- Serve as the primary cybersecurity advisor for assigned information systems throughout the system lifecycle.
- Lead Risk Management Framework (RMF) activities supporting initial authorization, ongoing authorization, annual assessments, and continuous monitoring.
- Coordinate with System Owners, Authorizing Officials, business stakeholders, engineering teams, and Government personnel to maintain system authorization readiness.
- Develop, maintain, and continuously update System Security Plans (SSPs), security documentation, authorization artifacts, and supporting RMF documentation.
- Track vulnerabilities, POA&Ms, risk acceptance decisions, and remediation activities to ensure cybersecurity risks are appropriately managed and documented.
- Support annual security assessments, Security Control Assessments (SCAs), and independent assessments by coordinating evidence collection and stakeholder participation.
- Review assessment findings, validate remediation activities, and coordinate corrective actions with technical teams and system owners.
Cybersecurity