RMF Lead - Risk Management Support Task Lead - Secret or TS at S2i2 Inc
, Illinois, United States -
Full Time


Start Date

Immediate

Expiry Date

29 Aug, 26

Salary

0.0

Posted On

31 May, 26

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Risk Management Framework, Information Systems Security Engineering, Vulnerability Management, Security Control Assessment, eMASS, ACAS, DISA STIGs, Azure, AWS, NIST SP 800-37, DoDI 8510.01, IAM Level III, CISSP, CISM, Zero Trust, Security Architecture

Industry

IT Services and IT Consulting

Description
Job Title: RMF Lead – Risk Management Support Task Lead Location: Scott AFB, IL - St. Clair County – On Site Clearance Required: Active Secret or Top-Secret Salary Range: $135K-$165K Based on Experience Application Deadline: June 30, 2026 Overview Leads the risk management support team on the Senior Information Security Officer (SISO) effort, managing on-site deliverables and serving as the day-to-day technical lead for Information Systems Security Engineering (ISSE), security control assessment, and vulnerability management across the approximately 40 systems in the portfolio. Executes the DoD Risk Management Framework (RMF) per DoDI 8510.01 and NIST SP 800-37 Rev 2 across on-premises and commercial cloud environments. Reports to the Task Order Program Manager and coordinates directly with the Government functional lead. Responsibilities - Lead execution of the DoD Risk Management Framework (DoDI 8510.01; NIST SP 800-37 Rev 2) across on-premises and commercial cloud (Azure/AWS) environments for assigned USTRANSCOM systems - Manage on-site deliverables and coordinate directly with the Government functional lead on priorities, schedules, and work products - Direct ISSE lifecycle support consistent with NIST SP 800-160 Vol I and Vol II, including security architecture and control-selection input - Oversee security control assessment and continuous monitoring, producing risk analyses and recommendations for the Security Control Assessor (SCA) and Authorizing Official (AO) - Lead vulnerability management - ACAS scanning, DISA STIG compliance, IAVM tracking, and POA&M development and remediation - Drive eMASS workflows (package build, control assessment, artifact review) and complete RMF triage within required timelines - Supervise team utilization, schedules, and the quality of risk-management work products across the support team - Brief risk posture, residual risk, and mitigation recommendations to Government stakeholders and S2i2 program leadership Minimum Qualifications - Minimum 7 years leading teams in Information Systems Security Engineering (ISSE), security control assessment, and vulnerability management within the DoD - Proven expertise applying the Risk Management Framework (RMF) to DoD systems - Active DoD 8570.01-M / 8140 Information Assurance Management (IAM) Level III certification (e.g., CISM or CISSP) - Demonstrated hands-on experience with eMASS, ACAS, and DISA STIGs - Active SECRET or TS clearance - Eligible for DoDD 8140.01 / DoDM 8140.03 cyber-workforce qualification (Foundational, plus Residential if assigned privileged access) at commencement of work Preferred Qualifications -Scott AFB, or other Combatant Command / Joint headquarters cyber experience -Prior service as a Security Control Assessor Representative (SCAR) on behalf of an SCA/AO -Experience managing RMF across a large multi-system portfolio (30+ systems) -NIPRNet and SIPRNet experience; commercial cloud (Azure/AWS) authorization experience -Familiarity with Zero Trust implementation across on-premises and cloud applications -Bachelor's degree in cybersecurity, information systems, or a related technical field About S2i2 S2i2 is a growing company with a supportive and inclusive culture and many opportunities for professional development and growth. We have created a supportive, family-like work environment where contributions are recognized. Regular company updates and open lines of communication with leadership fosters collaboration within the company. We are proud to include: Support to achieve professional certifications and degrees Leadership that is accessible to all employees Regular company updates Client networking social engagements Monthly team-building activities (past examples: Top Golf) Supporting our community - including veterans All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information
Responsibilities
Lead the risk management support team in executing the DoD Risk Management Framework across on-premises and cloud environments for USTRANSCOM systems. Manage on-site deliverables, oversee security control assessments, and brief risk posture to government stakeholders.
Loading...