Senior Security Consultant – DoD RMF & CMMC Implementation
Arlington, VA
Redhorse
We’ve all been on your side of the table at some point in our careers, in uniform or government. That experience helps us understand your challenges in a…About the RoleRedhorse is seeking a highly experienced Senior Security Consultant to play a crucial role in our growing cybersecurity practice. You will be a key player in guiding Redhorse project teams through the complexities of DoD Risk Management Framework (RMF) implementation and supporting our corporate CMMC compliance efforts. Your expertise will directly impact the success of our projects and help secure our clients' critical systems while contributing to Redhorse's continued growth and market leadership in the government technology space. This is a high-impact role where your contributions will directly benefit our clients’ mission success and enhance Redhorse's reputation as a trusted cybersecurity partner.
Key Responsibilities
- RMF Compliance & Implementation:
- Guide the implementation of the DoD Risk Management Framework (RMF) across multiple Redhorse projects, ensuring compliance with DoDI 8510.01, NIST SP 800-37, and NIST SP 800-53.
- Manage security control assessments and documentation, including System Security Plans (SSP), Security Assessment Reports (SAR), and Plans of Action & Milestones (POA&M).
- Support Authorization to Operate (ATO) and related processes for DoD systems.
- CMMC Compliance & Implementation:
- Advise on the implementation of the Cybersecurity Maturity Model Certification (CMMC) requirements for DoD contractors and corporate networks.
- Perform gap analyses, risk assessments, and security audits to prepare the company for CMMC certification.
- Develop and execute remediation plans to align with CMMC Level 1–3+ controls.
- Assist in the development of CMMC policies, procedures, and training programs.
- Business Development & Client Engagement:
- Support proposal development, RFP responses, and whitepaper creation for cybersecurity services.
- Identify new business opportunities and expand service offerings in RMF and related cybersecurity solutions.
- Engage with clients to understand security needs and develop tailored cybersecurity strategies.
- Provide cybersecurity advisory services to leadership and stakeholders.
Required Experience/Clearance
- Strong knowledge of DoD RMF, NIST SP 800-37, NIST SP 800-53, FISMA, FedRAMP, and CNSSI 1253.
- Experience with network security concepts, including firewalls, IDS/IPS, SIEM, and endpoint security.
- Familiarity with CMMC Level 1-3+ requirements and compliance strategies.
- DoD 8570/8140 IAM/IAT Level II or III certification (e.g., CISSP, CISM, CAP, Security+ CE, CEH).
- Bachelor’s Degree in Cybersecurity, Information Security, Computer Science, or a related field (or equivalent experience).
- 20+ years of experience in cybersecurity consulting, RMF, network security, and compliance.
- Numerous successful ATO packages/approvals across multiple DoD impact levels.
- Experience in business development, proposal writing, and cybersecurity solution design.
Desired Experience
- Hands-on experience with security tools such as ACAS, Nessus, OpenVAS, STIGs, SCAP, Splunk, or ELK Stack.
- CMMC Certified Professional (CCP) or CMMC Certified Assessor (CCA) certification.
- Networking and security certifications (CCNA Security, CCNP Security, OSCP).
- Experience with cloud security architectures and implementation.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: ACAS Audits CCNP CEH CISM CISSP Clearance Cloud CMMC Compliance Computer Science DoD DoDD 8140 DoDD 8570 DoD RMF ELK Endpoint security FedRAMP Firewalls FISMA IAM IDS IPS Nessus Network security NIST NIST 800-53 OpenVAS OSCP POA&M RFPs Risk assessment Risk management RMF SCAP Security assessment Security Assessment Report SIEM Splunk STIGs System Security Plan
Perks/benefits: Career development Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.