Gathering your results ...
16 days
Not Specified
Not Specified
Not Specified
<p>Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.</p> <p>RMC is hiring a Risk Management Framework (RMF) Analyst (Package Owner). The Risk Management Framework (RMF) Analyst plays a critical role in obtaining and maintaining authorization of core infrastructure systems managed by Data Center and Cloud Hosting Services (DC2HS). This position requires hands-on experience with Enterprise Mission Assurance Support Services (eMASS) to capture information and artifacts necessary for authorization in accordance with the Department of the Navy (DoN) RMF Process Guide, Navy Security Control Assessor Risk Assessment Guide, CYBERSAFE requirements, and other applicable agency policies.</p> <p>The RMF Analyst will collaborate with system owners, developers, and security personnel to identify, assess, and mitigate risks throughout the system lifecycle. A strong working knowledge of the Navy's RMF process and tools such as eMASSter and RAFT is essential.</p> <p>Responsibilities:</p> <ul> <li>Develop and maintain RMF documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms). </li><li>Determine applicable security controls in alignment with NIST 800-53 and other guidance. </li><li>Test and monitor security controls to ensure effectiveness. </li><li>Review and assess technical test results (e.g., ACAS scans, SCAP scans, EvaluateSTIG results, STIG checklists) and work with engineers/cybersecurity teams to resolve findings. </li><li>Conduct periodic security reviews and audits to maintain compliance. </li><li>Update Department of Defense Information Technology Portfolio Repository - Department of the Navy (DITPR-DON) records, if applicable. </li><li>Work closely with system owners, developers, and stakeholders to integrate security across the system development lifecycle (SDLC). </li><li>Provide RMF guidance and best practices to system owners. </li><li>Clearly communicate security risks, findings, and recommendations to leadership and stakeholders. </li><li>Stay current with evolving threats, vulnerabilities, and compliance requirements. </li><li>Recommend improvements to RMF documentation, processes, and reporting. </li></ul>
POST A JOB
It's completely FREE to post your jobs on ZiNG! There's no catch, no credit card needed, and no limits to number of job posts.
The first step is to SIGN UP so that you can manage all your job postings under your profile.
If you already have an account, you can LOGIN to post a job or manage your other postings.
Thank you for helping us get Americans back to work!
It's completely FREE to post your jobs on ZiNG! There's no catch, no credit card needed, and no limits to number of job posts.
The first step is to SIGN UP so that you can manage all your job postings under your profile.
If you already have an account, you can LOGIN to post a job or manage your other postings.
Thank you for helping us get Americans back to work!