Post Job Free
Sign in

FedRAMP RMF Cloud Security Engineer (ISSE)

Location:
Washington, DC
Posted:
August 13, 2026

Contact this candidate

Resume:

JANET L. MCFAUL

Maryland, US +1-540-***-**** *********@*****.*** https://www.linkedin.com/in/janet-mcfaul-a5667179/

Cybersecurity Systems Security Engineer (ISSE) ISSM Cloud Security RMF FedRAMP

United States Air Force Veteran –Enlisted Officer Major (O4)

Stateside or Remote

CISA CISM AWS Cloud Practitioner

EXECUTIVE SUMMARY

Cybersecurity and Systems Security Engineer with over 15+ years supporting Department of Defense, Intelligence Community, and Federal Civilian agencies in securing missioncritical onpremises and cloud environments up to Top Secret/SAP classification levels. CI Poly.

Recognized NIST Risk Management Framework (RMF) and FedRAMP governance authority with demonstrated success leading Authorization to Operate (ATO) initiatives, Zero Trust implementations (NIST SP 800207), and enterprise vulnerability management programs across largescale acquisition and cloud modernization efforts.

Proven record of reducing system vulnerabilities by over 20%, remediating compliance backlog across 1,500+ IT artifacts, and enabling CCRI/CORA certification readiness through documentation overhaul, policy updates, and auditdriven remediation strategies.

Experienced across AWS GovCloud, Kubernetes/OpenShift platforms, CI/CD pipelines, ACAS/Nessus scanning, and Microsoft Defender migration initiatives in support of DoD Zero Trust architecture mandates.

Seeking to leverage RMF, SOC 2, FedRAMP, and enterprise risk assessment expertise in an ISSE, ISSM, or Cybersecurity Analyst role supporting secure mission delivery.

CORE COMPETENCIES

NIST 80037 RMF Implementation

NIST 80053 Rev 5 Security Controls

FedRAMP High / IL5IL6 Systems

Zero Trust Architecture (NIST 800207)

DISA STIG Hardening

SOC 1 / SOC 2 Readiness

Enterprise Vulnerability Management

ATO Accreditation Lifecycle

ACAS / Nessus / AWS Inspector Vulnerability Scans

Fortify and Xray Static Scans

eMASS / XACTA Archives

Kubernetes / OpenShift

Supply Chain Risk Management (SCRM)

Cloud Security (AWS GovCloud)

HBSS to Microsoft Defender Migration

POA&M / SSP / STP / SAR

PCIDSS / ISO 27001 Alignment

PKI Implementation

COOP / DR / IR Planning

Project planning and AGILE processing.

PROFESSIONAL EXPERIENCE

Systek Corporation

Cybersecurity Systems Engineer- US Army

May 2026 – Present Onsite Hanover, MD

Assist the CISO in meeting their duties and responsibilities. Implement and enforce all DoD Information Systems and Platform IT system cybersecurity policies and procedures, as defined by cybersecurity-related documentation.

Ensure that all users have the requisite security clearances and access authorization and are aware of their cybersecurity responsibilities for DoD IS and PIT systems under their purview before being granted access to those systems.

In coordination with the CISO, initiate protective or corrective measures when a cybersecurity incident or vulnerability is discovered and ensure that a process is in place for authorized users to report all cybersecurity-related events and potential threats and vulnerabilities to the ISSO.

Ensure that all DoD IS cybersecurity-related documentation is current and accessible to properly authorized individuals.

Review reports from static code analysis, Pen Testing, and Scanning Results for vulnerabilities and compliance.

Review network, data flow, org charts and other security artifacts for potential vulnerabilities related to processes or personnel.

Thorough knowledge of NIST 800 series Special Publications, Federal Information Processing Standards (FIPS) and other relevant federal and DoD cybersecurity regulations.

Create and maintain security configuration baselines for Windows and Linux platforms, networking equipment, cloud technologies and custom hardware and software applications.

Update security archives on CUI and multiple high security level and departmental systems.

Ensure proper security protocols when accessing and retrieving classified materials.

ManTech Corporation

Cybersecurity Systems Engineer – US Navy

Nov 2025 – April 2026 Remote & Hybrid

Support FedRAMP IL5/IL6 cybersecurity authorization activities for U.S. Navy enterprise systems.

Apply NIST 80037 RMF processes and NIST 80053 security controls to balance system risk with cost, schedule, and performance.

Perform ACAS and AWS Inspector vulnerability assessments utilizing Nessus and STIGRevolution toolsets.

Develop architecture diagrams, privacy impact assessments, and security integration plans.

Provide recurring cybersecurity risk posture briefings to senior leadership supporting program compliance.

KBR Corporation

Cybersecurity Systems Engineer

Mar 2025 – Oct 2025 Eglin AFB

Led cybersecurity engineering efforts supporting the Hypersonic Attack Cruise Missile acquisition program.

Implemented AntiTamper (AT) and Defense Exportability Features (DEF) security requirements.

Developed Supply Chain Risk Management (SCRM) strategies to mitigate hardware/software vulnerabilities.

Produced program security documentation including SEP, SRD, SOW, and Program Protection Plans (PPP).

Ensured compliance with FedRAMP and PCIDSS control baselines within SSEdriven security initiatives.

Position reclassified by Government.

US Army Corps of Engineers

Senior Cybersecurity & Systems Engineer

Jun 2024 – Jan 2025 Remote

Led enterprise cyber compliance efforts for JFHQDODIN CCRI/CORA inspection readiness.

Eliminated eMASS compliance backlog by reviewing 1,500+ archived security artifacts.

Conducted 40 stakeholder interviews resulting in CIOlevel report identifying 35+ process improvement initiatives.

Assessed 50+ COOP, Disaster Recovery, and Incident Response plans.

Delivered enterprise impact analysis supporting migration from Trellix HBSS to Microsoft Defender in hybrid cloud environments.

Advanced organizational Zero Trust compliance to 90% in alignment with NIST 800207 standards.

Chenega Corporation

Senior Cybersecurity Cloud Engineer

Nov 2021 – Apr 2024 On-Site Springfield, Virginia

Supported $100M+ IC cloud modernization program as cybersecurity SME.

Implemented AWS GovCloud solutions aligned with ISO 27001, SOC 2, PCIDSS, and NIST 80053 control frameworks.

Served as DIA Kubernetes/OpenShift security SME AWS Cloud environments. Zero Trust Mesh network.

Performed vulnerability assessments using Prisma Cloud and JFrog across CI/CD pipelines.

Developed enterprise security policies and conducted cloud risk assessments.

Peraton Corporation

Cybersecurity Project Manager

Nov 2019 – Nov 2021 On-Site Springfield, Virginia

Reduced enterprise security breaches by 20% through CIS benchmark implementation and ACAS remediation.

Led RMF implementation enabling Authorization to Operate (ATO) for cloudbased defense program.

Managed PKI provisioning and log archival for enterprise audit compliance.

Authored ISCP and CONOPS supporting incident response lifecycle.

Deloitte

Senior Security Control Assessor

Sep 2018 – Nov 2019 On-Site Springfield, Virginia

Led security assessments across hundreds of federal IT systems.

Served as RMF, COBIT5, and NIST 80053 SME.

Developed POA&M, SAR, RAR, SSP, and Continuous Monitoring CONOPS artifacts.

Provided executivelevel cybersecurity compliance briefings.

CERTIFICATIONS

AWS Cloud Practitioner (2022–Present)

Certified Information Systems Auditor (CISA) (2018–Present)

Certified Information Security Manager (CISM) (2019–Present)

CMMI Level 3

EDUCATION

M.S. Cybersecurity Technology – University of Maryland Global Campus, College Park, MD.

M.S. Information Systems Management – Golden Gate University, San Francisco, CA.

B.A. Economics – California State University, Fresno, CA.

MILITARY SERVICE

United States Air Force – Enlisted/ Officer Major (O4)

22 Years Active Duty / Reserve

Systems Technician Senior Systems Engineer DISA HQ Watch Officer Network Systems Engineer UNIX/Linux Systems Engineer



Contact this candidate