This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF Program Governance Support: Provides program leadership supporting implementation and operation ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF Program Governance Support: Provides program leadership supporting implementation and operation ...
Understanding of DoD cybersecurity, safety, and RMF requirements for embedded systems * Experience ... While many positions offer remote or hybrid work options, these arrangements are subject to change ...
Understanding of DoD cybersecurity, safety, and RMF requirements for embedded systems * Experience ... While many positions offer remote or hybrid work options, these arrangements are subject to change ...
Undersea Systems Deputy Cyber Project Manager
Washington, DC · On-site +1
$112K - $257K/yr
Remote Work: No Job Number: R0244075 Location: Washington,DC,US Share job via: Share Undersea ... Coordinate RMF activities, security documentation development, and eMASS workflows. * Partner with ...
Undersea Systems Deputy Cyber Project Manager
Washington, DC · On-site +1
$112K - $257K/yr
Remote Work: No Job Number: R0244075 Location: Washington,DC,US Share job via: Share Undersea ... Coordinate RMF activities, security documentation development, and eMASS workflows. * Partner with ...
... RMF). This role works closely with federal stakeholders, system owners, and technical teams to ... in a remote and on-site work environment. Success in this role means delivering high-quality ...
... RMF). This role works closely with federal stakeholders, system owners, and technical teams to ... in a remote and on-site work environment. Success in this role means delivering high-quality ...
RAS Project Manager
Bethesda, MD · Remote
$135K - $165K/yr
... RMF, Governance, Risk & Compliance (GRC), Vulnerability Management, Incident Response, and Technical Operations teams to support research systems and applications. This position is fully remote.
RAS Project Manager
Bethesda, MD · Remote
$135K - $165K/yr
... RMF, Governance, Risk & Compliance (GRC), Vulnerability Management, Incident Response, and Technical Operations teams to support research systems and applications. This position is fully remote.
Manager, Cyber Security
Reston, VA · Remote
$115K - $156K/yr
... require RMF alignment, assessment documentation, POA&M management, contingency planning ... This position is remote within the United States. Please note that ICF monitors employee work ...
Manager, Cyber Security
Reston, VA · Remote
$115K - $156K/yr
... require RMF alignment, assessment documentation, POA&M management, contingency planning ... This position is remote within the United States. Please note that ICF monitors employee work ...
RAS Project Manager
Washington, DC · Remote
$135K - $165K/yr
... RMF, Governance, Risk & Compliance (GRC), Vulnerability Management, Incident Response, and Technical Operations teams to support research systems and applications. This position is fully remote.
Quick apply
RAS Project Manager
Washington, DC · Remote
$135K - $165K/yr
... RMF, Governance, Risk & Compliance (GRC), Vulnerability Management, Incident Response, and Technical Operations teams to support research systems and applications. This position is fully remote.
Cloud Security Engineer
Fort Belvoir, VA · On-site +1
$99K - $225K/yr
Remote Work: Hybrid Job Number: R0242418 Location: Fort Belvoir,VA,US Share job via: Share Cloud ... Develop Risk Management Framework (RMF) body of evidence artifacts, including system security plans ...
Cloud Security Engineer
Fort Belvoir, VA · On-site +1
$99K - $225K/yr
Remote Work: Hybrid Job Number: R0242418 Location: Fort Belvoir,VA,US Share job via: Share Cloud ... Develop Risk Management Framework (RMF) body of evidence artifacts, including system security plans ...
Understanding of DoD cybersecurity, safety, and RMF requirements for embedded systems * Experience ... While many positions offer remote or hybrid work options, these arrangements are subject to change ...
Understanding of DoD cybersecurity, safety, and RMF requirements for embedded systems * Experience ... While many positions offer remote or hybrid work options, these arrangements are subject to change ...
Cybersecurity Assessment And Authorization Subject Matter Expert (SME) (61123)
Fort Myer, VA · On-site +1
This is a fully remote role. Job Summary Serves as a Cybersecurity Subject Matter Expert (SME ... Briefs senior management on the status, progress, and results of RMF and authorization activities.
Cybersecurity Assessment And Authorization Subject Matter Expert (SME) (61123)
Fort Myer, VA · On-site +1
This is a fully remote role. Job Summary Serves as a Cybersecurity Subject Matter Expert (SME ... Briefs senior management on the status, progress, and results of RMF and authorization activities.
Task Order Project Manager (59843)
Fort Myer, VA · On-site +1
This is a fully remote position and contingent on contract award. Job Summary The TOPM provides ... RMF Program Management: Oversees contractor support activities associated with the Risk Management ...
Task Order Project Manager (59843)
Fort Myer, VA · On-site +1
This is a fully remote position and contingent on contract award. Job Summary The TOPM provides ... RMF Program Management: Oversees contractor support activities associated with the Risk Management ...
Junior Security Control Assessor
Bethesda, MD · Remote
$100K - $115K/yr
Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...
Quick apply
Junior Security Control Assessor
Bethesda, MD · Remote
$100K - $115K/yr
Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...
Lead Information System Security Officer (ISSO)
Washington, DC · On-site +1
$120K - $160K/yr
Public Trust Potential for Remote Work: ORA_HYBRID Description SAIC is seeking a Lead Information ... Ensure assigned systems remain aligned with NIST RMF, NIST SP 800-53, FISMA, and agency ...
Lead Information System Security Officer (ISSO)
Washington, DC · On-site +1
$120K - $160K/yr
Public Trust Potential for Remote Work: ORA_HYBRID Description SAIC is seeking a Lead Information ... Ensure assigned systems remain aligned with NIST RMF, NIST SP 800-53, FISMA, and agency ...
Junior Security Control Assessor
Bethesda, MD · Remote
$100K - $115K/yr
Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...
Quick apply
Junior Security Control Assessor
Bethesda, MD · Remote
$100K - $115K/yr
Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...
Cyber Policy Automation Specialist
Washington, DC · On-site +1
$69K - $158K/yr
Remote Work: Yes Job Number: R0242539 Location: Washington,DC,US Share job via: Share Cyber Policy ... Integrate Zero Trust, RMF, and mission assurance requirements into dashboard logic and automation ...
Cyber Policy Automation Specialist
Washington, DC · On-site +1
$69K - $158K/yr
Remote Work: Yes Job Number: R0242539 Location: Washington,DC,US Share job via: Share Cyber Policy ... Integrate Zero Trust, RMF, and mission assurance requirements into dashboard logic and automation ...
This is a full-time remote position; occasional travel may be required ( Job Duties and Responsibilities: * Own RMF controls documentation and evidence submission for the program ATO package ...
This is a full-time remote position; occasional travel may be required ( Job Duties and Responsibilities: * Own RMF controls documentation and evidence submission for the program ATO package ...
Junior Security Control Assessor
Bethesda, MD · Remote
$100K - $115K/yr
Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...
Quick apply
Junior Security Control Assessor
Bethesda, MD · Remote
$100K - $115K/yr
Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...
System Security Administrator - Remote
Ashburn, VA · On-site +1
Details: System Security Administrator Location: 100% Remote Duration: Full time/Direct Hire ... RMF), and security compliance processes * Experience with Federal Information Security Management ...
System Security Administrator - Remote
Ashburn, VA · On-site +1
Details: System Security Administrator Location: 100% Remote Duration: Full time/Direct Hire ... RMF), and security compliance processes * Experience with Federal Information Security Management ...
Cybersecurity / IAM Engineer
Bethesda, MD · On-site +1
We are currently seeking a Cybersecurity / IAM Engineer to join our team in Bethesda (REMOTE ... Experience with DoD RMF, IL4/IL5, and FedRAMP cybersecurity and compliance requirements
Cybersecurity / IAM Engineer
Bethesda, MD · On-site +1
We are currently seeking a Cybersecurity / IAM Engineer to join our team in Bethesda (REMOTE ... Experience with DoD RMF, IL4/IL5, and FedRAMP cybersecurity and compliance requirements
Junior Security Control Assessor
Bethesda, MD · Remote
$100K - $115K/yr
Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...
Quick apply
Junior Security Control Assessor
Bethesda, MD · Remote
$100K - $115K/yr
Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...
Remote Rmf information
What is a remote RMF?
A Remote RMF (Risk Management Framework) job involves managing cybersecurity risk and compliance for an organization while working remotely. Professionals in this role ensure that IT systems align with federal security standards, such as those outlined by NIST. Responsibilities may include conducting risk assessments, implementing security controls, and maintaining compliance documentation. Remote RMF specialists often work with government agencies, contractors, or private companies handling sensitive data. This position requires expertise in cybersecurity policies, risk management, and regulatory compliance.
What are the typical daily responsibilities of a remote RMF?
As a Remote RMF Specialist, your daily responsibilities often include conducting security assessments, preparing and reviewing authorization packages, and ensuring ongoing compliance with federal information security standards. You'll collaborate with cross-functional teams to identify risks, develop mitigation strategies, and document security control implementations. Regular communication with stakeholders, participation in virtual meetings, and continual monitoring of systems and processes to ensure compliance are also core aspects of the job. This role leverages remote work tools to collaborate effectively with cybersecurity, IT, and compliance professionals across multiple locations.
What are the key skills and qualifications needed to thrive in the remote RMF position, and why are they important?
To thrive as a Remote RMF (Risk Management Framework) Specialist, you need a strong understanding of information security principles, federal risk management frameworks (such as NIST SP 800-37), and relevant cybersecurity policies, typically backed by a degree in information security or related field. Familiarity with security assessment tools, governance, risk, and compliance (GRC) software, as well as certifications like CISSP, CAP, or CISM, is highly valued. Excellent organizational skills, attention to detail, and the ability to communicate complex security concepts clearly are important soft skills. These capabilities are critical to ensure regulatory compliance and robust information system security in a remote work context.

Cybersecurity Task Order Project Manager (59835)
Fort Myer, VA • On-site, Remote
Full-time
Medical, Dental, Vision, Retirement
Re-posted 8 days ago
Job description
Job Summary
BMA is seeking a Cybersecurity Task Order Project Manager (TOPM) to support our DLA Cybersecurity Policy and Oversight Support Services (CPOSS)contract. The Cybersecurity TOPM provides senior leadership and operational management for the Cybersecurity Policy and Oversight Support Services (CPOSS) contract supporting DLA J6/J611 Cybersecurity (CS) Directorate. The TOPM is responsible for the overall execution, coordination, and delivery of all cybersecurity support services across the enterprise RMF program, CS policy development, continuous monitoring activities, audit readiness support, and cybersecurity workforce management initiatives. Working under the guidance of the Program Manager, the TOPM serves as the primary operational interface with Government leadership, including the Contracting Officer, Contracting Officer's Representative, and other government stakeholders. The TOPM ensures that technical solutions, schedules, and deliverables required under the task order are executed effectively and on schedule, while maintaining compliance with DoD cybersecurity policies and DLA enterprise CS governance objectives.
Key Responsibilities
- Leadership and Contract Execution: Serves as the project manager responsible for the overall execution and delivery of CPOSS requirements, ensuring all activities align with the mission priorities of the DLA CS program. Provide leadership and oversight to personnel supporting enterprise CS functions including RMF authorization oversight, continuous monitoring, CS policy development, workforce management, and audit readiness support. Ensure that all technical solutions, schedules, and deliverables identified in the contract are executed efficiently and in accordance with government expectations.
- Government Coordination and Stakeholder Engagement: Serves as the primary coordination point with Government leadership including the KO, COR, COTRs, and other DLA program stakeholders. Facilitates effective communication between government leadership, CS teams, and enterprise service areas to ensure alignment with DLA cybersecurity program objectives. Participates in leadership meetings, technical interchange meetings, and working groups supporting the enterprise CS governance mission.
- Program Planning and Project Management: Develops and maintains project management plans supporting the CPOSS contract lifecycle including project initiation, implementation, sustainment, and transition activities. Oversees preparation and delivery of key project artifacts including project plans, status reports, briefing materials, and IPR presentations. Monitors program performance metrics, schedule adherence, and task execution to ensure successful delivery of cybersecurity support services.
- Enterprise Integration and Technical Oversight: Performs enterprise-wide horizontal integration planning, ensuring CS support services align across multiple DLA systems, organizations, and enterprise service areas. Coordinates with CS analysts, policy specialists, and RMF practitioners to ensure consistent application of enterprise cybersecurity standards and processes. Provides strategic oversight for CS initiatives supporting enterprise risk management and compliance with DoD CS policies.
- RMF Program Governance Support: Provides program leadership supporting implementation and operation of the enterprise DoDI 8510.01 Risk Management Framework for DoD IT program. Ensures support activities properly align with enterprise RMF authorization processes, continuous monitoring activities, and CS policy development initiatives. Monitors CS program activities and provide leadership recommendations to improve CS governance and operational effectiveness.
Clearance Requirements
There is a Secret Security clearance requirement for this position.
Required Skills & Certifications
- Current Project Management Professional (PMP) certification.
- Current Risk Management Professional certification such as one or more of the following: PMP-RMP, ISACA Certified in Risk and Information Systems Control (CRISC), ISACA Certified Information Systems Auditor (CISA), ISACA Certified Information Security Manager (CISM), ISC2 Certified in Governance, Risk and Compliance (CGRC), or Risk and Insurance Management Society (RIMS) Certified Risk Management Professional (RIMS-CRMP).
- Current DoD 8670.01/8140 IAM Level III certification that includes one or more of the following: ISACA CISM, ISC2 Certified Information Systems Security Professional (CISSP), GIAC/SANS GIAS Security Leadership Certification (GSLC), or EC-Council Certified Chief Information Security Officer (CCISO).
- 6+ years of general Information Technology experience.
- 6+ years of cybersecurity experience supporting enterprise IT or cybersecurity programs.
- Demonstrated leadership experience managing projects of similar size, scope, and complexity.
- Strong knowledge of Risk Management Framework (RMF) processes and enterprise cybersecurity governance.
- Demonstrated ability to manage multidisciplinary cybersecurity teams supporting complex enterprise environments.
- Strong analytical, organizational, and problem-solving skills.
- Must be eligible for IT-II designation upon assignment.
- Proven ability to manage complex cybersecurity programs and coordinate across large enterprise organizations.
- Exceptional written and oral communication skills capable of supporting executive-level briefings.
- Ability to balance cybersecurity governance requirements with operational mission needs.
- Demonstrated capability to guide technical teams and ensure delivery of high-quality cybersecurity services.
Desired Skills & Certifications
- Experience supporting DoD or DLA program offices.
- Experience supporting DoD DLA environments.
- Experience leading enterprise-level cyber modernization initiatives.
- Familiarity with DLA-specific cybersecurity governance frameworks.
- Current Project Management Professional (PMP) certification.
- Current Risk Management Professional certification such as one or more of the following: PMP-RMP, ISACA Certified in Risk and Information Systems Control (CRISC), ISACA Certified Information Systems Auditor (CISA), ISACA Certified Information Security Manager (CISM), ISC2 Certified in Governance, Risk and Compliance (CGRC), or Risk and Insurance Management Society (RIMS) Certified Risk Management Professional (RIMS-CRMP).
Other Duties
- Able to travel within a week's notice.
- This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job.
- Duties, responsibilities, and activities may change at any time with or without notice.
Overview
BMA is an employee-owned small business headquartered in Huntsville, AL that provides superior customer service by empowering all levels of our staff to make timely decisions to produce high-quality results. BMA fosters an environment of passion, precision, and dedication in order to fulfill our commitments to our partners, government, and country.
Benefits
We believe that our employees well-being is paramount to our success so our benefits package has been crafted with that in mind. We offer multiple healthcare coverage options to include low deductible, high deductible, and plans eligible for our Health Savings Account (HSA) option. Along with medical coverage, employees have dental, vision, accident & illness, short- and long-term disability all available to them. BMA proudly maintains a 401(k) plan with an industry leading 6% match that can include profit sharing based on company performance. Lastly, being an employee-owned company means that BMA offers a 100% Employee Stock Ownership Plan (ESOP), providing eligible employees the opportunity to earn stock in BMA, subject to plan eligibility and vesting requirements.
AAP & EEO Statement
Beshenich Muir & Associates, LLC (BMA) is an Equal opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, religious creed, gender, sexual orientation, gender identity, gender expression, transgender, pregnancy, marital status, national origin, ancestry, citizenship status, age, disability, protected Veteran Status, genetics or any other characteristics protected by applicable Federal, State, or Local Law.