Title:
Senior RMF Policy Analyst
KBR is seeking a highly skilled Senior RMF Policy Analyst to support cybersecurity governance, Risk Management Framework (RMF) compliance, and Assessment & Authorization (A&A) efforts within a complex Department of Defense (DoD) environment. The successful candidate will serve as a trusted cybersecurity subject matter expert responsible for developing, maintaining, and enhancing RMF policies, standard operating procedures (SOPs), training materials, and documentation that support mission-critical systems and applications. This role requires extensive knowledge of DoD cybersecurity requirements, eMASS, NIST guidance, and DHA authorization processes, along with the ability to collaborate across technical and program teams to improve compliance, automate workflows, and ensure adherence to evolving cybersecurity standards.
The ideal candidate is a self-driven professional with strong analytical, communication, and leadership skills who can effectively manage multiple priorities while serving as a key advisor on RMF policy, cybersecurity documentation, training, and process improvement initiatives.
Role and Responsibilities:
- Review, analyze, and update existing A&A Process SOPs to reflect current Government-approved practices.
- Review and update, where and when needed, the existing certification/testing model so it reflects best business practices in information technology/security once approved by the Government.
- Review current processes and recommend/develop automated processes in the areas of application risk assessments and additionally update/map these processes to existing interactive workflows and processes in SharePoint.
- Function as the primary Point of Contact with responsibility for the development and maintenance of the cybersecurity SOPs.
- Provide subject matter expertise in the area of DoD and DHA A&A requirements.
- Ensure accuracy of the information introduced in the SOPs and institute and exercise proper change control mechanisms when proposing or making changes to the technical, functional, or contextual information contained in the SOPs.
- Ensure the accuracy and correctness of the procedures and processes in the SOPs by utilizing a thorough Quality Assurance (QA) plan.
- Maintain all RMF/DIACAP documentation templates associated with A&A efforts and associated deliverables.
- Create, maintain, and manage training materials for approval by the Government.
- Apprise users about available assistance as well as technical security products and techniques. Varying levels of security training are required depending on a person's roles and responsibilities.
- Attend weekly CCB/SCAR Tiger Team meetings and monthly ACAS/CMRS meetings to understand issues and changes which drive potential updates to training content.
- Understand how eMASS functions and provide responses to technical and cyber-related questions.
Basic Qualifications
- Bachelor's degree in Engineering, Physics, Network Security, Computer Science, or related field. In lieu of a degree, 15 years of relevant experience may be considered.
- Ten (10) years of experience in Engineering, Systems Analysis, Medical Systems, Cybersecurity, Web Development, or Engineering Management.
- Five (5) years of technical experience supporting cybersecurity, network protection, or virtualization projects.
- Demonstrated experience with RMF Steps 1-5.
- Working knowledge of eMASS (Enterprise Mission Assurance Support Service).
- Knowledge of NIST SP 800-53, NIST SP 800-37, CNSSI 1254, and applicable DoD Risk Management policies.
- Experience developing RMF cybersecurity documentation.
- Familiarity with vulnerability scanning and assessment tools used to identify, assess, and document compliance.
- Ability to lead teams and effectively interact with senior-level program personnel and government stakeholders.
- Ability to manage multiple priorities and projects simultaneously.
- Strong written, verbal, and customer service communication skills.
- Self-starter with the ability to work independently while collaborating in a dynamic team environment.
- Active Secret clearance required.
- Current CompTIA Security+ certification or DoD 8570 IAT/IAM Level I (or higher) certification required.
Preferred Qualifications
- Experience supporting the Defense Health Agency (DHA) Cyber Security Directorate.
- Experience developing, maintaining, or updating cybersecurity policies, SOPs, and training materials.
- Experience conducting cybersecurity training in virtual and/or classroom environments.
- Experience supporting Assessment & Authorization (A&A) efforts for DoD systems.
- Experience with SharePoint workflow development, process automation, and application risk assessment processes.
- Familiarity with RMF/DIACAP documentation templates and A&A deliverables.
- Advanced degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related technical field.
Scheduled Weekly Hours: 40 hours/week.
Compensation: $115,000-140,000. The salary range posted is based on the national average. The offered rate will be based on the selected candidate’s location, knowledge, skills, abilities, and/or experience, contract affordability, and in consideration of internal parity.
Additional Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels per internal policy or contractual designation. Additional compensation may be in the form of a sign-on bonus, relocation benefits, short-term incentives, long-term incentives, or discretionary payments for exceptional performance.
KBR Benefits: KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.
Belong, Connect and Grow here
We are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together.
We is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.