Demo

Risk Management Framework / Cybersecurity Specialist

4A-Consulting
Woodlawn, MD Full Time
POSTED ON 7/23/2026
AVAILABLE BEFORE 8/23/2026

Company Overview

At 4A Consulting, we turn complexity into opportunity. Founded in 2014 and headquartered in Baltimore, MD, we are a women-owned, boutique consulting firm specializing in delivering innovative, data-driven solutions to both the Federal Government and Fortune 500 clients. Our team blends deep industry knowledge with advanced technologies to design tailored strategies that drive measurable and sustainable outcomes. We pride ourselves on an agile, collaborative approach that helps organizations navigate challenges and seize emerging opportunities in a rapidly evolving digital landscape. At 4A, we don’t just deliver projects, we build trusted partnerships that empower our clients to lead with confidence in the digital age.

 

Position Overview

We are seeking a Risk Management Framework / Cybersecurity Specialist to provide end-to-end Risk Management Framework (RMF) documentation and Authorization to Operate (ATO) support. In this role, you will work closely with Information System Security Officers (ISSOs), technical teams, and agency stakeholders using automated Security Authorization & Assessment (SA&A) tools to guide information systems through all seven steps of the NIST RMF lifecycle.

 

Key Responsibilities

  • RMF & ATO Lifecycle Support
  • Assist in establishing the framework for RMF implementation, identifying key stakeholders, defining boundary scopes, and conducting operational guidance/training.
  • Guide stakeholders in classifying information systems and data types based on functionality, sensitivity, and organizational impact.
  • Help select baseline security controls from NIST SP 800-53 and establish appropriate common control inheritance tailored to system boundaries.
  • Support control implementation; assist ISSOs and stakeholders in establishing SI-2 (Flaw Remediation) and RA-5 (Vulnerability Monitoring and Scanning) reports for each system boundary.
  • Provide support during Targeted Control Assessments and Continuous Monitoring Assessments, aiding ISSOs and stakeholders in collecting, organizing, and validating assessment artifacts.
  • Review Security Assessment Reports (SARs), analyze residual risks, and recommend technical/operational mitigations to support executive ATO decisions.
  • Drive continuous monitoring efforts across system lifecycles:
  • Facilitate Plan of Actions and Milestones (POA&M) remediation with technical teams to mitigate audit findings and vulnerabilities, while tracking and reporting status to supervisors and ISSOs.
  • Conduct semi-annual Quality Assurance (QA) reviews of assigned security boundaries and present findings to system leadership.
  • Documentation & Stakeholder Management
  • Independently author, review, and maintain System Security Plans (SSPs) and associated SA&A artifacts with minimal oversight.
  • Gather security requirements, evaluate incoming requests, and interface effectively across agency SMEs, customers, and leadership.
  • Lead stakeholder meetings, interviews, and working sessions independently.

 

Required Qualifications

  • Master’s with 5 years, Bachelor\''s 7 years, or 13 years of relevant experience.
  • Deep, practical knowledge of NIST SP 800-37 (RMF) and NIST SP 800-53 controls, with direct experience conducting Security Control Assessments.
  • Strong working knowledge of federal cybersecurity directives, including FISMA, FedRAMP, OMB Circulars, NIST standards, and HIPAA.
  • Hands-on experience navigating RMF-related Security Authorization & Assessment (SA&A) tools (e.g., ServiceNow, eMASS, CSAM, or equivalent GRC platforms).
  • Demonstrated track record of managing POA&Ms through remediation and working with vulnerability scanning/reporting datasets (SI-2/RA-5).
  • Proficient with Microsoft Office 365 applications (Word, Excel, PowerPoint, Teams, SharePoint).
  • Exceptional written and verbal communication skills with a proven ability to explain technical risk to diverse audiences and build consensus among stakeholders.

 

Preferred Qualifications

  • The ideal candidate brings deep technical knowledge of NIST SP 800-37 and 800-53, hands-on experience with vulnerability reporting and POA&M remediation, and the ability to operate independently with minimal oversight.

 

Applicants must be legally authorized to work in the United States.

Why Join 4A 

  • Be part of a mission-driven, women-owned consulting firm with a reputation for excellence.
  • Work on high-impact projects across federal and commercial clients.
  • Collaborate in an inclusive, growth-oriented culture where innovation is valued.
  • Access career development programs, mentorship, and learning opportunities.
  • Enjoy a comprehensive benefits package, flexible work options, and a focus on work-life balance.

Equal Opportunity Statement

4A Consulting is an Equal Opportunity Employer committed to an inclusive hiring process. Applicants requiring a reasonable accommodation due to a disability may contact . This email is intended solely for accommodation requests.

Please note that 4A Consulting participates in the federal E-Verify program. Upon hire, we will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the US. 4A Consulting will only use E-Verify once you have accepted a job offer and completed the Form I-9. 

Salary : $55 - $60

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Risk Management Framework / Cybersecurity Specialist?

Sign up to receive alerts about other jobs on the Risk Management Framework / Cybersecurity Specialist career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$71,440 - $92,105
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$102,189 - $143,024
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at 4A-Consulting

  • 4A-Consulting Woodlawn, MD
  • Company Overview At 4A Consulting, we turn complexity into opportunity. Founded in 2014 and headquartered in Baltimore, MD, we are a women-owned, boutique ... more
  • 2 Days Ago

  • 4A-Consulting Woodlawn, MD
  • Company Overview At 4A Consulting, we turn complexity into opportunity. Founded in 2014 and headquartered in Baltimore, MD, we are a women-owned, boutique ... more
  • 2 Days Ago

  • 4A-Consulting Woodlawn, MD
  • Position Overview We are seeking a Business Continuity Management Specialist to support a large federal agency in transforming and maturing its enterprise-... more
  • 3 Days Ago

  • 4A-Consulting Washington, DC
  • In this position you will be responsible for providing insights to clients. To do so, you will first meet with our clients to uncover their business needs ... more
  • 4 Days Ago


Not the job you're looking for? Here are some other Risk Management Framework / Cybersecurity Specialist jobs in the Woodlawn, MD area that may be a better fit.

  • Arlo Solutions Aberdeen, MD
  • Company Summary Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our rep... more
  • 1 Day Ago

  • arlosolutionsllc Aberdeen, MD
  • Company Summary Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our rep... more
  • 1 Month Ago

AI Assistant is available now!

Feel free to start your new journey!