RMF SME

ECS_FEDERAL
Washington, DC Full Time
POSTED ON 9/13/2023 CLOSED ON 9/14/2023

What are the responsibilities and job description for the RMF SME position at ECS_FEDERAL?

ECS is seeking a RMF SME to work in our Washington, DC office.

 

Job Description:

  • Be a driver of holistic and enterprise-scale changes in cyber-security programs within large Federal clients.  Act as a “disruptor to the status-quo” to drive needed changes to cybersecurity and related agency-wide workflows (Privacy, SDLC, procurement, etc.) to ensure that security and privacy best-practices and statutory and regulatory requirements are met in a holistic and cost-effective manner.
  • Provide consultation expertise at various levels with a large Federal agency to develop and maintain enterprise-scale cyber security program that reacts quickly to changing regulatory and operational drivers, including emerging technical, operational and management risk-drivers:
  • Participate in Daily, Weekly, and Monthly status meetings with key Government personnel, at times on short notice, to ensure stakeholders are informed of program status and progress on various cyber initiatives. Provide an opportunity to set priorities, identify opportunities or concerns, and coordinate resolution of identified problems.
  • Develop program level security documentation, audit liaison activities, and compliance oversight activities to strengthen the security program and promote compliance with the Risk Management Framework (RMF).
  • Support the performance of independent security and privacy control assessments in support of Security Assessment & Authorization (SA&A).
  • Support the management and implementation of continuous monitoring solutions to increase the visibility and transparency of network activity.

 

Required Skills:

  • A Bachelor's degree from an accredited college in systems engineering, computer science, computer engineering, information technology, management information systems or equivalent.
  • 8 years of Executive-Level cyber RMF consulting experience advising Cybersecurity programs in large federal organizations.
  • Strong interpersonal and human relations skills, including ability to communicate technical concepts to non-technical personnel.
  • Strong written, verbal, and presentation skills, including demonstrated ability to interact effectively with Senior Agency management and leadership.
  • Strong stakeholder management and engagement skills with staff at all levels, including ability to collaborate with people of varied technical backgrounds and management levels.
  • Advanced understanding of and experience with GRC tools, policy, procedures, and processes, including (but not limited to) FISMA audits and compliance, NIST, RMF, and recent Executive Orders.
  • Experience with NIST Risk Management Framework and Governance, Risk & Compliance (GRC) and Information Assurance capabilities/tools.
  • Strong familiarity with NIST Risk Management Framework at the subject matter expert level, particularly including SP 800-30, -37, -39, -137, -53, and -53A/B.
  • Ability to guide the development of enterprise-specific implementation guidance for agency management.
  • Ability to analyze and interpret Federal legislation, directives, Office of Management and Budget (OMB) mandates, and guidance provided by the National Institute of Standards and Technology (NIST) against existing information security and privacy policy to identify required updates.
  • Ability to conduct research on new and emerging information technologies and develop comprehensive information security and privacy policy, standards/guidelines, and procedures to facilitate the implementation of information security and privacy controls. Must have working knowledge of the Privacy Act of 1974 (as amended), the Federal Information Security Modernization Act (FISMA).
  • Manage the program team and oversee the development of Enterprise Information Security Trainings and Enterprise Outreach Campaign Plans.

 

Desired Skills:

  • Planning, developing, and implementing enterprise-scale cyber security programs for Federal Agencies.
  • Planning and overseeing cyber and information security policies, processes, and procedures management activities.
  • Experience managing Security Controls Assessment teams.
  • Experience overseeing the development and execution of security and privacy assessment plans in accordance with NIST SP 800-53A, as amended, requirements, for each security assessment project.
  • Experience overseeing enterprise-scale standards, guidance, administration, templates, reports, processes and procedures, and leverage communication vehicles used by the key stakeholders.
  • Knowledge of penetration testing principles, tools, and techniques.
  • Knowledge of an organization’s threat environment.
  • Experience with tools such as ServiceNow, Cylance, Tenable, Netsparker, Symantec DLP and Federal GRC tools (Xacta, CSAM, RSA Archer, Trusted Agent FISMA, Archangel, eMASS, etc.).

 

ECS is an equal opportunity employer and does not discriminate or allow discrimination on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state, or local law. ECS promotes affirmative action for minorities, women, disabled persons, and veterans.

 

ECS is a leading mid-sized provider of technology services to the United States Federal Government. We are focused on people, values and purpose. Every day, our 3800 employees focus on providing their technical talent to support the Federal Agencies and Departments of the US Government to serve, protect and defend the American People.

General Description of Benefits

Back
Apply Now
SME
Govcio LLC -
Washington, WA
Sme
ICF -
Reston, VA
RMF Cyber Analyst
clearAvenue -
Alexandria, VA

For Employer
Looking for Real-time Job Posting Salary Data?
Keep a pulse on the job market with advanced job matching technology.
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

Sign up to receive alerts about other jobs with skills like those required for the RMF SME.

Click the checkbox next to the jobs that you are interested in.

  • Access Control Skill

    • Income Estimation: $83,365 - $128,216
    • Income Estimation: $74,968 - $98,739
  • Data Analysis Skill

    • Income Estimation: $80,289 - $108,549
    • Income Estimation: $82,736 - $140,702
This job has expired.
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at ECS_FEDERAL

ECS_FEDERAL
Hired Organization Address Washington, DC Full Time
ECS is seeking a Requirements Analyst to work in our Metro DC area Hybrid Remote office . Please Note: This position is ...
ECS_FEDERAL
Hired Organization Address Warner, GA Full Time
ECS is seeking a Senior SIGINT System Engineer to work in our Warner Robins, GA office. Job Description: ECS is seeking ...
ECS_FEDERAL
Hired Organization Address Pittsburgh, PA Full Time
ECS is seeking an Oracle DBA (Int) to work in our Pittsburgh, PA office . Please Note: This position is contingent upon ...
ECS_FEDERAL
Hired Organization Address Morgantown, WV Full Time
ECS is seeking an Information Security Engineer (Senior) to work in our Morgantown, WV office Please Note: This position...

Not the job you're looking for? Here are some other RMF SME jobs in the Washington, DC area that may be a better fit.

RMF Analyst

BAE Systems, Sterling, VA

RMF Administrator

Booz Allen, Chantilly, VA