The posting
Job Description
SAIC is seeking an experienced Risk Management Framework (RMF) Specialist to support critical national security missions by ensuring the cybersecurity compliance and resilience of complex Department of Defense (DoD) information systems. In this role, you will guide systems through the full RMF lifecycle, collaborate with mission partners, and help shape secure architectures that protect the nation’s most sensitive assets.
Responsibilities
- Lead systems through all phases of the RMF process, including categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
- Serve as a cybersecurity advisor, connecting policy requirements with real‑world system design and implementation.
- Conduct risk assessments, review security test results, and recommend mitigation strategies including configuration changes, tool updates, and process improvements.
- Interpret, implement, and document security controls across networks, enclaves, and complex information systems in alignment with NIST SP 800‑53 and DoD guidance.
- Manage eMASS packages, support ACAS vulnerability identification, and track remediation and mitigation activities.
- Support monitoring, detection, analysis, and audit readiness through log review, security testing, and authorization documentation development.
Qualifications
- Bachelor’s degree in a STEM field and 9+ years of relevant experience (or 4 additional years of experience in lieu of a degree).
- Active Top Secret or DOE Q clearance with SCI eligibility (must be SCI‑eligible within the first 3 months).
- 5+ years of experience supporting RMF activities, including categorization, control implementation, assessment, and continuous monitoring.
- Experience supporting Assessment & Authorization (A&A) tasks such as POA&M maintenance, evidence collection, and security documentation.
- Experience applying cybersecurity controls from NIST SP 800‑53 Rev. 5 or DoD‑specific frameworks.
- Experience integrating Zero Trust principles into RMF packages and system architectures.
- At least one of the following certifications: CASP+, Security+, or SSCP.
Desired Skills
- Experience conducting security engineering analyses and advising system owners on risk impacts and mitigation strategies.
- Familiarity integrating RMF workflows into DevSecOps or Agile environments, including sprint‑based compliance and automated monitoring processes.
- Experience performing enterprise‑level risk assessments, documenting findings, and advising leadership on security posture and long‑term compliance strategies.
About Us
SAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.
We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.



