Risk Management Framework / Cybersecurity Specialist


4A-Consulting
Dice Job Match Score™
📋 Comparing job requirements...
Job Details
Skills
- NIST
- FISMA
- REDRAMP
- ATO
- Cybersecurity
- Risk Management
- Vulnerability
Summary
Company Overview
At 4A Consulting, we turn complexity into opportunity. Founded in 2014 and headquartered in Baltimore, MD, we are a women-owned, boutique consulting firm specializing in delivering innovative, data-driven solutions to both the Federal Government and Fortune 500 clients. Our team blends deep industry knowledge with advanced technologies to design tailored strategies that drive measurable and sustainable outcomes. We pride ourselves on an agile, collaborative approach that helps organizations navigate challenges and seize emerging opportunities in a rapidly evolving digital landscape. At 4A, we don’t just deliver projects, we build trusted partnerships that empower our clients to lead with confidence in the digital age.
Position Overview
We are seeking a Risk Management Framework / Cybersecurity Specialist to provide end-to-end Risk Management Framework (RMF) documentation and Authorization to Operate (ATO) support. In this role, you will work closely with Information System Security Officers (ISSOs), technical teams, and agency stakeholders using automated Security Authorization & Assessment (SA&A) tools to guide information systems through all seven steps of the NIST RMF lifecycle.
Key Responsibilities
- RMF & ATO Lifecycle Support
- Assist in establishing the framework for RMF implementation, identifying key stakeholders, defining boundary scopes, and conducting operational guidance/training.
- Guide stakeholders in classifying information systems and data types based on functionality, sensitivity, and organizational impact.
- Help select baseline security controls from NIST SP 800-53 and establish appropriate common control inheritance tailored to system boundaries.
- Support control implementation; assist ISSOs and stakeholders in establishing SI-2 (Flaw Remediation) and RA-5 (Vulnerability Monitoring and Scanning) reports for each system boundary.
- Provide support during Targeted Control Assessments and Continuous Monitoring Assessments, aiding ISSOs and stakeholders in collecting, organizing, and validating assessment artifacts.
- Review Security Assessment Reports (SARs), analyze residual risks, and recommend technical/operational mitigations to support executive ATO decisions.
- Drive continuous monitoring efforts across system lifecycles:
- Facilitate Plan of Actions and Milestones (POA&M) remediation with technical teams to mitigate audit findings and vulnerabilities, while tracking and reporting status to supervisors and ISSOs.
- Conduct semi-annual Quality Assurance (QA) reviews of assigned security boundaries and present findings to system leadership.
- Documentation & Stakeholder Management
- Independently author, review, and maintain System Security Plans (SSPs) and associated SA&A artifacts with minimal oversight.
- Gather security requirements, evaluate incoming requests, and interface effectively across agency SMEs, customers, and leadership.
- Lead stakeholder meetings, interviews, and working sessions independently.
Required Qualifications
- Master’s with 5+ years, Bachelor\''s 7+ years, or 13+ years of relevant experience.
- Deep, practical knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 controls, with direct experience conducting Security Control Assessments.
- Strong working knowledge of federal cybersecurity directives, including FISMA, FedRAMP, OMB Circulars, NIST standards, and HIPAA.
- Hands-on experience navigating RMF-related Security Authorization & Assessment (SA&A) tools (e.g., ServiceNow, eMASS, CSAM, or equivalent GRC platforms).
- Demonstrated track record of managing POA&Ms through remediation and working with vulnerability scanning/reporting datasets (SI-2/RA-5).
- Proficient with Microsoft Office 365 applications (Word, Excel, PowerPoint, Teams, SharePoint).
- Exceptional written and verbal communication skills with a proven ability to explain technical risk to diverse audiences and build consensus among stakeholders.
Preferred Qualifications
- The ideal candidate brings deep technical knowledge of NIST SP 800-37 and 800-53, hands-on experience with vulnerability reporting and POA&M remediation, and the ability to operate independently with minimal oversight.
Applicants must be legally authorized to work in the United States.
Why Join 4A
- Be part of a mission-driven, women-owned consulting firm with a reputation for excellence.
- Work on high-impact projects across federal and commercial clients.
- Collaborate in an inclusive, growth-oriented culture where innovation is valued.
- Access career development programs, mentorship, and learning opportunities.
- Enjoy a comprehensive benefits package, flexible work options, and a focus on work-life balance.
Equal Opportunity Statement
4A Consulting is an Equal Opportunity Employer committed to an inclusive hiring process. Applicants requiring a reasonable accommodation due to a disability may contact . This email is intended solely for accommodation requests.
Please note that 4A Consulting participates in the federal E-Verify program. Upon hire, we will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the US. 4A Consulting will only use E-Verify once you have accepted a job offer and completed the Form I-9.
- Dice Id: 91163794
- Position Id: 9033842
- Posted 13 hours ago
Company Info
About 4A-Consulting
Our employees tell us they came for an opportunity and stay because our culture makes 4A a great place to work. We invest in our people and help them leverage their strengths so that they thrive along with their company. We champion inclusion, collaboration, high performance, and opportunity; while never losing focus on doing the right thing for our customers. We offer direct employment, contract to hire, and long-& short-term contract positions.
We provide competitive salaries, great benefits, and the opportunity to expand your knowledge and gain new skills. Our management team has an open-door policy and is excited to entertain new ideas, explore better ways to get the job done, and implement suggestions to enhance our employees' work experience. If you’re interested in a career that is both challenging and rewarding, check-out our open positions below or contact our recruiting department.
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs