RMF Process Specialist (R-00181)

1 month, 3 weeks ago
Full-time
Mid Level
Cybersecurity
True Zero Technologies

True Zero Technologies

True Zero Technologies specializes in cybersecurity programs and software solutions, focusing on proactive defense and IT engineering services.

Internet Software & Services
11-50
Founded 2016

Description

  • Develop, revise, and maintain RMF policies, standard operating procedures, process guides, work instructions, templates, checklists, and governance documentation.
  • Document current-state and target-state RMF processes, including activities, decision points, handoffs, approvals, roles, responsibilities, and dependencies.
  • Translate regulatory, cybersecurity, and operational requirements into clear and actionable process documentation.
  • Gather workflow requirements and inputs from system owners, ISSOs, ISSMs, assessors, engineers, authorization personnel, and other stakeholders.
  • Define workflow steps, required data fields, supporting documentation, approval paths, notifications, escalation criteria, and completion requirements.
  • Support the development and maintenance of authorization documentation, including System Security Plans, control implementation statements, POA&Ms, risk assessments, and continuous-monitoring artifacts.
  • Review RMF documentation for accuracy, completeness, consistency, proper formatting, and alignment with established standards.
  • Maintain document version control, review schedules, approval records, change histories, and controlled-document repositories.
  • Support governance boards, process reviews, working groups, audits, and compliance assessments by preparing agendas, materials, reports, and action-item trackers.
  • Monitor adherence to RMF policies, procedures, documentation standards, and governance requirements, and identify areas requiring corrective action.

Requirements

  • Bachelor’s degree in cybersecurity, information technology, information systems, business, technical writing, or a related field, or equivalent professional experience.
  • 3 to 5 years of experience supporting RMF, cybersecurity compliance, governance, security authorization, or federal information assurance programs.
  • Working knowledge of NIST RMF, NIST SP 800-37, NIST SP 800-53, FIPS 199, FIPS 200, and federal authorization requirements.
  • Demonstrated experience developing policies, procedures, process maps, governance documents, templates, and technical or compliance documentation.
  • Experience gathering requirements and translating stakeholder inputs into documented workflows, business rules, roles, and approval processes.
  • Strong writing, editing, organization, facilitation, and stakeholder-coordination skills, with close attention to documentation quality and detail.
  • Ability to obtain a clearance may be required.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security GRC Specialist

SAP Fioneer 1K-5K Internet Software & Services

SAP Fioneer is seeking a Security GRC Specialist to strengthen and scale security governance, risk, and compliance practices across its financial services software products and operations.

15 hours, 54 minutes ago

VCE Reviewer - Biology

Atomi 51-250 Diversified Consumer Services

Atomi is seeking a casual VCE Biology Reviewer to review and improve educational content for high school students, ensuring it is accurate, engaging, and aligned with the VCE syllabus.

1 day, 15 hours ago

CyberSecurity Analyst

Avertium 251-1K IT Services

Avertium is seeking a Cybersecurity Analyst to support clients through proactive security monitoring, incident response, security administration, and alignment of business and IT security objectives.

Active Directory Cybersecurity HIPAA Juniper Linux Network Security Penetration Testing SQL Unix Windows Server
1 day, 15 hours ago

CyberSecurity Analyst

Avertium 251-1K IT Services

Avertium is seeking a Cybersecurity Analyst to support clients through proactive monitoring, security event response, technical guidance, and administration of application, web, and infrastructure security measures.

Cybersecurity HIPAA Juniper Linux Network Security Penetration Testing SQL Unix Windows Server
1 day, 15 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers