
Senior RMF Specialist/Information System Security Manager (ISSM)
- Huntsville, AL
- Permanent
- Full-time
Responsibilities
- Develop and maintain Risk Management Framework (RMF) documentation and reports to achieve and maintain compliance with cybersecurity regulations, optimize current process to streamline approval process with Program Information Security System Manager (P-ISSM), Authorizing Official (AO) and Authorizing Official Designated Representatives (AODR) across the AMC Enterprise Mission Assurance Support System (eMASS) Portfolio for HQ and Enterprise records.
- Work in all steps of the RMF process with system owners, ISSO and ISSMs, and validate adequate security controls are in place to enable sound risk management decisions by the AO.
- coordinate with the Government in obtaining security authorization for updated systems and emerging requirements.
- Develop, implement, and maintain security policies, procedures, and documentation to ensure compliance with DoD security standards and regulations (e.g., NIST, RMF, FISMA).
- Achieve and maintain compliance with cybersecurity regulations, optimize current process to streamline approval process.
- Coordinate with the Government in obtaining security authorization for updated systems and emerging requirements.
- Support developing a Privacy Program Plan to streamline privacy risk assessments around system vulnerabilities, threat assessments, and operational mission impacts.
- Support development of the command cybersecurity program to include reviews of external Policies, Guidance, Standard Operation Procedures (SOPs), and regulations from Department of Defense (DoD), Department of Army, National Institute of Standards and Technology (NIST), etc.
- Develop internal plans, policies, SOPs to execute the command program with a policy development process.
- Provide Communication Security governance and compliance reporting based on Orders and directives from higher headquarters to maintain security of encapsulation and encryption devices. Develop a knowledge management plan to capture data and provide business intelligence and data analysis related to all functions.
- Provide exercise support to validate the security of systems accredited by the Authorizing Official and/or Privacy Official.
- Develop additional technical and managerial cybersecurity training plans, guides and materials to enable workforce knowledge and compliance.
- Interactions involving clients and interfacing with senior management and Government.
- Coordinate with cross-functional teams (engineering, IT, operations) to implement and enforce security protocols and best practices.
- Ensure the accreditation process for DoD systems (e.g., RMF accreditation) is completed and maintained in compliance with all applicable requirements.
- Act as the primary point of contact for security-related issues, coordinating incident response and reporting to senior management and government customers.
- Stay current with emerging cybersecurity threats, vulnerabilities, and trends to ensure the program adapts to evolving security challenges.
- May supervise others.
- Other duties as assigned.
- Associates Degree or Bachelor's Degree in Computer Science, Engineering, Cyber Security or equivalent experience in lieu of degree.
- 8+ years of experience in applying the Risk Management Framework (RMF) to complex IT systems, specifically within a DoD environment.
- 8+ years of overall cybersecurity experience, with at least 5 years in a leadership or management role.
- Experience with eMASS.
- Experience with system security engineering, risk management, and vulnerability assessments.
- Active certifications like CISSP, CISM, or equivalent DoDi 8540.02 compliance required
- Must have active Top Secret with SCI eligibility.
- Must have in-depth knowledge of DoD cybersecurity policies, frameworks, and compliance standards (e.g., NIST 800-53, RMF, FISMA, ICD 503).
- Must have a strong understanding of network security, security controls, and common cybersecurity tools (e.g., firewalls, IDS/IPS, SIEM, endpoint protection).
- Familiarity with cloud security practices and systems, particularly in a hybrid or government cloud environment
- Effective communication skills for information between various functional disciplines as well as strong briefing skills with senior customer and corporate leadership.
- Proven leadership skills including working in a team environment, fostering communication, listening to teammate concerns and reconciling internal issues or differences.
- Proven ability to solicit and process complex information and data to solve complex problems and make sound decisions.
- Analytical and strong organizational skills, with excellent verbal and written ability.
- Good work ethic and active desire to learn.
- Skillful time management and organizational skills to set and meet deadlines.
- Ability to work both independently and within a team.
- Ability to work effectively in a team environment to encourage collaboration, innovation, and continuous improvement.
- Ability to meet minimum clearance requirements.
- Ability to work nights, weekends, and holidays as required.
- Ability to travel up to 10%.