DoD Risk Management Framework (RMF) and Assessment & Authorization (A&A) Continuous Monitoring (ConMon) and cybersecurity governance System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and POA&M management Security control implementation, validation, inheritance, and reciprocity Vulnerability management, STIG compliance, ACAS, and cybersecurity reporting eMASS, Xacta, or comparable Governance, Risk, and Compliance (GRC) platforms Microsoft Windows, Linux, virtualization, enterprise networking, and cloud environments supporting FedRAMP High and the DoD Cloud Computing Security Requirements Guide (SRG) Zero Trust Architecture (ZTA) and secure system engineering principles
The ideal candidate is a proactive cybersecurity leader capable of managing multiple complex DoD information systems while balancing mission requirements, cybersecurity risk, and regulatory compliance.
Success in this role requires strong leadership, technical expertise, and the ability to communicate cybersecurity risk effectively to senior Government decision-makers while enabling secure modernization and mission success through disciplined application of the DoD Risk Management Framework.