RMF, Cybersecurity, and ATO Policy Consultant
Job Description
Delta Solutions & Strategies is hiring a full-time consultant to support HQ United States Space Force organizations at the Pentagon.
Responsibilities
- Analyze and develop national and military cyber strategy, doctrine, and policy to support creation of a new Risk Management framework
- Coordinate, develop, and integrate strategic guidance and policy documents
- Identify and review national cyber policy goals, objectives, and senior-level direction affecting USSF missions
- Conduct research, analyze findings, and provide recommendations to develop and evolve strategy, doctrine, and policy
- Evaluate, assess, and recommend actions for DoD and Intelligence Community (IC) RMF and Authority to Operate (AO) policies and requirements across multiple classification levels (up to TS/SCI) to support approval and re-certification for pilot efforts in digital capabilities, digital infrastructure, and software applications
- Provide expertise to support Security and Operations (DevSecOps), AI/ML algorithms, and other digital services
- Identify alternate strategies to manage risk to enterprise responsibilities while pursuing state-of-the-art capabilities
- Interface remotely and on-site with Department of the Air Force organizations in different geographic locales as needed to advise and support cyber and infrastructure needs
Requirements
- Bachelor’s Degree (Master’s preferred) plus a minimum of 5 years of experience analyzing program information system schemes or equivalent
- Strategic knowledge of processes within DAF to formulate and execute technology-related projects
- Ability to travel frequently or work remotely as needed
- Active TS/SCI Security Clearance
- Ability to identify and resolve challenges at the strategic level
- Ability to brief and interact with senior (GO/FLAG) officers and senior civilians while developing and writing doctrine and policy
- Experience coordinating doctrine and policy between staff agencies to support coherent planning efforts
- Previous cyber planning or doctrine experience at operational/theater level (e.g., combatant command, joint/combined task force) highly desired
- Previous experience on a CCMD, MAJCOM, HHQ, Joint Staff, OSD, etc. staff highly desired
- Deep understanding of Zero Trust principles and architectures
- Experience designing and implementing micro-segmentation, identity and access management (IAM), least privilege, and continuous monitoring
- Familiarity with relevant security frameworks: NIST 800-207, DoD Zero Trust Reference Architecture
- Expertise in network segmentation, firewalls, IDS/IPS, and network behavior analysis
- Knowledge of software-defined networking (SDN) and network function virtualization (NFV) for dynamic policy enforcement
- Strong understanding of MFA, SSO, RBAC, and PAM
- Experience with identity federation and directory services
- Experience with data encryption, DLP, and data classification
- Knowledge of data governance and compliance requirements relevant to space systems and operations
- Strong planning, organization, and communication skills for complex infrastructure modernization projects
- Expertise integrating systems and data across different security domains and classification levels
- Understanding of cross-domain solutions (CDS) and guard technologies
- Knowledge of multi-level security (MLS) networks, boundary protection mechanisms, and data diodes
- Experience with secure data transfer protocols and encryption technologies
- Understanding of current cyber threats targeting space systems and infrastructure
- Ability to analyze threat intelligence and translate it into actionable security measures
- Expertise in vulnerability scanning, penetration testing, and red teaming
- Ability to identify, prioritize, and remediate security vulnerabilities in space systems and ground segments
- Ability to work with multidisciplinary teams, including space and cyber experts
- Strong understanding of space systems, operations, and architectures
- Excellent communication, collaboration, and problem-solving skills
- Ability to adapt to rapidly evolving technologies and threats
- Strong work ethic and commitment to national security
Skills & Technologies
- Risk Management Framework (RMF), Authority to Operate (AO), TS/SCI
- DevSecOps, AI/ML
- Zero Trust, NIST 800-207, DoD Zero Trust Reference Architecture
- Micro-segmentation, IAM, least privilege, continuous monitoring
- Network segmentation, firewalls, IDS/IPS, network behavior analysis
- SDN, NFV
- MFA, SSO, RBAC, PAM, identity federation, directory services
- Data encryption, DLP, data classification
- Cross-domain solutions (CDS), guard technologies
- Multi-level security (MLS), data diodes, boundary protection mechanisms
- Threat intelligence, vulnerability scanning, penetration testing, red teaming
- Secure data transfer protocols
Location
- Pentagon, DC
- Onsite
Benefits
- Medical, Dental, Vision
- Life insurance
- 401(k)
- PTO, Paid holidays
- Parental leave, Military leave, Jury duty paid leaves