2

Remote Rmf Jobs in Virginia (NOW HIRING)

Remote / Alexandria, VA Clearance: Preferred US Gov Secret or above clearance (not a hard ... Implement and manage DoD STIGs, DISA baselines, and RMF controls in Infrastructure as Code (IaC)

Cybersecurity Engineer - ISSO

Vienna, VA ยท On-site +1

$160K - $200K/yr

None Potential for Remote Work: ORA_ON_SITE Description SAIC is seeking a Cyber Security Engineer ... Execute RMF processes for Assessment & Authorization (A&A). * Develop/maintain SSPs, POA&Ms, SARs ...

Manager, Cyber Security

Reston, VA ยท Remote

$115K - $156K/yr

... require RMF alignment, assessment documentation, POA&M management, contingency planning ... This position is remote within the United States. Please note that ICF monitors employee work ...

IA Engineer

Chantilly, VA ยท On-site +1

$99K - $225K/yr

Remote Work: No Job Number: R0245020 Location: Chantilly,VA,US Share job via: Share IA Engineer The ... Experience supporting RMF activities, including documentation in tools such as EMASS, SNOW, or ...

next page

Showing results 1-20

Remote Rmf information

See Virginia salary details

$29.2K

$94.1K

$169K

How much do remote rmf jobs pay per year?

As of Aug 16, 2026, the average yearly pay for remote rmf in Virginia is $94,111.00, according to ZipRecruiter salary data. Most workers in this role earn between $49,100.00 and $126,400.00 per year, depending on experience, location, and employer.

What is a remote RMF?

A Remote RMF (Risk Management Framework) job involves managing cybersecurity risk and compliance for an organization while working remotely. Professionals in this role ensure that IT systems align with federal security standards, such as those outlined by NIST. Responsibilities may include conducting risk assessments, implementing security controls, and maintaining compliance documentation. Remote RMF specialists often work with government agencies, contractors, or private companies handling sensitive data. This position requires expertise in cybersecurity policies, risk management, and regulatory compliance.

What are the typical daily responsibilities of a remote RMF?

As a Remote RMF Specialist, your daily responsibilities often include conducting security assessments, preparing and reviewing authorization packages, and ensuring ongoing compliance with federal information security standards. You'll collaborate with cross-functional teams to identify risks, develop mitigation strategies, and document security control implementations. Regular communication with stakeholders, participation in virtual meetings, and continual monitoring of systems and processes to ensure compliance are also core aspects of the job. This role leverages remote work tools to collaborate effectively with cybersecurity, IT, and compliance professionals across multiple locations.

What are the key skills and qualifications needed to thrive in the remote RMF position, and why are they important?

To thrive as a Remote RMF (Risk Management Framework) Specialist, you need a strong understanding of information security principles, federal risk management frameworks (such as NIST SP 800-37), and relevant cybersecurity policies, typically backed by a degree in information security or related field. Familiarity with security assessment tools, governance, risk, and compliance (GRC) software, as well as certifications like CISSP, CAP, or CISM, is highly valued. Excellent organizational skills, attention to detail, and the ability to communicate complex security concepts clearly are important soft skills. These capabilities are critical to ensure regulatory compliance and robust information system security in a remote work context.

What cities in Virginia are hiring for Remote Rmf jobs?

Cities in Virginia with the most Remote Rmf job openings:

Infographic showing various Remote Rmf job openings in Virginia as of August 2026, with employment types broken down into 92% Full Time, 4% Part Time, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $94,111 per year, or $45.2 per hour.

Defense - ISSM - Information Systems Security Manager/RMF

Tetrad Digital Integrity LLC

Arlington, VA โ€ข Remote

$200K/yr

Full-time

This job post hasย expired 1 day ago.ย Applications are no longer accepted.


Job description

Tetrad Digital Integrity (TDI) is a leading-edge cybersecurity firm with a mission to safeguard and protect our customers from increasing threats and vulnerabilities in this digital age.
TDI is seeking a Risk Management Framework (RMF) subject matter experts as Information Systems Security Managers to support cloud-based and Artificial Intelligence (AI) integrated systems. We are looking for candidates who have demonstrated experience building and maintaining RMF packages from development and through sustainment, are technically sharp, and ready to work in a fast-paced environment on some of the nations most advanced systems. We need experts who can support ATO efforts and turn DoW Component RMF, NIST 800-53, and Cloud SRG guidance into clear, defensible deliverables. These roles require in-depth knowledge of DoW requirements and the ability to independently lead and support complex systems integrating cloud IaaS/SaaS, custom applications and AI. if youโ€™re eager to build credibility fast, experience cutting edge technology, leading artificial intelligence models, and make a visible impact on mission systemsโ€”including cloud-native, containerized workloadsโ€”youโ€™ll fit right in. 
We have multiple openings supporting U.S. Navy and U.S. Marine Corps programs in the Northern Virginia area. Opportunities are available for both fully onsite and remote work, depending on skill set and security clearance level. Candidates must possess an active Secret or Top-Secret security clearance.RESPONSIBILITIES:
  • Lead and support RMF execution and customer coordination.
  • Provide expert guidance on DoW cloud security policies, NIST SP 800-53 controls, CNSS policies, and DoW-specific frameworks such as Cloud Computing SRG and AI-specific guidance.
  • Conduct security architecture reviews and security engineering analysis for cloud-native and containerized workloads.
  • Evaluate security controls associated with Kubernetes, Docker, and container orchestration platforms within cloud infrastructure.
  • Assess security risks related to generative AI components, including large language models (LLMs) and AI/ML workloads, ensuring responsible and compliant use.
  • Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action and Milestones (POA&Ms), and related RMF documentation.
  • Perform threat modeling, vulnerability assessments, and risk analysis tailored to cloud environments and AI technologies.
  • Interface with system architects, developers, and DevSecOps teams to integrate security throughout the Software Development Lifecycle (SDLC).
  • Support security control assessments (SCAs) and coordinate with third-party assessors.
  • Monitor, track, and report on security compliance posture through Continuous Monitoring (ConMon) processes.
  • Minimal travel will be required.
QUALIFICATIONS:
  • Active Secret or Top-secret security clearance.
  • Bachelorโ€™s degree in Cybersecurity, Computer Science, or Information Technology, and 8+ years of cybersecurity experience, including demonstrated experience supporting Risk Management Framework (RMF) activities for Department of War (DoW) systems.
  • Security certifications such as Certified Information System Security Professional (CISSP) and Certified Information System Manager (CISM).
  • Practical knowledge and application of concepts with cloud platforms. Experience with AWS, Azure and/or Google Cloud Platform (GCP), including IAM, VPC, Kubernetes, and security-related services are preferable.
  • Strong knowledge of containerized environments (e.g., Docker, Kubernetes) and container security best practices.
  • Familiarity with Generative AI technologies, including LLMs and AI/ML security considerations.
  • Deep understanding of NIST SP 800-53, DoD RMF, FedRAMP, and other relevant cybersecurity frameworks.
  • Experience with security risk assessments in DoW environments.
PAY RANGE:
The anticipated salary range for this position is $150,000 - $200,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range.

TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States.

โ€œTDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws.โ€