1

Rmf Jobs in Indiana (NOW HIRING)

next page

Showing results 1-20

Rmf information

See Indiana salary details

$37.1K

$92.4K

$159.9K

How much do rmf jobs pay per year?

As of Sep 7, 2026, the average yearly pay for rmf in Indiana is $92,419.00, according to ZipRecruiter salary data. Most workers in this role earn between $66,100.00 and $112,300.00 per year, depending on experience, location, and employer.

What is an RMF?

An RMF (Risk Management Framework) job involves implementing security measures and compliance processes to protect an organization's information systems. Professionals in this role assess risks, develop mitigation strategies, and ensure adherence to federal cybersecurity regulations, such as those outlined by NIST. They often work with government agencies, contractors, and businesses handling sensitive data. RMF specialists conduct security assessments, document controls, and support continuous monitoring efforts to maintain system integrity and compliance.

What are the key skills and qualifications needed to thrive in the RMF position, and why are they important?

To excel as a Risk Management Framework (RMF) specialist, a solid background in cybersecurity principles, risk assessment, and knowledge of federal compliance standards is essential, often supported by a degree in information security or a related field. Familiarity with tools like eMASS, NIST guidelines, and certifications such as CISSP or CAP is highly advantageous. Strong analytical thinking, attention to detail, and effective communication skills set outstanding RMF professionals apart in this role. These skills are vital to ensure secure system operations and maintain regulatory compliance in sensitive environments.

What are the primary responsibilities of an RMF specialist on a daily basis?

An RMF specialist typically oversees the implementation and documentation of security controls for information systems, ensuring continuous compliance with government and organizational regulations. Daily tasks may include conducting risk assessments, preparing security authorization documentation, communicating with stakeholders about security requirements, and staying updated on regulatory changes. They also collaborate closely with IT, cybersecurity, and compliance teams to address vulnerabilities and support audits. This role requires regular monitoring and reporting to maintain a secure and compliant operational environment.

What does an RMF analyst do?

An RMF analyst is responsible for managing and implementing the Risk Management Framework to ensure the security of information systems. They assess vulnerabilities, develop security plans, and ensure compliance with cybersecurity standards, often using tools like NIST guidelines. The role requires strong analytical skills and knowledge of cybersecurity protocols.

What job categories do people searching Rmf jobs in Indiana look for?

The top searched job categories for Rmf jobs in Indiana are:

What cities in Indiana are hiring for Rmf jobs?

Cities in Indiana with the most Rmf job openings:

Infographic showing various Rmf job openings in Indiana as of August 2026, with employment types broken down into 88% Full Time, 6% Part Time, and 6% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $92,419 per year, or $44.4 per hour.

Information Security Assurance Lead

Computer World Services

Indianapolis, IN • On-site

Full-time

Re-posted 18 days ago


Job description

Job Description
The Information Security Assurance Lead serves as the senior technical and management authority for Information Assurance (IA) and cybersecurity compliance efforts. This role provides expert-level oversight across Assessment & Authorization (A&A), Risk Management Framework (RMF), FISMA compliance, FISCAM audits, and overall IT security posture. The Lead is responsible for supervising IA personnel, coordinating security activities with stakeholders, and ensuring systems maintain Authority to Operate (ATO) and Authority to Connect (ATC).
This position requires deep technical acumen, leadership capabilities, and hands-on experience developing, maintaining, and governing enterprise-level security programs within Federal environments.
Key Tasks & Responsibilities
  • Leadership
  • Serve as the Team Lead, providing daily task direction, technical guidance, scheduling, and performance oversight for IA personnel.
  • Maintain expertise in emerging cybersecurity technologies, policies, and federal compliance standards.
  • Lead the planning, initiation, and execution of IT security projects, ensuring adherence to scope, deadlines, and cost targets.
  • Act as liaison between technical teams, program leadership, auditors, and Government stakeholders.
  • Provide advanced documentation development including installation guides, SOPs, troubleshooting procedures, vulnerability management reports, and configuration standards.
  • Provide expert-level technical and management leadership on complex cybersecurity tasks and programs.
  • Develop and implement security strategies supporting mission objectives and enterprise risk posture.
  • Direct major activities related to financial management, staffing, and security compliance.
  • Conduct strategic analysis, evaluations, and recommendations to improve system security, efficiency, and compliance.
  • Lead studies, surveys, data analysis, and problem identification initiatives, providing actionable recommendations to the Government.
  • Risk Management Framework (RMF)/Assessment & Authorization (A&A)
  • Perform and manage all RMF steps to obtain and sustain ATO/ATC for systems in compliance with DoD and DIA requirements.
  • Conduct periodic security assessments in accordance with DoD RMF, FISMA, and JWICS-related requirements.
  • Develop and maintain all required RMF artifacts, including:
  • Security Categorization
  • System Security Plan (SSP)
  • Control Validation/Implementation documentation
  • Implementation Plan
  • Plan of Action and Milestones (POA&M)
  • Acceptance of Risk (AOR)
  • Security Override Letter (SOL)
  • RMF package and Scorecard
  • Deliverables
  • Standard Operating Procedures (SOPs)
  • Incident Response Plan (IRP)
  • Continuity of Operations Plan (COOP)
  • Configuration Management Plan (CMP)
  • Appointment memos
  • DD2875s
  • Current ATO, ATC, and ATO with Conditions
  • Network diagrams and supporting technical documents

eMASS Responsibilities
  • Maintain system records in eMASS in accordance with DoD RMF and FISMA requirements.
  • Ensure all required artifacts, test results, and compliance actions are accurately entered into eMASS.
  • Coordinate with the CIO Validator for all RMF actions and approvals.
  • Maintain and track the ATO Status Process Calendar, ensuring all action items meet required compliance dates.

FISMA Compliance
  • Perform annual control testing, evidence collection, and compliance analysis.
  • Support internal and external FISMA reviews and assessments.

FISCAM Audit Support
  • Document and validate IT general controls applicable to the CCE infrastructure.
  • Support FISCAM audits and self-assessments; test and record results of annual IT general controls testing.
  • Update and enhance process documentation to address deficiencies identified during audits.

Security Monitoring & Protection
  • Plan, implement, upgrade, and monitor security controls to protect information systems and data.
  • Ensure appropriate safeguards are in place to protect digital assets and infrastructure.
  • Respond to security incidents, breaches, and vulnerabilities in accordance with approved procedures.
  • Coordinate mitigation strategies for all non-compliance issues.

Desired Skills and Experience
  • Expertise in federal cybersecurity frameworks including RMF, FISMA, NIST 800-series, and FISCAM.
  • Experience working with DoD, DIA, or IC security compliance programs.
  • Strong leadership skills and experience managing technical cybersecurity teams.
  • Excellent written and verbal communication skills for technical documentation and stakeholder engagement.
  • Proficiency with eMASS, vulnerability management platforms, configuration management tools, and audit tracking systems.

Education & Experience
  • Minimum Education
  • Bachelor's degree in a related field required.
  • Minimum General Experience
  • Ten (10) years of experience in Information Technology.
  • At least eight (8) years of experience as a Security Administrator or in a similar technical role, or a closely related IT discipline involving oversight of large, complex, multi-site programs.

Certifications
  • CISSP or equivalent required
  • Information Assurance Technical (IAT) II required
  • Computing Environment (CE) certification relevant to Microsoft, Linux, Cloud, or other privileged access technologies (required)
  • ITIL Required
  • Must maintain all mandatory certifications.

Security Clearance
  • Must be a U.S. Citizen.
  • Selective Service registration required (if applicable).
  • Top Secret Security Clearance required
  • Must maintain fitness and eligibility for national security positions.

Other (Travel, Work Environment, DoD 8570 Requirements, Administrative Notes, etc.)
  • Onsite at customer location

Computer World Services is an affirmative action and equal employment opportunity employer. Current employees and/or qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, disability, protected veteran status, genetic information or any other characteristic protected by local, state, or federal laws, rules, or regulations.
Computer World Services is committed to the full inclusion of all qualified individuals. As part of this commitment, Computer World Services will ensure that individuals with disabilities (IWD) are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact Human Resources at [email protected].
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.