Stand out for this role — generate a tailored resume and cover letter in about a minute.
PingWind is seeking an RMF / CSAM Analyst to ensure the FSA IAM system maintains continuous security authorization and compliance using RMF and CSAM tools. This remote role supports a cloud-based IAM solution adhering to federal identity standards.
Required: Public Trust clearance, 2 years’ experience, and a Bachelor's degree. Responsibilities include FedRAMP alignment, logging and encryption controls, CSAM security controls, and CSF scorecard maintenance for ATO readiness.
Position Description
The RMF / CSAM Analyst is responsible for ensuring the FSA IAM system maintains continuous security authorization and compliance through the Risk Management Framework (RMF) and the Cyber Security Assessment and Management (CSAM) tool. This role supports the secure operation of the new cloud-based IAM solution while meeting all federal standards for identity services.
Location: Remote
Required Clearance: Public Trust
Required Education: Bachelors Degree
Required Experience: 2 years
Position Description
The RMF / CSAM Analyst is responsible for ensuring the FSA IAM system maintains continuous security authorization and compliance through the Risk Management Framework (RMF) and the Cyber Security Assessment and Management (CSAM) tool. This role supports the secure operation of the new cloud-based IAM solution while meeting all federal standards for identity services.
Responsibilities
The RMF / CSAM Analyst ensures the IAM solution complies with FedRAMP requirements, OMB M-24-15 guidance, and NIST SP 800-63 Digital Identity Guidelines. They manage event logging to meet OMB M-21-31 standards and oversee proper encryption of data at rest (AES-256 with SHA-256) and data in transit (latest TLS protocols). The analyst supports Security Incident Management, maintains environment support documentation, and handles key user data encryption and protection requirements. In CSAM, they manage security controls and inheritance statements, track and remediate Plan of Action and Milestones (POA&M) items, support FISMA reporting and corrective action plans, address Continuous Diagnostics and Monitoring (CDM) findings, handle Common Vulnerabilities and Exposures (CVE) responses, and maintain the Cybersecurity Framework (CSF) scorecard at the required level or higher. Additional responsibilities include supporting supply chain risk management, data planning, federal records and Controlled Unclassified Information (CUI) handling, IT accessibility (Section 508), technology business management reporting, and project, risk, and schedule documentation needed to sustain the Authority to Operate (ATO).
Required Qualifications