Sr. RMF Security Engineer

Leidos

Actively hiring
San Diego, CA Posted 65 days ago $131,300$237,350 / year

At a glance

AI generated

TL;DR

Leidos seeks a Sr. RMF Security Engineer to join its National Security Sector's Cyber & Analytics Business Area in San Diego, where the role involves guiding information systems through the Risk Management Framework lifecycle at a Navy base. The engineer will categorize systems based on risk, implement and assess security controls according to NIST standards and DoD requirements, conduct continuous monitoring, identify vulnerabilities, and recommend mitigation strategies. Essential qualifications include a relevant degree or equivalent experience, an active Secret clearance, RMF expertise, and proficiency with tools like eMASS, SCAP, SIEM systems, and STIG compliance. Preferred skills encompass automation scripting in Python, Bash, PowerShell, AI/ML integration, Zero Trust Architecture knowledge, CMMC 2.0 understanding, and CISSP certification.

Skills

NIST_SP_800_53 RMF eMASS SCAP SIEM STIG Python Bash PowerShell CI/CD Nessus Tenable_sc OpenSCAP Splunk ArcSight CMMC_2_0 Zero_Trust_Architecture

What you'll do

  • Conduct risk assessments and vulnerability scans for information systems.
  • Implement and assess security controls based on NIST SP 800-53 or DoD requirements.
  • Prepare System Security Plans (SSP), Security Assessment Reports (SAR), and POA&Ms.
  • Guide projects through the RMF lifecycle, ensuring compliance with federal cybersecurity standards.
  • Recommend mitigation strategies to address identified risks and vulnerabilities.

What we're looking for

  • Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science or related field with extensive experience.
  • DoD 8570 approved security certification required within 90 days of hire.
  • Active Secret DoD security clearance and US citizenship.
  • Deep expertise in RMF compliance including NIST SP 800-37, 800-53, 800-171, FedRAMP, and DIARMF.
  • Experience preparing SSPs, SARs, POA&Ms, conducting risk assessments, vulnerability scans, and penetration testing.
  • Proficiency with eMASS, SCAP tools (Nessus, Tenable.sc), and SIEM tools (Splunk, ArcSight).
  • Knowledge of STIG compliance (DISA STIGs, SCAP benchmarks).

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $164k
This role $184k
$103k most similar roles pay here $252k

This role pays more than 72% of similar roles. Most pay $142,400–$185,500 — the shaded band above. At the midpoint, this role pays about $184k versus about $164k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 214 open roles on FindRole.

Listed pay typically runs $107,900–$195,050 across 204 roles with salary data.

Most-posted roles

View all roles at Leidos

More like this

Similar roles

Sr. RMF Security Engineer

Leidos

San Diego, CA 7 days ago $131,300$237,350
NIST_SP_800_37 NIST_SP_800_53 FedRAMP DoD_Instruction_8510_01 eMASS SCAP SIEM STIG Python Bash PowerShell CI/CD CMMC_2_0 COMSEC CISSP

Cybersecurity and RMF Engineer, Mid

Booz Allen Hamilton

Arlington, VA 7 days ago $69,400$158,000
RMF NIST 800-53 Zero Trust STIGs DevSecOps AWS MSSQL Azure CI/CD IL5 DoD Cloud PoA&M Tracking Continuous Monitoring

Cybersecurity and RMF Engineer, Lead

Booz Allen Hamilton

Arlington, VA 35 days ago $112,800$257,000
RMF NIST 800-53 Zero Trust STIGs DevSecOps AWS MSSQL Azure CI/CD IL5 PoA&M continuous monitoring

Sr. Security Engineer

CoStar Group

Arlington, VA 13 days ago
AWS NGFW Python CASB SSE Terraform Azure DevOps CI/CD Subnetting Routing Network Isolation SSO OAuth API Tokens Service Principals AI Security Threat Modeling Risk Assessment Security Documentation High-Quality Technical Writing
Hybrid

Sr. WAF Security Engineer

Warner Bros. Discovery

Atlanta, GA 50 days ago $105,280$195,520
AWS Azure GCP Terraform CloudFormation Python Bash PowerShell Akamai Fastly NGWAF AWS WAF HTTP/S OWASP Top 10 API security Log analysis tools CI/CD DDoS mitigation CDN integrations Infrastructure as code
Hybrid

Sr. Engineer, Information Security

Green Dot Corp

Los Angeles, CA 26 days ago $113,400$162,000
IAM Sailpoint Saviynt Okta PCI DSS SOC2 ISO 27001 CIS Benchmarks MITRE ATT&CK Terraform AWS Azure GCP Python Bash Kubernetes Docker CI/CD Prometheus Grafana
Hybrid