Mid-Level RMF Controls, ConMon Analyst

Jobtailor

Maryland

On-site

USD 110,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a skilled RMF/ConMon professional to lead continuous monitoring, risk registers, and POA&M processes across a federal portfolio.

You will maintain control assessments, coordinate with audit teams, and deliver executive-ready risk reporting, including weekly dashboards and annual risk profiles.

Qualifications

  • Bachelor’s degree or equivalent experience per policy.
  • 4+ years in federal RMF, continuous monitoring, or security control assessment per NIST 800-37/800-53/800-53A.
  • Experience managing portfolio-scale POA&M, aging analysis, milestones, evidence, and closures.
  • Experience with control assessments using interview, examine, and test methods.
  • Knowledge of risk registers, risk-acceptance and waiver processes, and NIST SP 800-30 risk assessment methodology.
  • Experience with enterprise GRC platforms such as JCAM, CSAM, eMASS, or Xacta.
  • Strong analytical writing for executive audiences.
  • Ability to meet federal background investigation requirements.

Responsibilities

  • Conduct quarterly RMF control evaluations and document results in POA&M.
  • Maintain system-level ConMon plans and posture visibility.
  • Populate and maintain the Enterprise Risk Management Register with risks, severity, and mitigation.
  • Manage and track POA&M with milestones, owners, and evidence.
  • Support risk mitigation waivers, intake, approvals, and reassessment.
  • Coordinate annual Contingency Plan and Incident Response Plan tests.
  • Verify artifact freshness and flag stale evidence.
  • Provide oversight for High Value Assets and reporting.
  • Prepare inputs for weekly dashboards and quarterly/annual risk reports.
  • Assist audits (OIG, GAO) with artifact collection and corrective actions.

Skills

POA&M management
RMF operations
NIST standards
GRC platforms
executive reporting
risk assessment
background clearance

Education

Bachelor’s degree
Equivalent experience

Tools

JCAM
CSAM
EMASS
Xacta

Job description

  • Execute ongoing-authorization control evaluations on a rotating quarterly cycle, documenting results, dispositioning each control as satisfied or other-than-satisfied, and injecting findings into the POA&M process.
  • Develop and maintain system-level Continuous Monitoring (ConMon) Plans providing ongoing visibility into each system’s security posture.
  • Populate and continuously maintain the enterprise Risk Management Register, logging all identified system-level risks with severity, status, and mitigation plans, and preparing the monthly register deliverable.
  • Manage and track POA&M to timely remediation, enforcing linkage of every weakness to a control, aging findings against remediation clocks, and maintaining milestones, owners, and evidence.
  • Support the risk mitigation waiver lifecycle, including standardized intake, documented risk determination and approval authority, maintenance of the Risk Mitigation Waiver Register, annual reassessment of active waivers, escalation of expirations, and recommendations to terminate, modify, or renew based on current risk posture.
  • Coordinate and document annual Contingency Plan and Incident Response Plan tests, including test reports with results, lessons learned, and corrective actions.
  • Verify artifact freshness across the authorization portfolio and flag stale evidence for refresh before it becomes an audit finding.
  • Provide enhanced oversight for High Value Assets, including prioritized monitoring and reporting.
  • Prepare continuous monitoring inputs for weekly executive dashboards, the monthly cybersecurity risk profile, and quarterly and annual FISMA reporting.
  • Support internal and external assessments and audits, including artifact collection, interview support, and corrective-action tracking for OIG, GAO, and departmental reviews.
Requirements
  • Bachelor’s degree in a related field, or equivalent experience as allowed by company and contract policy.
  • Four or more years of experience in federal RMF operations, continuous monitoring, or security control assessment under NIST SP 800-37, 800-53, and 800-53A.
  • Demonstrated experience managing POA&M at portfolio scale, including aging analysis, milestone tracking, evidence management, and closure validation.
  • Experience conducting or supporting control assessments using interview, examine, and test methods, and documenting defensible results.
  • Working knowledge of risk registers, risk-acceptance and waiver processes, and NIST SP 800-30 risk assessment methodology.
  • Experience with enterprise GRC platforms such as JCAM, CSAM, eMASS, or Xacta.
  • Strong analytical writing skills, including the ability to summarize technical risk for executive audiences.
  • Ability to meet federal background investigation requirements.
Core Competencies

Demonstrates expertise in federal Risk Management Framework (RMF) operations, continuous monitoring, and security control assessments, with a strong focus on managing Plans of Action and Milestones (POA&Ms) and risk registers. Proficient in analytical writing for executive reporting and maintaining compliance with NIST standards.

Tools & Technologies
  • JCAM
  • CSAM
  • EMASS
  • Xacta
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Risk Management Support Lead
Risk Management Support Lead

Jobtailor • Illinois

On-site
USD 120,000 - 180,000
Risk Management Framework Cyber SME
Risk Management Framework Cyber SME

TMC TECHNOLOGIES • Albuquerque (NM)

On-site
USD 90,000 - 130,000
Security Control Assessor
Security Control Assessor

RMantra Solutions • Virginia (MN)

On-site
USD 100,000 - 130,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital Global Connectors • McLean (VA)

Hybrid
USD 110,000 - 160,000
Information Assurance Specialist – Mid-Level
Information Assurance Specialist – Mid-Level

Jobtailor • United States

On-site
USD 90,000 - 150,000
RMF Analyst / ISSO Support
RMF Analyst / ISSO Support

American Operations Corporation • Town of Texas (WI)

On-site
USD 85,000 - 110,000
Health Care Plan (Medical, Dental & Vision)
Retirement Plan (401k)
Life Insurance (Basic, Voluntary & AD&D)
+2
Cyber Systems Engineer
Cyber Systems Engineer

PL Consulting, Inc. • Chantilly (VA)

On-site
USD 150,000 - 175,000
401(k) with matching
Health, dental, vision insurance
Paid time off
+3
RMF Subject Matter Expert
RMF Subject Matter Expert

Centuria • Lincoln (MA)

On-site
USD 120,000 - 180,000
RMF / Cybersecurity Compliance Specialist
RMF / Cybersecurity Compliance Specialist

Triwill Group • United States

Remote
USD 110,000 - 150,000
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

P3S CORPORATION • Dayton (OH)

On-site
USD 95,000 - 120,000