Jobs and Careers
QB

Defensive Cybersecurity Advisor — RMF/A&A Lead

QBE LLC
UKRemotefull_timeVerifiedPosted 7 Aug 2026

About the role

Job Type
Full-time
Description

About QBE, LLC

QBE, LLC is a small business dedicated to delivering innovative technology, cybersecurity, and mission-support solutions to federal government customers. Our experienced professionals work closely with our customers to solve complex challenges, protect critical information, and support essential government missions.

At QBE, we turn the possible into the proven.


Overview

QBE, LLC is seeking an experienced Defensive Cybersecurity Advisor — RMF/A&A Lead to support comprehensive information security services for the National Institutes of Health, Office of the Director, Office of Information Technology (NIH/OD-OIT).


Responsibilities

  • Lead and coordinate Risk Management Framework (RMF) and Assessment and Authorization (A&A) activities for federal information systems and applications.
  • Provide subject-matter expertise related to federal cybersecurity requirements, security authorization processes, and risk management.
  • Guide system owners and technical teams through the full system authorization lifecycle.
  • Develop, review, and maintain security authorization documentation, including:

o System Security Plans

o Security Assessment Plans and Reports

o Plans of Action and Milestones

o Risk assessments

o Security control implementation statements

o Contingency planning documentation

o Continuous monitoring documentation

  • Evaluate system security controls using applicable NIST guidance and federal security requirements.
  • Coordinate security assessments, control testing, evidence collection, and remediation activities
  • Review system changes to determine potential impacts on security authorizations and organizational risk.
  • Identify cybersecurity risks, control deficiencies, and compliance gaps and recommend appropriate corrective actions.
  • Track security findings, vulnerabilities, and remediation activities through closure
  • Support continuous monitoring activities for Low- and Moderate-impact systems.
  • Review technical and nontechnical security documentation for accuracy, consistency, and compliance.
  • Provide cybersecurity guidance for on-premises, cloud-based, hybrid, and third-party systems.
  • Support Governance, Risk, and Compliance initiatives across the customer environment.
  • Collaborate with Security Operations and Engineering teams to ensure technical security activities align with RMF and authorization requirements.
  • Assist with the development and improvement of cybersecurity policies, procedures, standards, and governance processes.
  • Prepare cybersecurity status reports, risk summaries, dashboards, and briefing materials for technical and executive audiences.
  • Participate in meetings with government stakeholders, system owners, auditors, assessors, and cybersecurity personnel.
  • Provide recommendations that support the continued improvement and maturation of the organization’s cybersecurity program.

**This position will be primarily REMOTE but will require some onsite work in Bethesda, MD


#qf #qg

Requirements

Minimum Qualifications

  • Associate degree in cybersecurity, information technology, computer science, information systems, or a related field, or an additional two or more years of relevant experience in place of the degree requirement.
  • At least eight years of relevant cybersecurity, information assurance, risk management, or security compliance experience.
  • Demonstrated experience leading RMF and A&A activities for federal information systems.
  • Working knowledge of NIST Special Publication 800-37, NIST Special Publication 800-53, FIPS 199, FIPS 200, and related federal cybersecurity guidance.
  • Experience developing, reviewing, and maintaining security authorization documentation.
  • Experience assessing security controls and supporting security control validation activities.
  • Experience managing Plans of Action and Milestones and tracking remediation activities.
  • Experience supporting Low- and Moderate-impact federal information systems.
  • Understanding of cybersecurity risks associated with hybrid, cloud-based, on-premises, and third-party environments.
  • Ability to communicate complex cybersecurity and compliance requirements to technical and nontechnical stakeholders.
  • Strong documentation, analytical, organizational, and problem-solving skills.
  • CompTIA Security+ certification.
  • CompTIA SecurityX certification.
  • Ability to obtain and maintain the required Public Trust determination associated with the position.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

QBE LLC

View company profile →