user avatar

Archer / GRC Subject Matter Expert

Rividium, Inc

Posted today

Job Requirements

Washington, DC
Secret Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Title Archer / GRC Subject Matter Expert Full-Time/Part-Time Full-Time Description
Position Overview

RiVidium Inc. is seeking an experienced Archer / Governance, Risk, and Compliance (GRC) Subject Matter Expert (SME) to support federal cybersecurity, risk management, compliance, and information assurance activities.

The Archer / GRC SME will provide expert-level guidance in the design, implementation, administration, and optimization of RSA Archer and GRC processes. The position will support cybersecurity governance, Risk Management Framework (RMF) activities, security controls, risk assessments, compliance reporting, Plans of Action and Milestones (POA&Ms), and ongoing authorization activities.

The successful candidate will work closely with ISSOs, ISSMs, Security Control Assessors (SCAs), cybersecurity engineers, system owners, program managers, and government stakeholders to ensure accurate and effective management of cybersecurity risk and compliance information.

Key Responsibilities
  • Serve as the technical subject matter expert for RSA Archer and GRC processes supporting federal cybersecurity programs.
  • Administer, configure, maintain, and optimize RSA Archer GRC applications and modules.
  • Develop and maintain GRC workflows, forms, fields, dashboards, reports, and data structures.
  • Configure Archer to support cybersecurity risk management, compliance, assessment, and reporting requirements.
  • Manage cybersecurity information within Archer, including systems, controls, risks, findings, POA&Ms, assessments, and compliance activities.
  • Support integration of Archer with other enterprise cybersecurity, vulnerability management, identity, and IT service management platforms.
  • Develop dashboards and reports that provide government and program leadership with visibility into cybersecurity risk and compliance posture.
  • Ensure GRC data is accurate, complete, current, and aligned with established cybersecurity policies and procedures.
  • Support NIST Risk Management Framework (RMF) activities and maintain associated security and compliance information within GRC platforms.
  • Assist with Authority to Operate (ATO), continuous monitoring, security assessment, and ongoing authorization activities.
  • Develop and maintain GRC workflows that improve the efficiency and consistency of cybersecurity processes.
  • Analyze existing GRC processes and recommend improvements to reduce manual effort and improve data quality.
  • Establish and maintain data standards, validation rules, and governance procedures for GRC information.
  • Support cybersecurity risk assessments and facilitate the documentation, tracking, and remediation of identified risks.
  • Track and report security findings, vulnerabilities, POA&Ms, and corrective actions.
  • Support security control assessment and continuous monitoring activities.
  • Develop and maintain executive-level cybersecurity dashboards, metrics, and status reports.
  • Provide technical guidance and mentoring to junior GRC and cybersecurity personnel.
  • Coordinate with system owners, ISSOs, ISSMs, SCAs, security engineers, and other stakeholders to resolve GRC issues.
  • Support audits, inspections, assessments, and compliance reviews by providing accurate GRC data and supporting documentation.
  • Ensure GRC processes remain aligned with federal cybersecurity policies, NIST standards, and organizational requirements.
  • Evaluate emerging GRC technologies and recommend enhancements to improve cybersecurity risk management capabilities.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Systems, Information Assurance, Computer Science, or a related field.
  • Demonstrated experience working with RSA Archer or comparable GRC platforms.
  • Strong understanding of Governance, Risk, and Compliance principles.
  • Experience supporting cybersecurity risk management and compliance programs.
  • Experience with cybersecurity controls, risk assessments, security assessments, POA&Ms, and compliance reporting.
  • Experience developing or maintaining GRC workflows, dashboards, reports, and data structures.
  • Strong understanding of the NIST Risk Management Framework (RMF).
  • Ability to analyze cybersecurity requirements and translate them into effective GRC processes and configurations.
  • Strong analytical, problem-solving, documentation, and communication skills.
  • Ability to work effectively with technical teams, cybersecurity professionals, government stakeholders, and senior leadership.
Required Certification
  • RSA Archer Certified Administrator or RSA Archer Certified Professional certification.
Preferred Qualifications
  • Experience supporting federal civilian or Department of Defense cybersecurity programs.
  • Experience with NIST SP 800-53, NIST SP 800-37, FISMA, and federal information security requirements.
  • Experience with other GRC platforms such as ServiceNow GRC, eMASS, or equivalent.
  • Knowledge of vulnerability management and cybersecurity assessment processes.
  • Experience integrating GRC platforms with enterprise IT and cybersecurity tools.
  • Experience with cloud security and cloud governance.
  • AWS, Azure, Google Cloud, or Microsoft 365 certifications are highly desirable.
  • Experience supporting ATO and continuous authorization activities.
  • Experience developing cybersecurity metrics and executive dashboards.
  • CISSP, CISM, CAP, or equivalent cybersecurity/GRC certification is a plus.
Technical Skills
  • RSA Archer GRC
  • Archer administration and configuration
  • GRC workflow development
  • GRC dashboards and reporting
  • Risk management
  • Cybersecurity compliance
  • NIST RMF
  • NIST SP 800-53
  • FISMA
  • Security controls
  • POA&M management
  • ATO / Authorization
  • Continuous Monitoring
  • Security Assessment & Authorization (A&A)
  • Vulnerability and risk management
  • Cybersecurity metrics and reporting
  • GRC data governance
RiVidium Inc is seeking a 'Archer / Governance, Risk, and Compliance (GRC) Subject Matter Expert (SME)' to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify qualified candidates for a potential future opportunity and does not represent a currently available position. Compensation has not yet been determined and will be established based on contract requirements, candidate qualifications, experience, and applicable market conditions.

About the Organization Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology. EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at hr@rividium.com.
This position is currently accepting applications.
group id: RTX15cf25

Similar Jobs


Clearance Level
Secret