1

Rmf Jobs (NOW HIRING)

RMF Engineer

San Diego, CA · On-site

$120K - $149K/yr

RMF Engineer Innovatus Technology Consulting Location: San Diego, CA or Norfolk/Suffolk, VA area (Hybrid - mostly remote) Clearance: Active DoD Secret clearance (minimum) required About Innovatus ...

RMF Lead

Fort Huachuca, AZ · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The RMF lead will perform RMF tasks for each system, capability and service using established Government guidelines and procedures. The lead will all coordinate with the Government Project Lead to ...

RMF Lead

Fort Huachuca, AZ · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The RMF lead will perform RMF tasks for each system, capability and service using established Government guidelines and procedures. The lead will all coordinate with the Government Project Lead to ...

Description RMF Engineer Xcelerate Solutions is seeking a RMF Engineer to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA ...

Description RMF Engineer Xcelerate Solutions is seeking a RMF Engineer to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA ...

Support RMF activities throughout the system lifecycle, including system categorization, control implementation, assessment, authorization, and continuous monitoring. * Work closely with system ...

RMF Analyst II

Oak Ridge, TN · On-site +1

$70K - $100K/yr

  • Medical

  • Retirement

  • PTO

As the RMF Analyst II you will directly liaison with the government customer to manage the review, audit, and authorization of Risk Management Framework (RMF) assessment and authorization (A&A)/ATO ...

RMF Analyst II

Oak Ridge, TN

$70K - $100K/yr

  • Medical

  • Retirement

  • PTO

As the RMF Analyst II you will directly liaison with the government customer to manage the review, audit, and authorization of Risk Management Framework (RMF) assessment and authorization (A&A)/ATO ...

RMF Analyst II

Oak Ridge, TN

$70K - $100K/yr

  • Medical

  • Retirement

  • PTO

As the RMF Analyst II you will directly liaison with the government customer to manage the review, audit, and authorization of Risk Management Framework (RMF) assessment and authorization (A&A)/ATO ...

RMF Subject Matter Expert

Lincoln, MA · On-site

$120 - $170/hr

RMF Subject Matter Expert Location: Hanscom Air Force Base Clearance: Secret - Top Secret Preferred Program: BLITS 3.0 Company/ Program Description: Centuria, a Service-Disabled Veteran-Owned Small ...

Description RMF Engineer - Intermediate Xcelerate Solutions is seeking a RMF Engineer to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support ...

RMF Engineer - Intermediate

Seaside, CA · On-site

$94K - $127K/yr

Description RMF Engineer - Intermediate Xcelerate Solutions is seeking a RMF Engineer to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support ...

The ISSO/RMF Lead is responsible for RMF compliance across two ATO systems ANG-DSS and AROWS supporting a shared user base of approximately 120,000 ANG service members (200,000+ total user accounts ...

next page

Showing results 1-20

RMF information

See salary details

$39K

$97.1K

$168K

How much do rmf jobs pay per year?

As of Aug 14, 2026, the average yearly pay for rmf in the United States is $97,123.00, according to ZipRecruiter salary data. Most workers in this role earn between $69,500.00 and $118,000.00 per year, depending on experience, location, and employer.

What are the primary responsibilities of an RMF specialist on a daily basis?

An RMF specialist typically oversees the implementation and documentation of security controls for information systems, ensuring continuous compliance with government and organizational regulations. Daily tasks may include conducting risk assessments, preparing security authorization documentation, communicating with stakeholders about security requirements, and staying updated on regulatory changes. They also collaborate closely with IT, cybersecurity, and compliance teams to address vulnerabilities and support audits. This role requires regular monitoring and reporting to maintain a secure and compliant operational environment.

What is an RMF?

An RMF (Risk Management Framework) job involves implementing security measures and compliance processes to protect an organization's information systems. Professionals in this role assess risks, develop mitigation strategies, and ensure adherence to federal cybersecurity regulations, such as those outlined by NIST. They often work with government agencies, contractors, and businesses handling sensitive data. RMF specialists conduct security assessments, document controls, and support continuous monitoring efforts to maintain system integrity and compliance.

What are the key skills and qualifications needed to thrive in the RMF position, and why are they important?

To excel as a Risk Management Framework (RMF) specialist, a solid background in cybersecurity principles, risk assessment, and knowledge of federal compliance standards is essential, often supported by a degree in information security or a related field. Familiarity with tools like eMASS, NIST guidelines, and certifications such as CISSP or CAP is highly advantageous. Strong analytical thinking, attention to detail, and effective communication skills set outstanding RMF professionals apart in this role. These skills are vital to ensure secure system operations and maintain regulatory compliance in sensitive environments.

What does an RMF analyst do?

An RMF analyst is responsible for managing the Risk Management Framework process, which involves assessing, implementing, and monitoring security controls to protect information systems. They often work with cybersecurity tools, conduct risk assessments, and ensure compliance with security standards such as NIST SP 800-37. The role requires strong analytical skills and knowledge of security frameworks and regulations.
More about RMF jobs

What cities are hiring for Rmf jobs?

Cities with the most Rmf job openings:

What are the most commonly searched types of Rmf jobs?

The most popular types of Rmf jobs are:

What states have the most Rmf jobs?

States with the most job openings for Rmf jobs include:

Infographic showing various Rmf job openings in the United States as of August 2026, with employment types broken down into 92% Full Time, 2% Part Time, and 6% Contract. Highlights an 86% Physical, 4% Hybrid, and 10% Remote job distribution, with an average salary of $97,123 per year, or $46.7 per hour.

RMF Engineer

Innovatus Technology Consulting

San Diego, CA • On-site

$120K - $149K/yr

Full-time

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

RMF Engineer
Innovatus Technology Consulting
Location: San Diego, CA or Norfolk/Suffolk, VA area (Hybrid – mostly remote)
Clearance: Active DoD Secret clearance (minimum) required
About Innovatus Technology Consulting
Innovatus Technology Consulting is a Service-Disabled Veteran-Owned Small Business (SDVOSB) headquartered in San Diego, California. Founded in 2012, we deliver mission-critical IT, cybersecurity, cloud engineering, and engineering solutions to Department of Defense and federal customers. Guided by ethics, experience, and expertise, we help defense organizations achieve operational readiness through secure, compliant, and innovative technology solutions.
Position Overview
Innovatus is seeking an experienced Risk Management Framework (RMF) Engineer to support Assessment & Authorization (A&A) activities for DoD systems in accordance with NIST and DoD RMF requirements. The role focuses on developing, maintaining, and managing RMF documentation and artifacts throughout the system lifecycle. This is a hybrid position that is mostly remote, with candidates based in the San Diego, CA or Norfolk/Suffolk, VA areas preferred to support occasional on-site collaboration, meetings, or program needs.
Key Responsibilities
  • Support system categorization by identifying information types, system boundaries, and information flows.
  • Develop, update, and maintain RMF artifacts, including System Security Plans (SSPs), Contingency Plans (CPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Continuous Monitoring Strategies, and supporting diagrams.
  • Assess and evaluate implemented security controls; identify gaps and work with engineering and cybersecurity teams on remediation.
  • Manage and validate RMF packages in eMASS (or equivalent DoD tools), including uploading artifacts and tracking authorization status.
  • Support continuous monitoring, ATO package preparation, and authorization/renewal processes.
  • Collaborate with system engineers, ISSOs/ISSMs, Security Control Assessors, Authorizing Officials, and government stakeholders.
  • Provide guidance on NIST SP 800-53 controls, DoD cybersecurity policies, STIGs, and RMF best practices.
  • Contribute to risk assessments, vulnerability management coordination, and compliance documentation as needed.
Required Qualifications
  • Active DoD Secret security clearance (minimum).
  • U.S. citizenship.
  • 3+ years of hands-on experience supporting DoD RMF processes and A&A activities.
  • Proven experience developing RMF artifacts (SSPs, CPs, control evidence, test plans, POA&Ms, etc.).
  • Strong familiarity with NIST SP 800-53, RMF steps (per NIST SP 800-37 / DoDI 8510.01), and authorization workflows.
  • Experience with eMASS (or similar authorization management systems) for package management and artifact validation.
  • Ability to work independently in a mostly remote environment while collaborating effectively with distributed teams.
  • Strong written and verbal communication skills for technical documentation and stakeholder interaction.
Preferred Qualifications
  • Experience supporting Navy, NAVWAR, or other DoD component systems.
  • Familiarity with additional tools such as ACAS, Nessus, or STIG Viewer.
  • Relevant certifications (e.g., CAP, Security+, CISSP, CISM, or DoD 8570/8140 IAM Level I/II).
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
What We Offer
  • Competitive salary and benefits package.
  • Mostly remote hybrid flexibility with work-life balance.
  • Opportunity to support high-impact DoD missions.
  • Professional growth in a mission-driven, veteran-friendly SDVOSB environment.
  • Collaborative culture focused on ethics, expertise, and results.

Powered by JazzHR

8jvRRseeDZ