RMF Assessment & Quality Assurance Lead

True Zero Technologies

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

Responsibilities

  • Lead quality assurance activities supporting the full Risk Management Framework (RMF) lifecycle
  • Review System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and supporting authorization documentation
  • Validate assessment evidence to ensure security controls are properly documented and supported
  • Coordinate assessment readiness activities across RMF analysts, ISSOs, system owners, and technical stakeholders
  • Develop and maintain quality review checklists, documentation standards, and authorization package review procedures
  • Identify documentation deficiencies, control implementation gaps, and process improvement opportunities
  • Support coordination with independent assessors during Security Control Assessments (SCAs) and annual assessments
  • Verify that remediation activities and POA&M updates are accurately reflected within authorization packages
  • Track assessment readiness metrics and recommend process improvements
  • Support continuous monitoring by validating ongoing updates to authorization documentation
  • Mentor RMF analysts and ISSOs on documentation quality and authorization best practices

Requirements

  • Bachelor's degree in Cybersecurity, Information Systems, IT, Computer Science, or related discipline
  • 5+ years of experience supporting Federal RMF, Assessment and Authorization (A&A), or cybersecurity governance
  • Experience reviewing authorization packages for quality and compliance with Federal requirements
  • Strong knowledge of NIST RMF, NIST SP 800-37, NIST SP 800-53 Rev. 5, NIST SP 800-53A, and FISMA
  • Experience supporting Security Control Assessments (SCAs), annual assessments, and continuous monitoring
  • Experience coordinating with ISSOs, System Owners, and Authorizing Officials
  • Excellent analytical, technical writing, and communication skills

Preferred Qualifications

  • Experience supporting NIH, HHS, or other Federal civilian agencies
  • Experience using JCAM, eMASS, ServiceNow GRC, or comparable platforms
  • Experience supporting High Value Assets (HVAs), cloud authorizations, or enterprise RMF programs
  • Familiarity with FedRAMP, common control inheritance, and Federal audit support
  • Certifications such as CGRC, CISSP, CAP, CISM, Security+, or PMP

Benefits

  • Competitive salary
  • 100% of medical premiums covered
  • 3 weeks of PTO + 11 Paid Holidays annually
  • 401k with 100% company match on the first 4%
  • Monthly reimbursement for Cell Phone and Home Internet
  • Paternity/Maternity Leave
  • Investment in training and certifications

Skills & tools

RMFNISTCybersecurity

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 01Bachelor's degree in Cybersecurity or related field
  2. 025+ years Federal RMF or A&A experience
  3. 03Knowledge of NIST SP 800-53 and FISMA
  4. 04Experience with Security Control Assessments (SCA)
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches