Home › Companies › DEFCON AI › Platform Security & RMF Lead
Platform Security & RMF Lead
DEFCON AI · Remote, USA · Remote · Active · $175,000–$215,000 / year · Greenhouse
Job facts
| Field | Value |
|---|---|
| Company | DEFCON AI |
| Title | Platform Security & RMF Lead |
| Normalized title | - |
| Department / team | Defcon - Client Engagement |
| Location | United States |
| Work model | Remote / Remote |
| Employment type | - |
| Salary | $175,000–$215,000 / year |
| Status | active |
| ATS provider | Greenhouse |
| Posted / first seen | 2026-06-02 / 2026-06-02 |
| Changed / last seen | 2026-06-03 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from DEFCON AI. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through Greenhouse. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| Department jobs | Active postings in Defcon - Client Engagement. | Open |
| Work model jobs | Active Remote postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | DEFCON AI |
| Source | c8add047-356a-462f-bab6-fb7e6a87c5f9 |
| ATS provider | Greenhouse |
Description
ABOUT DEFCON AI
RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.
In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.
About the Role
This is a rare opportunity to define the security posture of a mission-critical DoD software platform from the ground up.
As the Platform Security & RMF Lead, you will own the authorization posture and platform-level security discipline for DEFCON AI’s government-facing systems and integration platform. You are responsible for the full RMF lifecycle—from ATO strategy through continuous monitoring—and serve as the authoritative voice on whether the system is secure, compliant, and authorized to operate.
You will work closely with Architecture and DevSecOps leadership to define the security standards the platform must meet, while ensuring cross-domain data flows comply with classification and authorization requirements. This is a deeply specialized role requiring expert-level fluency in DoD security frameworks, RMF processes, and cleared-system environments.
This is a senior level role combining hands-on RMF execution with platform-wide security leadership. You will guide both government stakeholders and engineering teams through complex authorization, classification, and security decisions.
Key Responsibilities
ATO Strategy & RMF Ownership
Define and execute the ATO pathway, including responsibility allocation across government and contractor teams
Author and maintain RMF documentation (SSP, SAP, SCTM, ConMon) in accordance with DoDI 8510.01 and NIST 800-53
Coordinate with eMASS and Authorizing Officials on assessment and authorization activities
Lead continuous monitoring and reauthorization efforts across the system lifecycle
Cross-Domain Security & Classification Policy
Define security requirements for cross-domain data flows (IL-5, IL-6, tactical edge)
Evaluate and guide selection of DoD-approved cross-domain solutions
Ensure classification-aware data segmentation is enforceable, auditable, and aligned with policy (e.g., NOFORN, REL_TO, ORCON)
Review system architecture to ensure compliant handling of classified data flows
Multi-Enclave Security Architecture
Support secure operation across NIPR, SIPR, and higher classification environments
Define authorization approaches (inheritance vs. standalone ATOs) across enclaves
Ensure security posture scales without requiring fundamentally different architectures
Maintain alignment with evolving joint and service-level security requirements
Platform Security Advisory
Serve as the authoritative internal resource for DoD security and RMF-related questions
Advise on container security, RBAC, service mesh security, PKI/CAC integration, and secrets management
Define expectations for security scanning, container hardening, and vulnerability management (without owning the pipeline)
Evaluate new capabilities for security and authorization impacts prior to production deployment
Required Qualifications
10+ years of information assurance or security engineering experience with increasing seniority
5+ years of hands-on ownership of RMF / ATO packages for DoD production systems, including at least one full authorization cycle (categorization → controls → implementation → assessment → authorization → ConMon).
Deep familiarity with DoD security frameworks, RMF processes, and NIST 800-53 controls
Proven ability to operate in complex, multi-enclave or classified environment
US Citizenship Required
Active Secret Clearance
Willing to travel up to 25% for business needs
Preferred Qualifications
Active TS/SCI Clearance
Experience supporting USMC or Service-level network environments
Experience with ATO inheritance, reciprocity, or common control provider model
Experience with cross-domain solutions or multi-level security architectures \
Familiarity with Palantir Foundry or Anduril Lattice environments
Prior experience as an ISSO, SCA, or in a similar senior DoD security role
What Success Looks Like
A clear ATO pathway is defined, approved by stakeholders, and actively progressing
RMF artifacts and compliance evidence are built into the delivery process—not created after the fact
Cross-domain data flows are secure by design, with classification policy embedded at the data level
The platform operates securely across multiple enclaves without requiring re-architecture at each level
Engineering teams proactively engage security early in design decisions
Government stakeholders view the system’s security posture as credible, well-managed, and audit-ready
What We Offer:
A fully remote, results-based environment
Competitive salary, bonus, and equity package
100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
Unlimited PTO, with your manager’s approval
Flexible work environment where you manage your work day
14 weeks of fully-paid parental leave
Salary Range: $175,000-$215,000. This represents the typical salary range for this position based on experience, skills, and other factors.
We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.
Applicant Data Disclosure
By submitting an application, you acknowledge that Defcon AI uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, "Hiring Platforms"). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:
Managing and administering your application throughout the hiring process;
Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;
Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.
Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contact [email protected] .
Defcon AI requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Defcon AI's data retention policies.
For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice .
Full job record
| Job ID | 94e2bba0d0944966d3c99ca75182718c53eac199 |
| Org ID | 3320e559-7e8c-4324-836c-fca2ace29aca |
| Source ID | c8add047-356a-462f-bab6-fb7e6a87c5f9 |
| Board ID | c8add047-356a-462f-bab6-fb7e6a87c5f9 |
| Provider | greenhouse |
| Provider Job Key | 5147155007 |
| Title | Platform Security & RMF Lead |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | Remote, USA |
| Department | Defcon - Client Engagement |
| Team | — |
| Employment Type | — |
| Workplace Type | remote |
| Remote Policy | remote |
| Country | United States |
| Region | — |
| City | — |
| Salary Raw | Salary Range: $175,000-$215,000. This represents the typical salary range for this position based on experience, |
| Salary Min | 175,000 |
| Salary Max | 215,000 |
| Salary Currency | USD |
| Salary Period | year |
| Source URL | https://job-boards.greenhouse.io/defcon/jobs/5147155007 |
| Apply URL | https://job-boards.greenhouse.io/defcon/jobs/5147155007 |
| First Seen At | 2026-06-02 12:12:14Z |
| Last Seen At | 2026-06-06 07:35:24Z |
| Last Checked At | 2026-06-06 07:35:24Z |
| Last Changed At | 2026-06-03 12:03:01Z |
| Inactive At | — |
| Source Posted At | 2026-06-02 03:36:54Z |
| Source Updated At | 2026-06-03 06:58:12Z |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=greenhouse/board=defcon/date=2026-06-06/2026-06-06T07-35-24-073Z-9343277832bc3286370cfd62d005227a716ad0fea4ba4774a12ecc9ae1360988.json |
Event Fields
{
"content_hash": "a92cbece558ab6ad05c0c4c87e73d03bafe2fbc2e32e08b2a57146dac1174fb0",
"source_hash": "81f161454ba5b85b749106590993ffa39853559e912cd05dcb3f851755465667",
"last_changed_at": "2026-06-03T12:03:01.045Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Remote, USA",
"city": null,
"region": null,
"country": "United States",
"is_remote": true,
"confidence": 0.95
},
"salary_max": 215000,
"salary_min": 175000,
"inferred_at": "2026-06-06T07:35:24.177Z",
"launch_scope": {
"reason": "english_us_canada",
"included": true,
"language": "en",
"location": {
"raw": "Remote, USA",
"city": null,
"region": null,
"country": "United States",
"is_remote": true,
"confidence": 0.95
},
"countries": [
"United States"
]
},
"remote_policy": "remote",
"salary_period": "year",
"workplace_type": "remote",
"salary_currency": "USD"
}Extensions
{}Native Structured
{
"title": "Platform Security & RMF Lead",
"offices": [
{
"id": 4010136007,
"name": "RCP HQ (McLean, VA)",
"location": "McLean, Virginia, United States",
"child_ids": [],
"parent_id": null
}
],
"language": "en",
"location": {
"name": "Remote, USA"
},
"metadata": [],
"updated_at": "2026-06-03T02:58:12-04:00",
"departments": [
{
"id": 4045465007,
"name": "Defcon - Client Engagement",
"child_ids": [],
"parent_id": 4011176007
}
],
"company_name": "DEFCON AI",
"requisition_id": 4637010007,
"first_published": "2026-06-01T23:36:54-04:00",
"application_deadline": null
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/94e2bba0d0944966d3c99ca75182718c53eac199?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/3320e559-7e8c-4324-836c-fca2ace29acaJSONGET https://api.bluedoor.sh/job-postings/v1/sources/c8add047-356a-462f-bab6-fb7e6a87c5f9JSONGET https://api.bluedoor.sh/job-postings/v1/jobs/94e2bba0d0944966d3c99ca75182718c53eac199/eventsJSON