1

Rmf Jobs (NOW HIRING)

The ISSO/RMF Lead is responsible for RMF compliance across two ATO systems ANG-DSS and AROWS supporting a shared user base of approximately 120,000 ANG service members (200,000+ total user accounts ...

RMF/eMASS Specialist, Senior

Herndon, VA · On-site

$104K - $166K/yr

Lead RMF security assessment and authorization activities for enterprise systems across classified and unclassified DoDIN environments. * Interpret and apply DoD, Army, and ARNG cybersecurity policy ...

Cybersecurity /RMF Lead - Cloud

Suitland, MD · On-site

$150K - $165K/yr

The Cybersecurity / RMF Lead will work closely with system engineers, cloud architects, software developers, ISSMs, ISSOs, Security Control Assessors (SCAs), Authorizing Officials (AOs), and ...

New

The role involves conducting mid-level RMF analysis, System Security Plan development, and A&A coordination, ensuring compliance with cybersecurity standards. Responsibilities : • Assist RMF ...

They are seeking an experienced RMF Analyst III to oversee cybersecurity tasks and ensure compliance with Risk Management Framework (RMF) requirements. Responsibilities : • Assist Senior RMF ...

Sr. RMF Security Engineer

San Diego, CA · On-site

$131K - $237K/yr

Leidos has a new and exciting opportunity for a Sr. RMF Security Engineer in our National Security Sector's (NSS) Cyber & Analytics Business Area (CABA) . Our talented team is at the forefront in ...

Sr. RMF Security Engineer

San Diego, CA · On-site

$131K - $237K/yr

Leidos has a new and exciting opportunity for a Sr. RMF Security Engineer in our National Security Sector's (NSS) Cyber & Analytics Business Area (CABA) . Our talented team is at the forefront in ...

Guide enterprise RMF implementation: develop RMF plans, concepts of operations, authorization strategies, and organization-wide risk management approaches. * Coordinate selection, implementation ...

The Senior RMF Specialist/ISSO is responsible for guiding IT systems through the entire Risk Management Framework (RMF) lifecycle to achieve and maintain the Authority to Operate (ATO) for US Army G2 ...

Cybersecurity /RMF Lead - Cloud

Suitland, MD · On-site

$150K - $165K/yr

The Cybersecurity / RMF Lead will work closely with system engineers, cloud architects, software developers, ISSMs, ISSOs, Security Control Assessors (SCAs), Authorizing Officials (AOs), and ...

New

Guide enterprise RMF implementation: develop RMF plans, concepts of operations, authorization strategies, and organizationwide risk management approaches. * Coordinate selection, implementation ...

As the Platform Security & RMF Lead, you will own the authorization posture and platform-level security discipline for DEFCON AI's government-facing systems and integration platform. You are ...

New

E-logic is seeking a Security / RMF Lead to support the National Center for Health Statistics (NCHS) Office of Informatics, Governance, and Assurance (OIGA) under the VISION task order. Serving as a ...

As the Platform Security & RMF Lead, you will own the authorization posture and platform-level security discipline for DEFCON AI's government-facing systems and integration platform. You are ...

New

next page

Showing results 1-20

Rmf information

See salary details

$39K

$97.1K

$168K

How much do rmf jobs pay per year?

As of Jun 5, 2026, the average yearly pay for rmf in the United States is $97,123.00, according to ZipRecruiter salary data. Most workers in this role earn between $69,500.00 and $118,000.00 per year, depending on experience, location, and employer.

What is an RMF job?

An RMF (Risk Management Framework) job involves implementing security measures and compliance processes to protect an organization's information systems. Professionals in this role assess risks, develop mitigation strategies, and ensure adherence to federal cybersecurity regulations, such as those outlined by NIST. They often work with government agencies, contractors, and businesses handling sensitive data. RMF specialists conduct security assessments, document controls, and support continuous monitoring efforts to maintain system integrity and compliance.

What are the key skills and qualifications needed to thrive in the Rmf position, and why are they important?

To excel as a Risk Management Framework (RMF) specialist, a solid background in cybersecurity principles, risk assessment, and knowledge of federal compliance standards is essential, often supported by a degree in information security or a related field. Familiarity with tools like eMASS, NIST guidelines, and certifications such as CISSP or CAP is highly advantageous. Strong analytical thinking, attention to detail, and effective communication skills set outstanding RMF professionals apart in this role. These skills are vital to ensure secure system operations and maintain regulatory compliance in sensitive environments.

What are the primary responsibilities of an RMF specialist on a daily basis?

An RMF specialist typically oversees the implementation and documentation of security controls for information systems, ensuring continuous compliance with government and organizational regulations. Daily tasks may include conducting risk assessments, preparing security authorization documentation, communicating with stakeholders about security requirements, and staying updated on regulatory changes. They also collaborate closely with IT, cybersecurity, and compliance teams to address vulnerabilities and support audits. This role requires regular monitoring and reporting to maintain a secure and compliant operational environment.
What cities are hiring for Rmf jobs? Cities with the most Rmf job openings:
What are the most commonly searched types of Rmf jobs? The most popular types of Rmf jobs are:
What states have the most Rmf jobs? States with the most job openings for Rmf jobs include:
Infographic showing various Rmf job openings in the United States as of May 2026, with employment types broken down into 95% Full Time, 2% Part Time, and 3% Contract. Highlights an 82% Physical, 5% Hybrid, and 13% Remote job distribution, with an average salary of $97,123 per year, or $46.7 per hour.

Job description

Mission Objectives : The ISSO/RMF Lead is responsible for RMF compliance across two ATO systems ANG-DSS and AROWS supporting a shared user base of approximately 120,000 ANG service members (200,000+ total user accounts) across the ANGRC and 90 GSUs. This position ensures continuous compliance under FIAR and FISMA audits, maintains all system security artifacts within eMASS, manages DISA STIG implementation, and provides cybersecurity subject matter expertise IAW AFI 33-200, AFMAN 33-282, and DODI 8510.01. Position Responsibility Summary: Maintain system security artifacts (policies, procedures, evidence) for ANG-DSS and AROWS to support RMF control compliance IAW AFI 17-101 Document risk control item changes and manage eMASS records for both systems (26 Control Families, 431 Security Controls, 1,847 Assessments) Develop and maintain POA&Ms on all non-compliant controls; report progress in Monthly Status Reports Identify and implement DISA STIG requirements; coordinate remediation schedules with ANGRC IA and Network operations teams Review and implement security measures to meet IA/RMF directed actions from MTOs and STIGs Manage access control compliance for ~120K end-users: access request review, denials/approvals, inactivity suspensions, account restoral, and audit corrective actions Prepare reports and artifacts supporting DoD-initiated audits (FIAR/FISMA); develop Corrective Action Plans for audit findings Conduct annual RMF package reviews to ensure ATO maintenance; support eMASS-to-ITIPS data migration Verify all software purchases with ANGRC software manager to support vulnerability and security checks Manage risk management security software (Fortify or equivalent) for vulnerability scanning and correction Maintain and update security-related SOPs and protocols Provide SIEM expertise for real-time network visibility and cyberthreat detection/response Support CMDB/Enterprise Integration in alignment with SAF/FM CIO initiatives Support NGB/A1 responses to taskers and data calls regarding system health and ROI