Risk Management Framework / Cybersecurity Specialist
Quick Overview
Job Description
Company Overview
At 4A Consulting, we turn complexity into opportunity. Founded in 2014 and headquartered in Baltimore, MD, we are a women-owned, boutique consulting firm specializing in delivering innovative, data-driven solutions to both the Federal Government and Fortune 500 clients. Our team blends deep industry knowledge with advanced technologies to design tailored strategies that drive measurable and sustainable outcomes. We pride ourselves on an agile, collaborative approach that helps organizations navigate challenges and seize emerging opportunities in a rapidly evolving digital landscape. At 4A, we don’t just deliver projects, we build trusted partnerships that empower our clients to lead with confidence in the digital age.
Position Overview
We are seeking a Risk Management Framework / Cybersecurity Specialist to provide end-to-end Risk Management Framework (RMF) documentation and Authorization to Operate (ATO) support. In this role, you will work closely with Information System Security Officers (ISSOs), technical teams, and agency stakeholders using automated Security Authorization & Assessment (SA&A) tools to guide information systems through all seven steps of the NIST RMF lifecycle.
Key Responsibilities
- RMF & ATO Lifecycle Support
- Assist in establishing the framework for RMF implementation, identifying key stakeholders, defining boundary scopes, and conducting operational guidance/training.
- Guide stakeholders in classifying information systems and data types based on functionality, sensitivity, and organizational impact.
- Help select baseline security controls from NIST SP 800-53 and establish appropriate common control inheritance tailored to system boundaries.
- Support control implementation; assist ISSOs and stakeholders in establishing SI-2 (Flaw Remediation) and RA-5 (Vulnerability Monitoring and Scanning) reports for each system boundary.
- Provide support during Targeted Control Assessments and Continuous Monitoring Assessments, aiding ISSOs and stakeholders in collecting, organizing, and validating assessment artifacts.
- Review Security Assessment Reports (SARs), analyze residual risks, and recommend technical/operational mitigations to support executive ATO decisions.
- Drive continuous monitoring efforts across system lifecycles:
- Facilitate Plan of Actions and Milestones (POA&M) remediation with technical teams to mitigate audit findings and vulnerabilities, while tracking and reporting status to supervisors and ISSOs.
- Conduct semi-annual Quality Assurance (QA) reviews of assigned security boundaries and present findings to system leadership.
- Documentation & Stakeholder Management
- Independently author, review, and maintain System Security Plans (SSPs) and associated SA&A artifacts with minimal oversight.
- Gather security requirements, evaluate incoming requests, and interface effectively across agency SMEs, customers, and leadership.
- Lead stakeholder meetings, interviews, and working sessions independently.
Required Qualifications
- Master’s with 5+ years, Bachelor\''s 7+ years, or 13+ years of relevant experience.
- Deep, practical knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 controls, with direct experience conducting Security Control Assessments.
- Strong working knowledge of federal cybersecurity directives, including FISMA, FedRAMP, OMB Circulars, NIST standards, and HIPAA.
- Hands-on experience navigating RMF-related Security Authorization & Assessment (SA&A) tools (e.g., ServiceNow, eMASS, CSAM, or equivalent GRC platforms).
- Demonstrated track record of managing POA&Ms through remediation and working with vulnerability scanning/reporting datasets (SI-2/RA-5).
- Proficient with Microsoft Office 365 applications (Word, Excel, PowerPoint, Teams, SharePoint).
- Exceptional written and verbal communication skills with a proven ability to explain technical risk to diverse audiences and build consensus among stakeholders.
Preferred Qualifications
- The ideal candidate brings deep technical knowledge of NIST SP 800-37 and 800-53, hands-on experience with vulnerability reporting and POA&M remediation, and the ability to operate independently with minimal oversight.
Applicants must be legally authorized to work in the United States.
Why Join 4A
- Be part of a mission-driven, women-owned consulting firm with a reputation for excellence.
- Work on high-impact projects across federal and commercial clients.
- Collaborate in an inclusive, growth-oriented culture where innovation is valued.
- Access career development programs, mentorship, and learning opportunities.
- Enjoy a comprehensive benefits package, flexible work options, and a focus on work-life balance.
Equal Opportunity Statement
4A Consulting is an Equal Opportunity Employer committed to an inclusive hiring process. Applicants requiring a reasonable accommodation due to a disability may contact . This email is intended solely for accommodation requests.
Please note that 4A Consulting participates in the federal E-Verify program. Upon hire, we will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the US. 4A Consulting will only use E-Verify once you have accepted a job offer and completed the Form I-9.
Skills
Similar jobs
Data Engineer (Kusto)
iPeople Infosystems LLC · Bellevue, United States
13 minutes agoAppian Lead Developer- Full Time- Remote
Visionary Innovative Technology Solutions · United States
13 minutes agoNode.js Developer
Trebecon LLC · New York, United States
13 minutes agoSalesforce Developer | REMOTE | Citizens Required, Must Pass Federal Backgrounds
Salem Infotech · United States
13 minutes agoPrincipal AI Engineer
Synechron · Dallas, United States
13 minutes ago$140k - $150k/yrSenior Software Developer - SDET/QA
Purplejack Technologies LLC · Chicago, United States
13 minutes ago