Please mention DailyRemote when applying
Location: This is a US-based remote position.
Employment Type: Full-Time
Security Clearance: No security clearance required. Minimum active Tier 1 (or higher) federal background investigation required prior to start; ability to obtain a CAC if required by duties.
Job Summary
Lucayan Technology Solutions LLC is seeking an RMF / Cybersecurity Compliance Specialist to support the U.S. Army Corps of Engineers (USACE) Walla Walla Business Intelligence (WWBI) program. This role owns cybersecurity compliance, Risk Management Framework (RMF) documentation, continuous monitoring, vulnerability management, and authorization artifacts, working closely with software developers, DevSecOps personnel, technical leadership, and Government stakeholders to ensure WWBI continuously complies with applicable Department of Defense (DoD), U.S. Army, USACE, and Civil Works Business Intelligence (CWBI) cybersecurity requirements. This position also supports maintenance of the WWBI authorization package and the program's planned migration into the CWBI Cloud and eventual integration into the CWBI security boundary.
Key Responsibilities
● Develop, update, and maintain WWBI Risk Management Framework authorization documentation, including the System Security Plan (SSP), Continuity of Operations Plan (COOP), Incident Response Plan (IRP), System Design Documents, and related authorization artifacts.
● Manage and document program-specific security controls applicable to the WWBI system, and support security requirements associated with Personally Identifiable Information (PII).
● Maintain documentation defining the WWBI authorization boundary, including applicable hardware, software, ports, protocols, interfaces, and data flows.
● Coordinate cybersecurity documentation and compliance activities associated with WWBI's migration into the CWBI Cloud and eventual incorporation into the CWBI authorization boundary.
● Maintain WWBI compliance records within the Enterprise Mission Assurance Support Service (eMASS), including uploading, mapping, organizing, and maintaining required RMF documentation, security-control evidence, implementation statements, and supporting artifacts.
● Support execution of the WWBI continuous-monitoring program, including coordinating and/or performing required ACAS and SCAP security scans, and maintaining a compliance score of at least 90% for applicable SCAP scans.
● Import and maintain security-scan results within DISA STIG Viewer and eMASS; analyze identified vulnerabilities and coordinate remediation activities with software developers and Government technical personnel.
● Track Critical and High findings for immediate remediation, Moderate findings for remediation within 60 days, and Low findings for remediation within 120 days; document approved exceptions and outstanding findings within the Plan of Actions and Milestones (POA&M).
● Develop, maintain, and submit the quarterly POA&M report detailing open, remediated, and outstanding security findings, and support quarterly updates to the RMF documentation package.
● Provide ACAS/SCAP scan results and associated STIG Viewer files following required scans, and maintain current system security, network topology, logical, and data-flow documentation in coordination with the development team.
● Complete and maintain security-control checklists required by the USACE CWBI Cloud environment, and monitor changes to CWBI cybersecurity requirements to coordinate implementation of new or modified requirements.
● Support annual Federal Information Security Management Act (FISMA) reporting requirements and associated forms, checklists, and documentation.
● Support compliance with applicable DoD Security Technical Implementation Guides (STIGs), Army cybersecurity requirements, and USACE policies, coordinating with developers and DevSecOps personnel to ensure applications and infrastructure remain compliant through modernization and cloud-migration activities.
Required Qualifications
● U.S. Citizenship required.
● Demonstrated experience supporting the DoD Risk Management Framework (RMF), including developing and maintaining RMF authorization packages and cybersecurity documentation.
● Experience using Enterprise Mission Assurance Support Service (eMASS).
● Knowledge of DoD, U.S. Army, and/or USACE cybersecurity requirements and processes.
● Experience with vulnerability management, security controls, POA&Ms, and continuous monitoring.
● Experience with ACAS, SCAP, DISA STIGs, and STIG Viewer.
● Ability to interpret technical vulnerability findings and coordinate remediation with software-development and infrastructure teams.
● Strong technical writing and documentation skills, with strong organizational skills and the ability to manage multiple recurring compliance requirements and deadlines.
● Ability to communicate effectively with technical personnel, program leadership, and Government stakeholders.
● Active federal background investigation at the Tier 1 level or higher prior to beginning contract performance.
● Ability to obtain and maintain CompTIA Security+ or a DoD-approved equivalent within six months of the contract start date, as applicable to the assigned DoD 8140 work role.
Preferred Qualifications
● Previous experience supporting USACE systems or applications.
● Experience supporting DoD systems through ATO authorization and continuous monitoring.
● Experience with AWS GovCloud or other DoD-authorized cloud environments.
● Familiarity with DevSecOps, GitHub, secure software-development pipelines, and application modernization.
● Experience supporting cloud migration of systems operating under an existing RMF authorization.
● Experience with FISMA reporting.
Certifications
● Active Tier 1 (or higher) background investigation prior to start.
● CompTIA Security+ or a DoD 8140-approved equivalent required within six (6) months of contract start.
● CISSP or another advanced DoD-recognized cybersecurity certification desired.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Legal
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“ I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!