Talent.com
Test & Evaluation SME-Cybersecurity Risk Management Construct (CSRMC)
Test & Evaluation SME-Cybersecurity Risk Management Construct (CSRMC)Foxhole Technology • Washington, DC, United States
Test & Evaluation SME-Cybersecurity Risk Management Construct (CSRMC)

Test & Evaluation SME-Cybersecurity Risk Management Construct (CSRMC)

Foxhole Technology • Washington, DC, United States
Hace 5 días
Tipo de contrato
  • A tiempo completo
Descripción del trabajo

Test & Evaluation SME-Cybersecurity Risk Management Construct (CSRMC)

Job Locations

US-DC

Job ID

2025-2027

Category

Information Technology

Type

Regular Full-Time

Clearance Required

Top Secret / SCI Capability

Overview

Title : Test & Evaluation SME-Cybersecurity Risk Management Construct (CSRMC)

Location : Washington D.C. (Hybrid)

Clearance : Top Secret with SCI Eligibility

Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recognized leader in navigating technology and security challenges, Foxhole delivers mission-focused innovations to answer evolving and complex needs. Our talented employee-owners provide agile, scalable services and solutions that solve operational gaps, operate critical systems, and protect and secure the enterprise - across the organization and around the world.

We are seeking a talented Test & Evaluation SME with hands-on experience focusing on Cybersecurity Risk Management Construct (CSRMC) within federal government environments.

Job Description

The Test & Evaluation SME plays a critical role in enabling the Department of War's CSRMC initiative by providing deep expertise in testing, evaluating, and validating cybersecurity controls and risk-management processes associated with systems authorized under the legacy RiskManagementFramework (RMF) and transitioning into the CSRMC lifecycle. This individual will lead or advise on test planning, execution, independent verification, and validation of security, resiliency, survivability, and continuous monitoring activities. They will partner with system owners, developers, cybersecurity engineers, authorizing officials (AOs), and program test teams to ensure systems meet evolving risk posture, mission assurance and cybersecurity requirements consistent with the CSRMC's five-phase lifecycle (Design Build Test Onboard Operations) and ten foundational tenets (Automation, Critical Controls, Continuous Monitoring, DevSecOps, Cyber Survivability, Training, Enterprise Services & Inheritance, Operationalization, Reciprocity, Cybersecurity Assessments).

Serve as the SME for cybersecurity test & evaluation (T&E) activities associated with RMF / CSRMC-governed systems - including defining test strategies, planning assessment events, coordinating independent verification and validation (IV&V), and integrating security testing into system lifecycle.

  • Develop and / or review test artifacts (e.g., Test & Evaluation Master Plan (TEMP) segments, T&E event plans, cybersecurity test plans, threat-informed test scenarios, penetration test / Red Team inputs, vulnerability assessment results, system stress / failover / resiliency tests) tailored to CSRMC requirements.
  • Ensure testing covers critical controls, cyber-survivability metrics, and continuous monitoring capabilities - validating that controls are implemented correctly, operating as intended, and achieving desired mission outcomes (akin to RMF "Assess" step) but aligned with CSRMC's dynamic operational posture.
  • Lead or interface with assessment teams (including system owner, developer, cybersecurity engineering, test-eval, ISSM / ISSO) to execute security control assessments, Red / Blue Team exercises, resilience testing in contested environments, and continuous monitoring verification.
  • Analyze test results and findings, produce Test Reports, provide recommendations for corrective actions (Plans of Action & Milestones (POA&Ms) where applicable), track remediation status, and provide visibility to Authorizing Officials (AOs) and cybersecurity leadership.
  • Support authority-to-operate (ATO / ATO-equivalent) decisions by providing test evidence, risk-based assessments of control implementation, system vulnerabilities, and threat-informed scenario outcomes.
  • Facilitate integration of T&E activities into DevSecOps pipelines, system development, and deployment workflows to meet CSRMC's emphasis on automation, continuous verification, and operational readiness.
  • Provide subject-matter advice on T&E methodologies, toolsets, and techniques (including automated scanning, STIG / SCAP compliance tools, threat-informed testing, and mission-based T&E) to enhance cybersecurity posture and support program test communities.
  • Mentor, coach, or assist less-experienced cybersecurity / test staff, and contribute to refining organizational test processes, templates, and best practices for RMF / CSRMC alignment.
  • Stay abreast of evolving DoW cybersecurity policy, guidance, and test & evaluation standards (e.g., DoDI8510.01, NISTSP80037, T&E Guidebooks) and ensure test activities reflect current requirements.

Minimum Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related discipline (or equivalent relevant experience).
  • Minimum of 15 years of cybersecurity and / or test & evaluation experience within the DoW, defense industry, or equivalent mission-critical environment.
  • Must hold (or be eligible to obtain) a DoW Top Secret or higher security clearance
  • At least 5 years of direct experience in test & evaluation of cybersecurity controls, system authorizations, or RMF / A&A activities in a DoW or Government context.
  • Demonstrated experience planning and executing cybersecurity test events (control assessments, penetration testing, resiliency tests, vulnerability scanning, threat-informed scenario testing) for complex systems, with documented results and remediation tracking.
  • Strong familiarity with the RMF process (Steps : Categorize, Select, Implement, Assess, Authorize, Monitor) and associated artifacts (SSP, SAR, POA&Ms) for DoW systems.
  • Knowledge / experience of the CSRMC initiative or ability to rapidly adapt to it - including understanding of continuous monitoring, automation, cyber-survivability, DevSecOps integration, and the five-phase lifecycle.
  • Strong analytical, problem-solving, and risk-based thinking skills - capable of assessing security posture, communicating test findings, supporting risk decisions, and advising senior leadership.
  • Excellent communication (verbal and written), coordination, and stakeholder engagement skills - able to work across program management, system engineering, cybersecurity, test & evaluation, operations, and authorizing officials.
  • Desired Experience / Certifications

  • Professional cybersecurity certifications such as CISSP, CISM, CAP, CEH, or equivalent; and / or test & evaluation credentials are strongly preferred.
  • Advanced degree in cybersecurity, engineering, or related discipline.
  • Experience working in contested, mission-critical, or warfighter-embedded environments (air, land, sea, space, cyberspace).
  • Familiarity with test & evaluation infrastructure / tools and frameworks (e.g., automated scanning tools [ACAS, Nessus], STIG / SCAP compliance, threat-informed test frameworks, resilience / failover testing).
  • Experience working with DevSecOps pipelines, continuous integration / continuous deployment (CI / CD) tools, and embedding security testing into agile development workflows.
  • Prior experience working with DoD programs migrating from RMF to CSRMC or similar risk models (or large-scale cybersecurity transformation initiatives).
  • More Information

    At Foxhole Technology, we are committed to pay transparency as required by law, for our applicants and employee-owners. The salary range for this position is $195,000-220,000. Actual compensation will be determined based on a number of factors as permitted by law.

    Foxhole Technology offers a competitive benefits package for our employees and their dependents, including health, dental, and vision care, paid leave, retirement plans (401K, Roth, and ESOP), life and disability insurance, flexible spending accounts, and education and training assistance.

    Requirements of position : Think analytically, effective verbal and written communication skills, make decisions, observe / remember details, interpret data, concentrate on tasks, adjust to change, handle stress / emotions. Regular attendance, maintain work schedule, attend meetings, meet deadlines, keyboard / type, handle confidential information, use math / calculations, stay organized, operate office equipment, may direct others. May be exposed to dust / dirt, humidity, and noise.

    Foxhole Technology is an Equal Opportunity Employer and makes hiring decisions without regard to race, color, religion, sex (including pregnancy, childbirth and sexual orientation), national origin, age, disability, genetic information, military / veteran status, or any other protected class.

    Need help finding the right job?

    We can recommend jobs specifically for you!

    Click here to get started.

    Crear una alerta de empleo para esta búsqueda

    Risk Management • Washington, DC, United States

    Ofertas relacionadas
    Space Operational Test Program Project Manager

    Space Operational Test Program Project Manager

    The Johns Hopkins University Applied Physics Laboratory • Laurel, MD, United States
    A tiempo completo
    Do you like leading complex, multidisciplinary projects that bring advanced military systems to life through hardware-in-the-loop experimentation?. Are you passionate about turning technical innovat...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    SAP Test Lead

    SAP Test Lead

    Cayuse Holdings • Washington, DC, United States
    A tiempo completo
    Independent Contract - Corp to Corp / 1099.The SAP Test Lead role offers a unique opportunity to drive critical testing initiatives within SAP implementation and enhancement projects.As an independen...Mostrar más
    Última actualización: hace 2 días • Oferta promocionada
    Accessibility Testing Expert

    Accessibility Testing Expert

    ANGARAI • College Park, MD, us
    A tiempo completo
    Quick Apply
    The ideal candidate will possess deep expertise in digital accessibility standards, testing methodologies, and assistive technologies to ensure that all digital content and applications are inclusi...Mostrar más
    Última actualización: hace 15 días
    Risk Manager III

    Risk Manager III

    Amazon • Arlington, VA, United States
    A tiempo completo
    Position : Risk Manager III (multiple positions available).Lead projects to identify technical, functional, operational, and compliance risks. Own projects to remediate issues, including technical an...Mostrar más
    Última actualización: hace 22 días • Oferta promocionada
    Test and Evaluation Task Lead

    Test and Evaluation Task Lead

    Stahl Companies • Washington DC, US
    A tiempo completo
    Quick Apply
    STAHL Companies provides the Program Management for its Channel of Commercial Technology companies in Government that consist of Small Businesses and New Technology start-ups.STAHL advocates for po...Mostrar más
    Última actualización: hace más de 30 días
    Subject Matter Expert (SME) - Cybersecurity

    Subject Matter Expert (SME) - Cybersecurity

    Lafayette Group Inc. • Arlington, VA, United States
    A tiempo parcial
    Subject Matter Expert (SME) - Cybersecurity.Lafayette Group is seeking qualified and team-oriented individuals to work with federal government organizations in support of national cybersecurity pro...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    SiteScope SME

    SiteScope SME

    Computer World Services • Bethesda, MD, US
    A tiempo completo
    Computer World Services Corp (CWS) is seeking an exceptional candidate to serve as the SiteScope SME for the National Institutes of Health (NIH) Center for Information Technology (CIT) Operations M...Mostrar más
    Última actualización: hace 21 horas • Oferta promocionada • Nueva oferta
    cUAS Emerging Threat & Risk Analysis Team Lead

    cUAS Emerging Threat & Risk Analysis Team Lead

    Amyx • Washington, DC, United States
    A tiempo completo
    The Counter-UAS Emerging Threat & Risk Analysis Team Lead will direct a team responsible for identifying, assessing, and mitigating evolving unmanned aircraft system (UAS) threats to critical infra...Mostrar más
    Última actualización: hace 17 días • Oferta promocionada
    Senior Cyber Assurance & Third-Party Risk Leader

    Senior Cyber Assurance & Third-Party Risk Leader

    Control Risks • Washington, DC, United States
    A tiempo completo
    A global risk consultancy is seeking a senior leader to drive the growth of Digital Risks focusing on cyber assurance, third-party risk management, and regulatory compliance audits.The ideal candid...Mostrar más
    Última actualización: hace 5 días • Oferta promocionada
    Project Risk Manager

    Project Risk Manager

    PL ASSOCIATES INC. (PLA) • Washington, DC, United States
    A tiempo completo
    PLA), we believe in the holistic protection of our assets and liabilities.We thrive on eliminating risks while doing business, and we are seeking a highly skilled risk manager to help us achieve th...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Sr. Scrum Master / Team Coach - Cyber Security

    Sr. Scrum Master / Team Coach - Cyber Security

    h3 Technologies • Washington, DC, United States
    A tiempo completo
    Scrum Master / Team Coach - Cyber Security.This role combines hands-on Agile facilitation with team-level coaching to accelerate delivery, increase transparency, and strengthen Agile maturity acros...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Cybersecurity Engineer, Contract Manager

    Cybersecurity Engineer, Contract Manager

    Nationwide IT Services • Arlington, VA, United States
    A tiempo completo
    Cybersecurity Engineer, Contract Manager.Full-time, contingent upon contract award.Nationwide IT Services (NIS) is seeking a highly qualified. This role will focus on delivering comprehensive cybers...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Senior Manager, Business Controls Testing, Enterprise Services Risk

    Senior Manager, Business Controls Testing, Enterprise Services Risk

    Capital One • Washington, DC, United States
    A tiempo completo +1
    Senior Manager, Business Controls Testing, Enterprise Services Risk.The Enterprise Services Risk organization is expanding with a focus on attracting innovative, pioneering, collaborative, and high...Mostrar más
    Última actualización: hace 8 días • Oferta promocionada
    Senior Cybersecurity Penetration Tester - Hybrid Role

    Senior Cybersecurity Penetration Tester - Hybrid Role

    Ernst & Young Oman • Washington, DC, United States
    A tiempo completo
    A global consulting firm is seeking a Cybersecurity – Attack and Penetration Tester to lead security implementations and foster business resilience in a hybrid role. The ideal candidate has 5+ years...Mostrar más
    Última actualización: hace 4 días • Oferta promocionada
    Insider Threat Program Systems SME

    Insider Threat Program Systems SME

    Leidos Inc • Washington, DC, United States
    A tiempo completo
    The Digital Modernization Sector at Leidos currently has an opening for a Systems Management SME supporting the HEITS Contract as part of an Insider Threat Program (ITP). This is an exciting opportu...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    IBM Maximo (EAM) Testing Lead

    IBM Maximo (EAM) Testing Lead

    Diverse Lynx • Washington, DC, United States
    A tiempo completo
    Role : IBM Maximo (EAM) Testing Lead.Must Have : Need someone with experience managing a 'Maximo implementation' project. Diverse Lynx LLC is an Equal Employment Opportunity employer.All qualified app...Mostrar más
    Última actualización: hace 2 días • Oferta promocionada
    Risk Management BSA I, II, III

    Risk Management BSA I, II, III

    Cambia Health Solutions • Washington, DC, United States
    A tiempo completo
    Risk Management – Business System Analyst I, II or III.Oregon, Washington, Idaho or Utah.Every day, Cambia’s dedicated team of Business System Analysts (BSA) is living our mission to make health ca...Mostrar más
    Última actualización: hace 7 días • Oferta promocionada
    Senior Product Manager - Risk Enablement

    Senior Product Manager - Risk Enablement

    Coinbase • Washington, DC, United States
    A tiempo completo
    Ready to be pushed beyond what you think you’re capable of?.At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, ...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada