Essnova Solutions, Inc.

Government Contracting

Security/RMFLead

United States FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Security / RMF Lead at Essnova Solutions, Inc.. Skills: NIST RMF, SSP development, POA&M management, ATO packages. Maintain System Security Plans (SSPs). Manage Plan of Action & Milestones (POA&Ms)”

What You'll Achieve.

Ensuring integrity and compliance of federal information systems; Impact security posture and regulatory compliance; Timely updates after security-impacting changes; Remediation within mandated timelines; Support submission within 30 days of contract award

Industry & Context.

Government Contracting
Problems you'll solve

Risk analysis

Eligibility Requirements

Active Tier 4 / High Risk / Public Trust Level 6+ clearance, Eligibility for HSPD-12/PIV, Availability to work during Eastern Time (ET) business hours

What They're Looking For.

Must Have

Bachelor's degree in cybersecurity, information assurance, computer science, or a related field, 6+ years of federal information security experience applying NIST RMF (NIST SP 800-37), Experience developing and maintaining SSPs, POA&Ms, and ATO packages for FIPS 199 Moderate or higher systems, Experience using vulnerability scanning results to track remediation to closure (including retesting evidence) in a federal environment, Hands-on experience with federal security management tools (CSAM and eMASS), Working knowledge of NIST SP 800-53 Rev. 5 and NIST SP 800-53A, Knowledge of FISMA 2014 reporting and OMB security directives, Knowledge of Privacy Act and E-Government Act privacy provisions, including PTA/PIA processes, Experience coordinating with federal ISSOs/CISOs and security authorization officials, Active Tier 4 / High Risk / Public Trust Level 6+ clearance at proposal submission, Eligibility for HSPD-12/PIV, Availability to work during Eastern Time (ET) business hours

Nice to Have

CISSP, CISM, or CAP certification (or equivalent), Experience supporting CDC, HHS, or federal health agencies, Experience with CIPSEA-protected data environments or federal statistical agencies, Experience with FedRAMP continuous monitoring and cloud security assessment

What You'll Do.

Maintain System Security Plans (SSPs)

Manage Plan of Action & Milestones (POA&Ms)

Remediate vulnerabilities

Prepare Authorization to Operate (ATO) packages

Conduct annual security assessments

Submit monthly scan results

Follow CDC CSPO Change Management SOP

Support implementation of RMF

Produce security-related EPLC artifacts

Support PTA/PIA activities

How You'll Work.

Team & Collaboration

Coordinate among developers, system owners, and security staff; Liaise with CDC CSPO, NCHS SSPO, and CDC Enterprise Architects

Process & Methodology

Manage POA&Ms with quarterly progress reviews, Track findings through closure

Full Job Description

Essnova Solutions, Inc. is an award-winning SBA 8(a) and HUBZone small business delivering innovative technology and professional services to government and commercial clients. As Security / RMF Lead, you will play a critical role in ensuring the integrity and compliance of federal information systems under the VISION contract for the National Center for Health Statistics (NCHS). Your leadership will directly impact the security posture and regulatory compliance of mission-critical systems supporting public health initiatives. Key responsibilities include: * Maintain System Security Plans (SSPs) as living documents for all NCHS systems, ensuring timely updates after security-impacting changes. * Manage Plan of Action & Milestones (POA&Ms) with quarterly progress reviews, closure evidence, and remediation tracking. * Remediate vulnerabilities within mandated timelines, track findings through closure, and provide retesting evidence. * Prepare Authorization to Operate (ATO) packages—including SSPs, POA&M status, assessment results, and risk analysis—for Authorizing Official review. * Conduct annual security assessments of one-third-plus-key-controls using CSAM or equivalent tools. * Submit monthly authenticated vulnerability and application scan results by the fifth business day. * Coordinate among developers, system owners, and security staff, and liaise with CDC CSPO, NCHS SSPO, and CDC Enterprise Architects. * Follow CDC CSPO Change Management SOP, including security impact analysis for post-ATO changes. * Support implementation of the Risk Management Framework (RMF), FISMA compliance, and OMB directives. * Produce security-related EPLC artifacts for governance and stage-gate reviews. * Lead SSP development during the 30-day transition-in activation sequence and support SSP submission within 30 days of contract award. * Support PTA/PIA activities with CDC privacy officials. **Requirements** ### Required Qualifications: * Bachelor's degree in cybersecurity, informati

Free ATS check

Applying for this Security / RMF Lead role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

ANONYMOUS · UNFILTERED

What do employees actually say about Essnova Solutions, Inc.?

Real rants from real employees. Read before you apply.

Read Company Rants →