago

This role manages continuous software sustainment and operational support for production systems in secure, multi-domain defense environments. You will perform tier 2/3 technical support, proactive vulnerability management, and technical debt remediation while executing zero-downtime deployments using Agile methodologies (Scrum, Kanban, SAFe).… You must maintain DISA STIG compliance, implement Risk Management Framework controls, and support Authority to Operate (ATO) activities. The position requires hands-on expertise with Linux and Windows Server administration, shell scripting (Bash/Python/Ansible), virtualization, SIEM/security monitoring, and DoD 8140 cyber workforce certifications.

San DiegoLast seen 20 days ago
$84,000 – $139,950 · Posted 26 days ago

This role performs continuous security monitoring, compliance assessments, and authorization documentation for Department of Defense information systems. The analyst will use tools like ACAS, SCAP, and eMASS to execute Risk Management Framework processes, conduct security audits, manage Plans of Action and Milestones (POA&Ms), and coordinate STIG remediation with system engineers and administrators.… The position requires 5–8 years of cybersecurity experience, current DoD 8140-compliant IAT II certification (Security+), and deep knowledge of RMF, system security plans, and automated compliance scanning. The analyst must be able to work independently, manage competing priorities, and be appointed Information System Security Officer (ISSO) within six months.

San DiegoLast seen 24 days ago
Posted 27 days ago

This role supports cybersecurity and compliance efforts across the Risk Management Framework (RMF) process for DoD programs. Responsibilities include developing and maintaining system security documentation, Plans of Action and Milestones (POA&Ms), assessing security controls, conducting vulnerability scanning and audits, and ensuring continuous monitoring of systems compliance.… The position requires IAM Level I certification (DoD 8570.1M), 4+ years of information security or cybersecurity experience, and hands-on proficiency with compliance and vulnerability scanning tools such as Nessus, SCAP, ACAS, and SCC on Windows, Linux, and network devices.

San DiegoLast seen 25 days ago
$95,000 – $125,000 · Posted 1 month ago

The ISSE will own an assigned eMASS package and drive interim authorization processes for a Navy client, ensuring RMF compliance and DoD cybersecurity guidance adherence. Key responsibilities include conducting STIG assessments, coordinating remediation activities, developing and maintaining POA&Ms, and supporting Microsoft 365 DDIL security testing.… The role requires a Bachelor's degree in Computer Science or related field, 3–5 years of RMF/cybersecurity accreditation experience, and a current DoD 8140 Level II certification (CISSP, CISM, CASP+, or CGRC). An active SECRET clearance is mandatory.

San DiegoLast seen 1 month ago
$80,001 – $120,000 · Posted 1 month ago

SAIC seeks a Network Engineer to support U.S. Navy cyber operations, providing engineering and technical support for the CND Deployer Toolkit and Defensive Cyber Operations Infrastructure.… Responsibilities include production integration, system design and architecture, DCO enclave technology implementation, interoperability testing, RMF compliance, site surveys, and Sensor2 system installations at Navy facilities. The role requires hands-on experience with Juniper SRX firewalls, Cisco routers/switches, IPsec/VPN tunnels, network design, and cybersecurity standards (STIGs, Security Controls); a Secret clearance, IAT Level II certification (Security+), and CCNA/CCNP/Network+ are mandatory.

San DiegoLast seen 1 month ago
$135,000 – $150,000 · Posted 1 month ago

Implement, assess, and authorize security controls for IT management systems under the Risk Management Framework (RMF). Conduct security reconnaissance, identify gaps, develop Plans of Action and Milestones (POA&Ms), and maintain A&A documentation (SSPs, SAPs, SARs).… Manage eMASS compliance, STIG assessments, and coordinate accreditation workflows. Requires 10+ years of cybersecurity experience, an active Secret clearance, IAT Level III certification (CISSP preferred), and hands-on A&A and ATO submission experience.

San DiegoLast seen 1 month ago
Posted 1 month ago

The Cybersecurity Engineer III will support Risk Management Framework (RMF) activities, Assessment & Authorization (A&A) processes, and continuous monitoring for DoD accredited systems. Responsibilities include developing and maintaining security documentation (SSPs, SAPs, SARs, POA&Ms), performing vulnerability assessments, managing eMASS tasking, and conducting security control validation and testing.… The role requires 10+ years in cybersecurity, RMF compliance, or incident response; expertise with eMASS, DISA STIGs, and vulnerability assessment tools; and an active Secret clearance with DoD 8570/8140 IAT Level III certification (CASP+, CCNP Security, CISA, CISSP, GCED, or GCIH).

San DiegoLast seen 1 month ago
$120,000 – $140,000 · Posted 1 month ago

The IT Cybersecurity Specialist will architect and implement ServiceNow security controls aligned with DoD cybersecurity requirements, including Role-Based Access Controls, Data Policies, and Edge Encryption. The role requires developing and maintaining RMF/ATO documentation, mapping configurations to NIST SP 800-53/800-171/172 and DoD IL4/IL5 controls, and managing Plans of Action and Milestones for vulnerability remediation.… The candidate will conduct continuous monitoring activities, compliance checks, and security assessments to maintain the Blue List platform's Authority to Operate and ensure alignment with DoD Zero Trust Strategy and CUI protection requirements.

San DiegoLast seen 1 month ago
$130,000 – $155,000 · Posted 1 month ago

Lyntris seeks a Cyber Security Engineer II to support Risk Management Framework (RMF) assessment and authorization for Navy software solutions. The role involves designing and implementing cybersecurity and information assurance policies for mission-critical systems, developing system documentation for RMF accreditation, and providing technical guidance on security scan remediation.… Required experience includes 2–3 years of Department of Navy accreditation work with NIST standards, eMASS, and ATO processes. The position requires an active U.S. national security clearance.

San DiegoLast seen 1 month ago
$69,300 – $158,000 · Posted 1 month ago

As a Cybersecurity Engineer and Risk Analyst, you will develop and implement security solutions to protect military infrastructure, performing vulnerability and compliance assessments using industry-standard tools like eMASS and ACAS. You'll troubleshoot complex security challenges, assess network and system threats, implement infrastructure controls, and communicate security risks to both technical and non-technical audiences.… The role requires 3+ years of experience leading Risk Management Framework (RMF) activities for DoD projects, vulnerability scanning, and security control implementation. You'll work closely with Navy missions to identify cyber risks, recommend solutions, and provide hands-on support using your knowledge of cybersecurity policy, networks, system infrastructure, and risk management.

San DiegoLast seen 1 month ago
$61,900 – $141,000 · Posted 1 month ago

As an information security risk specialist, you will work with DoD acquisition programs to identify cyber risks, assess threat landscapes, and develop mitigation strategies. You will conduct risk and vulnerability assessments across networks, systems, and applications, translate security concepts for stakeholders, and manage RMF (Risk Management Framework) and A&A (Assessment and Authorization) activities.… You need 4+ years of IT systems experience with DoD/government agencies, 3+ years leading Navy RMF projects, and expertise in security policy implementation, compliance assessment, and vulnerability mitigation. A Secret clearance and DoD 8140 Certification are required.

San DiegoLast seen 1 month ago
$69,300 – $158,000 · Posted 1 month ago

As a Cybersecurity Engineer and Risk Analyst, you will develop and implement security solutions to protect military infrastructure, performing risk and vulnerability assessments across networks, systems, and applications. You will leverage tools like ACAS, STIGs, and eMASS to assess security threats, implement infrastructure controls, and prepare Risk Management Framework (RMF) artifacts and Security Assessment Plans (SAP) for DoD customers.… You'll troubleshoot complex cybersecurity challenges, analyze big data security events to identify advanced threats, and communicate technical findings to both technical and non-technical audiences. The role requires 3+ years of IT experience with government/DoD agencies, hands-on RMF and A&A leadership, and an active TS/SCI clearance.

San DiegoLast seen 8 days ago
$130,000 – $159,987 · Posted 1 month ago

The RMF Engineer will support DoD Assessment & Authorization activities by developing, maintaining, and managing Risk Management Framework documentation and artifacts throughout the system lifecycle. Key responsibilities include system categorization, creating and updating security plans and control evidence, managing RMF packages in eMASS, assessing security controls, and coordinating with engineering and cybersecurity teams on remediation.… The role requires 3+ years of hands-on DoD RMF experience, deep knowledge of NIST SP 800-53 and RMF processes, and proficiency with authorization management tools. This hybrid position is mostly remote and demands strong technical documentation and stakeholder communication skills.

San DiegoLast seen 1 month ago
$69,300 – $158,000 · Posted 1 month ago

As a Cybersecurity Engineer and Risk Analyst, you will develop and implement security solutions to protect military systems, performing vulnerability assessments, risk analysis, and security compliance testing across networks, systems, and applications. You'll work with DoD Risk Management Framework (RMF) processes, manage security assessment and authorization activities, and use tools like eMASS, ACAS, and STIG scanning to identify threats and implement infrastructure controls.… The role requires 4+ years of IT experience with a DoD or government agency, 4+ years leading Navy RMF activities, and 3+ years implementing security controls and performing vulnerability remediation. You'll communicate security complexities to technical and non-technical audiences while supporting critical Navy mission areas.

San DiegoLast seen 1 month ago