Remote / Alexandria, VA Clearance: Preferred US Gov Secret or above clearance (not a hard ... Implement and manage DoD STIGs, DISA baselines, and RMF controls in Infrastructure as Code (IaC)
Remote / Alexandria, VA Clearance: Preferred US Gov Secret or above clearance (not a hard ... Implement and manage DoD STIGs, DISA baselines, and RMF controls in Infrastructure as Code (IaC)
DevSecOps Engineer
Alexandria, VA · Remote
Remote / Alexandria, VA Clearance: Preferred US Gov Secret or above clearance (not a hard ... Implement and manage DoD STIGs, DISA baselines, and RMF controls in Infrastructure as Code (IaC)
Quick apply
DevSecOps Engineer
Alexandria, VA · Remote
Remote / Alexandria, VA Clearance: Preferred US Gov Secret or above clearance (not a hard ... Implement and manage DoD STIGs, DISA baselines, and RMF controls in Infrastructure as Code (IaC)
Cybersecurity Assessment and Authorization Subject Matter Expert (SME) (59788)
Fort Myer, VA · On-site +1
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF Execution: Supports execution of all phases of the RMF authorization process, including system ...
Cybersecurity Assessment and Authorization Subject Matter Expert (SME) (59788)
Fort Myer, VA · On-site +1
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF Execution: Supports execution of all phases of the RMF authorization process, including system ...
Cybersecurity Assessment & Authorization SME
Fort Belvoir, VA · On-site +1
$115K - $125K/yr
Description Remote role but must live within 150 miles of the following DLA Location: Ft. Belvoir ... Requirements KP-1 Enterprise RMF & Authorization Lead Purpose: Serves as the senior cybersecurity ...
Cybersecurity Assessment & Authorization SME
Fort Belvoir, VA · On-site +1
$115K - $125K/yr
Description Remote role but must live within 150 miles of the following DLA Location: Ft. Belvoir ... Requirements KP-1 Enterprise RMF & Authorization Lead Purpose: Serves as the senior cybersecurity ...
Enterprise AI Security Engineer
Washington, DC · Remote
$141K - $236K/yr
This role supports Authorization and Accreditation (A&A), Risk Management Framework (RMF) ATO ... For Remote Opportunities), education and certifications as well as Federal Government Contract ...
Enterprise AI Security Engineer
Washington, DC · Remote
$141K - $236K/yr
This role supports Authorization and Accreditation (A&A), Risk Management Framework (RMF) ATO ... For Remote Opportunities), education and certifications as well as Federal Government Contract ...
Cyber Security Assessment & Authorization SME
Vienna, VA · Remote
$105K - $125K/yr
We are hiring a Cyber Security Assessment & Authorization SME for an exciting remote opportunity ... They also communicate the status, progress, and outcomes of RMF activities by briefing senior ...
Quick apply
Cyber Security Assessment & Authorization SME
Vienna, VA · Remote
$105K - $125K/yr
We are hiring a Cyber Security Assessment & Authorization SME for an exciting remote opportunity ... They also communicate the status, progress, and outcomes of RMF activities by briefing senior ...
This position is fully remote. Responsibilities: * Develop, edit, and maintain cybersecurity ... Familiarity with: * NIST Risk Management Framework (RMF) * NIST SP 800-53 * FISMA * Federal ...
Quick apply
This position is fully remote. Responsibilities: * Develop, edit, and maintain cybersecurity ... Familiarity with: * NIST Risk Management Framework (RMF) * NIST SP 800-53 * FISMA * Federal ...
Cybersecurity Engineer - ISSO
Vienna, VA · On-site +1
$160K - $200K/yr
None Potential for Remote Work: ORA_ON_SITE Description SAIC is seeking a Cyber Security Engineer ... Execute RMF processes for Assessment & Authorization (A&A). * Develop/maintain SSPs, POA&Ms, SARs ...
Cybersecurity Engineer - ISSO
Vienna, VA · On-site +1
$160K - $200K/yr
None Potential for Remote Work: ORA_ON_SITE Description SAIC is seeking a Cyber Security Engineer ... Execute RMF processes for Assessment & Authorization (A&A). * Develop/maintain SSPs, POA&Ms, SARs ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF Program Governance Support: Provides program leadership supporting implementation and operation ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF Program Governance Support: Provides program leadership supporting implementation and operation ...
Understanding of DoD cybersecurity, safety, and RMF requirements for embedded systems * Experience ... While many positions offer remote or hybrid work options, these arrangements are subject to change ...
Understanding of DoD cybersecurity, safety, and RMF requirements for embedded systems * Experience ... While many positions offer remote or hybrid work options, these arrangements are subject to change ...
Undersea Systems Deputy Cyber Project Manager
Washington, DC · On-site +1
$112K - $257K/yr
Remote Work: No Job Number: R0244075 Location: Washington,DC,US Share job via: Share Undersea ... Coordinate RMF activities, security documentation development, and eMASS workflows. * Partner with ...
Undersea Systems Deputy Cyber Project Manager
Washington, DC · On-site +1
$112K - $257K/yr
Remote Work: No Job Number: R0244075 Location: Washington,DC,US Share job via: Share Undersea ... Coordinate RMF activities, security documentation development, and eMASS workflows. * Partner with ...
Manager, Cyber Security
Reston, VA · Remote
$115K - $156K/yr
... require RMF alignment, assessment documentation, POA&M management, contingency planning ... This position is remote within the United States. Please note that ICF monitors employee work ...
Manager, Cyber Security
Reston, VA · Remote
$115K - $156K/yr
... require RMF alignment, assessment documentation, POA&M management, contingency planning ... This position is remote within the United States. Please note that ICF monitors employee work ...
RAS Project Manager
Washington, DC · Remote
$135K - $165K/yr
... RMF, Governance, Risk & Compliance (GRC), Vulnerability Management, Incident Response, and Technical Operations teams to support research systems and applications. This position is fully remote.
Quick apply
RAS Project Manager
Washington, DC · Remote
$135K - $165K/yr
... RMF, Governance, Risk & Compliance (GRC), Vulnerability Management, Incident Response, and Technical Operations teams to support research systems and applications. This position is fully remote.
Cloud Security Engineer
Fort Belvoir, VA · On-site +1
$99K - $225K/yr
Remote Work: Hybrid Job Number: R0242418 Location: Fort Belvoir,VA,US Share job via: Share Cloud ... Develop Risk Management Framework (RMF) body of evidence artifacts, including system security plans ...
Cloud Security Engineer
Fort Belvoir, VA · On-site +1
$99K - $225K/yr
Remote Work: Hybrid Job Number: R0242418 Location: Fort Belvoir,VA,US Share job via: Share Cloud ... Develop Risk Management Framework (RMF) body of evidence artifacts, including system security plans ...
Understanding of DoD cybersecurity, safety, and RMF requirements for embedded systems * Experience ... While many positions offer remote or hybrid work options, these arrangements are subject to change ...
Understanding of DoD cybersecurity, safety, and RMF requirements for embedded systems * Experience ... While many positions offer remote or hybrid work options, these arrangements are subject to change ...
Task Order Project Manager (59843)
Fort Myer, VA · On-site +1
This is a fully remote position and contingent on contract award. Job Summary The TOPM provides ... RMF Program Management: Oversees contractor support activities associated with the Risk Management ...
Task Order Project Manager (59843)
Fort Myer, VA · On-site +1
This is a fully remote position and contingent on contract award. Job Summary The TOPM provides ... RMF Program Management: Oversees contractor support activities associated with the Risk Management ...
Cybersecurity Assessment And Authorization Subject Matter Expert (SME) (61123)
Fort Myer, VA · On-site +1
This is a fully remote role. Job Summary Serves as a Cybersecurity Subject Matter Expert (SME ... Briefs senior management on the status, progress, and results of RMF and authorization activities.
Cybersecurity Assessment And Authorization Subject Matter Expert (SME) (61123)
Fort Myer, VA · On-site +1
This is a fully remote role. Job Summary Serves as a Cybersecurity Subject Matter Expert (SME ... Briefs senior management on the status, progress, and results of RMF and authorization activities.
Cyber Policy Automation Specialist
Washington, DC · On-site +1
$69K - $158K/yr
Remote Work: Yes Job Number: R0242539 Location: Washington,DC,US Share job via: Share Cyber Policy ... Integrate Zero Trust, RMF, and mission assurance requirements into dashboard logic and automation ...
Cyber Policy Automation Specialist
Washington, DC · On-site +1
$69K - $158K/yr
Remote Work: Yes Job Number: R0242539 Location: Washington,DC,US Share job via: Share Cyber Policy ... Integrate Zero Trust, RMF, and mission assurance requirements into dashboard logic and automation ...
Lead Information System Security Officer (ISSO)
Washington, DC · On-site +1
$120K - $160K/yr
Public Trust Potential for Remote Work: ORA_HYBRID Description SAIC is seeking a Lead Information ... Ensure assigned systems remain aligned with NIST RMF, NIST SP 800-53, FISMA, and agency ...
Lead Information System Security Officer (ISSO)
Washington, DC · On-site +1
$120K - $160K/yr
Public Trust Potential for Remote Work: ORA_HYBRID Description SAIC is seeking a Lead Information ... Ensure assigned systems remain aligned with NIST RMF, NIST SP 800-53, FISMA, and agency ...
This is a full-time remote position; occasional travel may be required ( Job Duties and Responsibilities: * Own RMF controls documentation and evidence submission for the program ATO package ...
This is a full-time remote position; occasional travel may be required ( Job Duties and Responsibilities: * Own RMF controls documentation and evidence submission for the program ATO package ...
Remote Rmf information
See Centreville, VA salary details
$29.2K - $41.9K
23% of jobs
$45.6K is the 25th percentile. Wages below this are outliers.
$41.9K - $54.6K
6% of jobs
$54.6K - $67.4K
5% of jobs
$67.4K - $80.1K
6% of jobs
The median wage is $88.4K / yr.
$80.1K - $92.8K
14% of jobs
$92.8K - $105.5K
8% of jobs
$105.5K - $118.2K
12% of jobs
$118.6K is the 75th percentile. Wages above this are outliers.
$118.2K - $130.9K
8% of jobs
$130.9K - $143.6K
8% of jobs
$143.6K - $156.3K
5% of jobs
$156.3K - $169K
3% of jobs
$29.2K
$94.1K
$169K
How much do remote rmf jobs pay per year?
What is a remote RMF?
A Remote RMF (Risk Management Framework) job involves managing cybersecurity risk and compliance for an organization while working remotely. Professionals in this role ensure that IT systems align with federal security standards, such as those outlined by NIST. Responsibilities may include conducting risk assessments, implementing security controls, and maintaining compliance documentation. Remote RMF specialists often work with government agencies, contractors, or private companies handling sensitive data. This position requires expertise in cybersecurity policies, risk management, and regulatory compliance.
What are the typical daily responsibilities of a remote RMF?
As a Remote RMF Specialist, your daily responsibilities often include conducting security assessments, preparing and reviewing authorization packages, and ensuring ongoing compliance with federal information security standards. You'll collaborate with cross-functional teams to identify risks, develop mitigation strategies, and document security control implementations. Regular communication with stakeholders, participation in virtual meetings, and continual monitoring of systems and processes to ensure compliance are also core aspects of the job. This role leverages remote work tools to collaborate effectively with cybersecurity, IT, and compliance professionals across multiple locations.
What are the key skills and qualifications needed to thrive in the remote RMF position, and why are they important?
To thrive as a Remote RMF (Risk Management Framework) Specialist, you need a strong understanding of information security principles, federal risk management frameworks (such as NIST SP 800-37), and relevant cybersecurity policies, typically backed by a degree in information security or related field. Familiarity with security assessment tools, governance, risk, and compliance (GRC) software, as well as certifications like CISSP, CAP, or CISM, is highly valued. Excellent organizational skills, attention to detail, and the ability to communicate complex security concepts clearly are important soft skills. These capabilities are critical to ensure regulatory compliance and robust information system security in a remote work context.

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 9 days ago
Job description
Location: Remote / Alexandria, VA
Clearance: Preferred US Gov Secret or above clearance (not a hard requirement)
Whitespace is dedicated to delivering innovative technological solutions that meet the highest standards of security and compliance. We are seeking a highly experienced Senior DevSecOps Engineer to join our team and play a key role in strengthening our cybersecurity posture and supporting federal compliance requirements.
We are seeking a DevSecOps Engineer with deep expertise in DoD DevSecOps Reference Architecture, secure CI/CD implementation, and Defense cloud environments (AWS GovCloud, Azure Government, DoD Cloud or Air gapped environments). The ideal candidate combines hands-on engineering capability with a strong understanding of DoD cybersecurity requirements, RMF compliance, and infrastructure automation.
The Senior DevSecOps Engineer will lead efforts to integrate security practices into our development and operations processes, with a primary focus on assisting the company in obtaining and maintaining a DoD/DoW Authorization to Operate (ATO). If you're passionate about making a difference in the world and being part of groundbreaking technology in national security, this position is for you!
This position is 100% remote! We're looking for a candidate who is a U.S. citizen and resides in the contiguous United States. You'll be a W-2 employee of GeoDelphi, Inc., and we do not accept third-party applications. This role requires less than 20% travel.
Requirements
1. Secure CI/CD and Cloud Infrastructure
- Design, implement, and maintain secure CI/CD pipelines aligned with DoD Enterprise DevSecOps Reference Design (DSOP).
- Automate deployment of secure environments using Terraform, Ansible, or CloudFormation for DoD or FedRAMP-compliant systems.
- Integrate static code analysis (SAST), dynamic testing (DAST), container scanning and various security toolsets within pipelines to enforce continuous compliance.
2. Security Baselines & Compliance Integration
- Implement and manage DoD STIGs, DISA baselines, and RMF controls in Infrastructure as Code (IaC).
- Translate DoD security controls into automated enforcement and validation within development pipelines.
- Develop scripts and tools for compliance validation (e.g., OpenSCAP, Chef InSpec, PowerSTIG).
- Help co-develop & maintain technical documentation for RMF authorization and continuous monitoring processes.
3. Automation & Toolchain Management
- Implement and manage DevSecOps tools such as GitLab, Jenkins, ArgoCD, Harbor, Nexus, SonarQube, Anchore, etc.
- Automate container security and orchestrate deployments using Kubernetes (Big Bang, Iron Bank images or similar.
- Manage secret storage, credential rotation, and logging using Vault, DoD-approved KMS, or AWS Secrets Manager.
4. Collaboration and Governance
- Work closely with security, development, and operations teams to ensure alignment with DoD RMF, NIST SP 800-53, and/or FedRAMP.
- Collaborate with Information System Security Officers (ISSOs), Information Systems Security Managers (ISSMs) and Security Control Assessors for ATO package development.
- Serve as an internal primary subject matter expert in federal compliance standards and cybersecurity practices.
EXPERIENCE
- Bachelor's degree in Computer Science or related field (or equivalent experience).
- 7+ years of hands-on experience with DevSecOps in AI/ML or data-intensive systems.
- Familiarity with OpenShift or Kubernetes security hardening.
- Knowledge of Zero Trust Architecture (ZTA) concepts.
- Proven experience managing and driving successful ATO processes.
- Expertise with DevSecOps tools, practices, and frameworks.
- Strong understanding of federal security compliance standards (e.g., NIST 800-53, RMF, FedRAMP).
- Hands-on experience with cloud environments (AWS, Azure, or GCP) and containerization (Docker, Kubernetes).
- Strong scripting and automation skills (Python, Bash, or similar).
- Excellent leadership, communication, and documentation abilities.
- Active security clearance or eligibility to obtain one.
DESIRED SKILLS
- Previous experience directly supporting government contracting or federal agencies.
- Relevant certifications such as: Certified Kubernetes Administrator (CKA), AWS Certified Security or DevOps Engineer, HashiCorp Certified Terraform Associate
Benefits
GEODELPHI BENEFITS
- Medical, Dental, and Vision plans
- Unlimited PTO ⎯ Federal Holiday Paid Leave
- 12 weeks of paid Parental Leave
- Employer paid STD/LTD
- Employer Paid Life Insurance
- 401K plan and Employer Match Professional Development Assistance
- Equity Incentive Plan
Who we are: GeoDelphi, Inc. dba Whitespace is building AI solutions for global leaders. Recognized as the most innovative company in the Geospatial Industry, Whitespace exponentially accelerates speed-to-answer with powerful analytics, high-cadence data feeds, and human expert-machine teaming. Our answers are rooted in truth data about human activity, delivering reliable decision advantage that keeps pace with world events. Whitespace is headquartered in Alexandria, Virginia. For further information, visit: http://www.inthewhitespace.com.
GeoDelphi, Inc. is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, sex, sexual orientation, pregnancy, gender identity, national origin, disability, or Veteran status.