CybersecurityJobs.io
← Back to all jobs

Job Description

Nortex Cyber Solutions supports mission-critical information systems with security authorization, assessment, and continuous monitoring. This onsite role in Fort George G Meade, MD helps teams keep systems compliant with established governance while partnering with cybersecurity and engineering stakeholders to implement and validate security controls.

Responsibilities

  • Support the full Risk Management Framework (RMF) lifecycle for information systems seeking or maintaining authorization.
  • Develop, review, maintain, and update system security authorization packages and supporting bodies of evidence.
  • Apply and interpret security controls and requirements in line with NIST SP 800-53 and DoD Instruction 8510.01 (RMF for DoD IT).
  • Use security package management and governance tools such as eMASS and Xacta to develop, maintain, track, and manage authorization documentation.
  • Scope and conduct assessments of systems undergoing accreditation/authorization or maintaining existing authorization.
  • Support preparation, coordination, and approval of Interim Authorizations to Test (IATTs) for systems requiring testing prior to full authorization.
  • Evaluate system configurations against DISA STIGs, CIS Benchmarks, and other security configuration standards.
  • Conduct and analyze vulnerability assessments using ACAS/SecurityCenter and Nessus.
  • Review vulnerability scan results, determine applicability and risk, track remediation, and support Plans of Action and Milestones (POA&Ms) as applicable.
  • Collaborate with system engineers, developers, and other stakeholders to implement and validate security controls.
  • Support automated solutions for continuous monitoring of security controls, vulnerabilities, configurations, and other requirements.
  • Identify automation opportunities to improve RMF, evidence collection, assessment, and continuous monitoring processes.
  • Appropriately leverage AI-enabled tools when beneficial, while maintaining sufficient cybersecurity and RMF expertise to understand, validate, and take responsibility for outcomes.
  • Maintain organized, accurate, and traceable documentation linking security requirements, controls, assessment results, findings, remediation activities, and supporting evidence.
  • Participate in Agile environments and work effectively within SAFe Agile processes.
  • Communicate security risks, findings, and requirements clearly to cybersecurity and engineering stakeholders.

Requirements

  • Active TS/SCI clearance with CI Polygraph required at time of hire.
  • Ability to access required classified environments and security packages within NSA systems.
  • Strong working knowledge of the DoD RMF and the complete authorization lifecycle.
  • Strong knowledge of NIST SP 800-53 security and privacy controls and DoDI 8510.01.
  • Experience developing, reviewing, and maintaining RMF authorization packages and supporting bodies of evidence.
  • Hands-on experience with eMASS and/or Xacta.
  • Strong understanding of DISA STIGs, CIS Benchmarks, system hardening, and security configuration requirements.
  • Experience using ACAS/SecurityCenter and Nessus for vulnerability scanning, analysis, and remediation support.
  • Experience scoping and conducting security assessments for systems undergoing or maintaining authorization.
  • Knowledge of the IATT process and experience supporting systems requiring authorization for testing.
  • Understanding of continuous monitoring requirements and approaches for validating security controls through the system lifecycle.
  • Ability to work with technical teams to develop or implement automation supporting cybersecurity and continuous monitoring activities.
  • Familiarity with SAFe Agile or similar Agile development environments.
  • Strong written and verbal communication skills.
  • Exceptional attention to detail, organization, documentation, and configuration management.
  • Ability to maintain clear traceability across security requirements, implementation details, assessment procedures, findings, and supporting evidence.

Preferred Qualifications

  • Experience supporting NSA, DoD, or Intelligence Community information systems.
  • Experience working directly with system owners, ISSMs, ISSOs, security control assessors, and Authorizing Official representatives.
  • Experience with continuous monitoring and automated security control validation.
  • Experience integrating security activities into CI/CD or DevSecOps environments.
  • Experience developing scripts, workflows, or automation to improve security assessment, evidence collection, vulnerability management, or compliance processes.
  • Familiarity with AI-assisted cybersecurity or compliance workflows, with the technical expertise necessary to independently verify AI-generated outputs.
  • Relevant cybersecurity certifications such as Security+, CISSP, CAP/CGRC, CASP+/SecurityX, or equivalent.

Benefits

  • 100% Company-paid medical insurance for employees
  • 100% Company-paid dental and vision insurance
  • Competitive salary
  • Generous 401k employer contribution with no required personal contribution and immediate vesting
  • Generous PTO and parental leave
  • Flexible work hours

Education & Experience

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field preferred.
  • 10+ years of relevant cybersecurity, information assurance, RMF, or systems security engineering experience.
  • Equivalent combinations of education, certifications, and directly relevant experience may be considered.

Location & Clearance

  • Location: Fort Meade, MD (onsite)
  • Clearance required for start: Yes
  • Clearance type: Top Secret/SCI with CI Polygraph

Physical Requirements

  • Ability to remain seated and work at a computer for extended periods.
  • Ability to occasionally lift up to 15 pounds.
  • Ability to communicate effectively in person and through virtual collaboration tools.

Similar Jobs