1

Rmf Jobs in Kentucky (NOW HIRING)

$130 - $170/hr

The RMF Support/Senior will serve as the RMF Lead, integrating security and risk management activities into the system development life cycle while applying a risk-based approach to security control ...

$90 - $130/hr

Processing Risk Management Framework (RMF) Authority to Operate (ATO) packages for different systems in various steps of the RMF process. * Work with Client's Cybersecurity team to ensure teams goals ...

$90 - $130/hr

Lead the creation and management of RMF packages to support system authorization efforts * Conduct security assessments, vulnerability scans, and risk analyses * Support Authority to Operate (ATO ...

$140 - $190/hr

Maintain RMF documentation including SSPs, POA&Ms, SARs, hardware/software inventories, and securityartifacts. * Support cybersecurity assessments conducted by Security Control Assessors, penetration ...

$110 - $160/hr

This role is responsible for supporting Risk Management Framework (RMF) compliance, Authority to Operate (ATO) activities, continuous monitoring, cybersecurity audit readiness, and security ...

$85 - $130/hr

Supporting government Cyber lead in performing RMF activities leading to system RMF acceptance IAW DoDI 8510.01, NIST 800-series special publications, USAF policy and instructions, and guidance as ...

$150 - $190/hr

Lead RMF implementation supporting initial ATOs and Continuous ATO (cATO). * Serve as the cybersecurity lead supporting multiple mission value streams. * Develop and maintain RMF authorization ...

$99 - $225/hr

You Have * 5+ years of experience executing Department of Defense (DoD) Risk Management Framework (RMF) activities for DoD information systems, including across the RMF lifecycle, development and ...

New

$120 - $150/hr

Support system authorization, RMF, and continuous monitoring activities * Maintain security documentation and authorization artifacts in eMASS * Review and validate user access requests, training ...

$125 - $170/hr

Engineer and implement security controls supporting Risk Management Framework (RMF) authorization,Continuous Authority to Operate (cATO), and continuous monitoring objectives. * Identify, assess, and ...

$95 - $130/hr

Executing all phases of the RMF lifecycle: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor to include decommission * Development, maintenance, and continuous updating of ...

New

$180 - $200/hr

Apply JSIG, RMF, and NIST SP 800-series requirements to system design, control implementation, assessment, and authorization * Manually develop and maintain authorization artifacts and bodies of ...

$87 - $157/hr

Ensure the accreditation process for DoD systems (e.g., RMF accreditation) is completed and continually maintained in compliance with all applicable requirements. * Act as the primary point of ...

$175 - $190/hr

Lead RMF, Security Authorization & Continuous Assurance -- Own NIST RMF implementation, system authorization and ongoing authorization activities, including SSPs, control implementation documentation ...

$120 - $160/hr

Implements the Assessment and Authorization (A&A) processes under the Risk Managed Framework (RMF) for new and existing information systems. * Facilitates development of Memorandums of Understanding ...

$140 - $175/hr

Lead RMF and A&A lifecycle: coordinate system categorization, control selection, implementation, assessment, and authorization; produce and maintain the System Security Plan (SSP), Security ...

$131 - $237/hr

Guide the development team in interpreting and applying DoD cybersecurity policies, NIST RMF guidance, and DISA STIG requirements throughout system development and deployment. * Ensure full ...

$108 - $195/hr

The ISSM will develop and implement security policies, conduct risk assessments, manage system accreditations (RMF), and lead continuous monitoring efforts. This role requires collaboration with ...

$78 - $164/hr

Translate Risk Management Framework (RMF) categorization results and applicable security control baselines into implementable and testable system security requirements allocated across hardware ...

New

$94 - $197/hr

Translate Risk Management Framework (RMF) categorization results and applicable security control baselines into implementable and testable system security requirements allocated across hardware ...

New

next page

Showing results 1-20

Rmf information

See Kentucky salary details

$33.9K

$84.4K

$145.9K

How much do rmf jobs pay per year?

As of Aug 25, 2026, the average yearly pay for rmf in Kentucky is $84,354.00, according to ZipRecruiter salary data. Most workers in this role earn between $60,400.00 and $102,500.00 per year, depending on experience, location, and employer.

What is an RMF?

An RMF (Risk Management Framework) job involves implementing security measures and compliance processes to protect an organization's information systems. Professionals in this role assess risks, develop mitigation strategies, and ensure adherence to federal cybersecurity regulations, such as those outlined by NIST. They often work with government agencies, contractors, and businesses handling sensitive data. RMF specialists conduct security assessments, document controls, and support continuous monitoring efforts to maintain system integrity and compliance.

What are the key skills and qualifications needed to thrive in the RMF position, and why are they important?

To excel as a Risk Management Framework (RMF) specialist, a solid background in cybersecurity principles, risk assessment, and knowledge of federal compliance standards is essential, often supported by a degree in information security or a related field. Familiarity with tools like eMASS, NIST guidelines, and certifications such as CISSP or CAP is highly advantageous. Strong analytical thinking, attention to detail, and effective communication skills set outstanding RMF professionals apart in this role. These skills are vital to ensure secure system operations and maintain regulatory compliance in sensitive environments.

What are the primary responsibilities of an RMF specialist on a daily basis?

An RMF specialist typically oversees the implementation and documentation of security controls for information systems, ensuring continuous compliance with government and organizational regulations. Daily tasks may include conducting risk assessments, preparing security authorization documentation, communicating with stakeholders about security requirements, and staying updated on regulatory changes. They also collaborate closely with IT, cybersecurity, and compliance teams to address vulnerabilities and support audits. This role requires regular monitoring and reporting to maintain a secure and compliant operational environment.

What does an RMF analyst do?

An RMF analyst is responsible for managing and implementing the Risk Management Framework to ensure the security of information systems. They assess vulnerabilities, develop security plans, and ensure compliance with cybersecurity standards, often using tools like NIST guidelines. The role requires strong analytical skills and knowledge of cybersecurity protocols.

What are popular job titles related to Rmf jobs in Kentucky?

For Rmf jobs in Kentucky, the most frequently searched job titles are:

Infographic showing various Rmf job openings in Kentucky as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $84,354 per year, or $40.6 per hour.

Risk Management Framework (RMF) Support/Senior

On-site

Koniag, Inc.
Investment Management and Consulting Services • 501 - 1,000 employees

$130 - $170/hr

Other

Medical, Dental, Vision, Retirement, PTO

Posted 6 days ago


Job description

Smyrna, GA, USA

Job Description

Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Risk Management Framework (RMF) Support/Senior with a Secret security clearance to support KITS and our government customer in Smyrna, GA. This position is for a Future New Business Opportunity.

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.


Koniag IT Systems, a Koniag Government Services company, is seeking an experienced Risk Management Framework (RMF) Support/Senior professional to serve as the RMF Lead supporting our government customer. The ideal candidate is a seasoned cybersecurity professional with deep expertise in the RMF process, security control assessments, and risk management within federal government environments. The successful candidate will perform dual functions as both a Team Lead and Senior Functional Expert, serving as the single point of contact for government stakeholders on all RMF-related activities. An active ADP-II/Secret clearance is required for this position.


The RMF Support/Senior will serve as the RMF Lead, integrating security and risk management activities into the system development life cycle while applying a risk-based approach to security control selection and specification.

Principal responsibilities will include but are not limited to:

  • Serve as the RMF Lead and primary single point of contact for the Government Task Monitor (GTM) and the Assessment & Authorization (A&A) government lead.
  • Perform dual functions as Team Lead and Senior Functional Expert, providing guidance, oversight, and expertise to team members supporting RMF activities.
  • Conduct and oversee all activities that integrate security and risk management into the system development life cycle (SDLC), ensuring alignment with applicable laws, directives, Executive Orders, policies, standards, and regulations.
  • Apply a risk-based approach to security control selection and specification, considering effectiveness, efficiency, and applicable constraints.
  • Lead and perform security control assessments and residual risk determinations across all steps of the RMF process.
  • Oversee the preparation, review, and maintenance of A&A documentation packages, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports.
  • Coordinate with system owners, information system security officers (ISSOs), and other stakeholders to ensure continuous monitoring and compliance with security requirements.
  • Provide expert guidance on RMF process steps including Categorize, Select, Implement, Assess, Authorize, and Monitor.
  • Identify and communicate security risks, recommend mitigation strategies, and support the development of risk acceptance decisions.
  • Ensure compliance with most current DoW guidance and other applicable federal cybersecurity frameworks and directives.
  • Mentor and provide technical direction to junior team members engaged in RMF and A&A activities.

Education and Experience:
Required:

  • Bachelor's Degree with an emphasis in Information Technology Security, Cybersecurity, or a related field from an accredited college or university. Extensive experience in the required discipline may serve as a substitution for the Bachelor's Degree requirement.
  • Minimum of 7 years of experience in the certification and accreditation process of Information Systems within the U.S. Federal Government.
  • Without a Bachelor's Degree, a minimum of 10+ years of experience in the certification and accreditation process of Information Systems within the U.S. Federal Government is required.
  • Certified in accordance with most current DoW guidance as an IAM Level III.

Required Skills and Competencies:

  • Exceptional communication skills in English – both written and oral – with the ability to effectively communicate complex security and risk concepts to both technical and non-technical stakeholders.
  • In-depth knowledge and expertise across all steps of the RMF process as defined by NIST SP 800-37 and related publications.
  • Extensive experience conducting security control assessments and residual risk determinations.
  • Strong knowledge of NIST Special Publications, including SP 800-53, SP 800-53A, SP 800-30, and SP 800-137.
  • Experience preparing and reviewing A&A documentation packages including SSPs, SARs, POA&Ms, and Risk Assessment Reports.
  • Proficiency in applying a risk-based approach to security control selection and specification in compliance with applicable laws, Executive Orders, directives, policies, and regulations.
  • Demonstrated experience serving as a team lead or senior subject matter expert in a federal government IT security environment.
  • Strong understanding of the System Development Life Cycle (SDLC) and how security and risk management activities integrate throughout each phase.
  • Ability to act as the primary point of contact and liaison between technical teams and government stakeholders on all RMF-related matters.
  • Experience with continuous monitoring strategies and tools to ensure ongoing system authorization and compliance.

Desired Skills and Competencies:

  • Experience supporting DoD or other federal agency A&A efforts using tools such as eMASS (Enterprise Mission Assurance Support Service) or similar platforms.
  • Familiarity with additional cybersecurity frameworks such as FISMA, FedRAMP, or CMMC.
  • Experience with cloud security assessments and the application of RMF within cloud environments.
  • IAM Level III certifications such as CISM, CISSP, or GSLC.
  • Knowledge of zero trust architecture principles and their application within federal environments.
  • Experience supporting or leading teams in a government contracting environment.
  • Familiarity with vulnerability management tools and techniques, including STIG compliance and SCAP scanning.

Our Equal Employment Opportunity Policy

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristicprotected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

The company is dedicated to seeking all qualified applicants.

If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

Equal Opportunity Employer/Veterans/Disabled.Shareholder Preference in accordance with Public Law 88-352

#J-18808-Ljbffr

Koniag logo

About Koniag

Sourced by ZipRecruiter

Industry

Investment management and consulting services

Company size

501 - 1,000 Employees

Headquarters location

Kodiak, AK, US

Year founded

1972

Social media