Risk Management Framework Analyst

SAIC

Colorado Springs (CO)

On-site

USD 80,000 - 120,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

SAIC seeks a Risk Management Framework (RMF) Analyst/ISSO to support NORAD/NORTHCOM IT services onsite in Colorado Springs. You will own RMF lifecycle artifacts, coordinate ATO sustainment, and drive continuous monitoring while ensuring controls align with DoD directives and NIST SP 800-53 standards.

You will develop and maintain SSPs, manage POA&Ms, and interact with system owners and engineers to maintain a robust security posture in a high-tempo environment.

Qualifications

  • Active TS/SCI security clearance required.
  • Bachelor’s degree in information assurance, cybersecurity, or related field; or 7–10 years of relevant experience with no degree.
  • 2+ years as ISSO or cybersecurity practitioner on DoD systems.
  • Certification per DoD 8140.03 at Intermediate level (e.g., Security+).

Responsibilities

  • Support and execute RMF lifecycle across enterprise systems and enclaves; maintain registrations, baselines, and evidentiary records in eMASS.
  • Drive continuous monitoring and ATO sustainment with ISSO ownership.
  • Ensure DoD/NIST controls (800-53) are implemented and audit-ready.
  • Develop, validate, and maintain System Security Plans (SSPs).
  • Lead POA&Ms management and coordinate closure with stakeholders.
  • Collaborate with system admins and leadership to remediate findings.

Skills

Security clearance TS/SCI
Autonomy
Cross-functional teamwork

Education

Bachelor’s degree in information assurance / cybersecurity
High school diploma with 7–10 years of experience

Tools

STIG Viewer
eMASS
POA&Ms management

Job description

Minimum Clearance Required TS.SCI

Job ID 2617151
Location Colorado Springs, CO, US
Date Posted 2026-09-23
Category Cyber
Subcategory Cybersecurity Spec
Schedule Full-Time
Shift Day Job
Travel No
Minimum Clearance Required TS.SCI
Clearance Level Must Be Able to Obtain None
Potential for Remote Work ORA_ON_SITE

Description

SAIC is seeking a Risk Management Framework (RMF) Analyst for an Information Systems Security Officer (ISSO) position supporting the RMF requirements of the North American Aerospace Defense Command and United States Northern Command (NORAD/USNORTHCOM) Information Technology (IT) Enterprise Services (NITES) contract. The primary work location is onsite in Colorado Springs.

Responsibilities
  • Supporting and executing the RMF process across multiple enterprise systems and enclaves by maintaining system registrations, security baselines, and evidentiary records within the Enterprise Mission Assurance Support Service (eMASS).
  • Operating with ISSO-level ownership to independently drive continuous monitoring and Authority to Operate (ATO) sustainment, ensuring an uninterrupted and robust security posture.
  • Ensuring cybersecurity standards and operational hygiene are consistently maintained to support a Cyber Operational Readiness Assessment (CORA)-ready posture.
  • Managing the continuous cybersecurity posture of enterprise systems and identifying mitigations necessary to meet Department of Defense Directive (DoDD) 8500.01, Department of Defense Instruction (DoDI) 8510.01, DoDD 8140.01, and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 requirements.
  • Analyzing and correlating scan results from the Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP), and other approved tools to evaluate system risk, determine security posture, and maintain ATO and Assess Only authorizations.
  • Assisting with system categorization in accordance with Committee on National Security Systems Instruction (CNSSI) 1253, including confidentiality, integrity, and availability impact levels, as information types, mission profiles, and system interconnections evolve.
  • Leading the development, maintenance, and technical validation of System Security Plans (SSPs), ensuring evidentiary artifacts accurately reflect current technical architectures and that applicable Security Technical Implementation Guides (STIGs) are implemented.
  • Exercising end-to-end ownership of Plans of Action and Milestones (POA&Ms) by systematically evaluating deficiencies, determining risk impacts, and coordinating with technical stakeholders to drive findings to timely closure.
  • Collaborating proactively with system administrators, network engineers, and leadership to remediate STIG findings, vulnerability scan results, and architectural deficiencies.
  • Providing strategic cybersecurity guidance, risk assessments, and status updates to system owners and leadership.
  • Providing weekly status reports that summarize accomplishments across assigned packages, risk posture, issues, and paths forward.
  • Creating, refining, and enforcing the operational policies, procedures, and artifacts necessary to ensure security controls are fully implemented and audit-ready.
Qualifications
Required Qualifications
  • Certification required in accordance with DoD Manual (DoDM) 8140.03 at the Intermediate level, such as CompTIA Security+ or an equivalent certification.
  • Bachelor’s degree in information assurance, cybersecurity, or a related field, plus 3–5 years of relevant experience; or a high school diploma or equivalent plus 7–10 years of relevant information assurance or cybersecurity experience.
  • At least 2 years of direct experience serving as an ISSO or cybersecurity practitioner supporting DoD systems, including
    • Direct experience managing RMF lifecycle artifacts and end-to-end eMASS package management across multiple concurrent systems.
    • Proven experience authoring, tracking, and coordinating technical remediation to drive POA&Ms to validated completion.
  • Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.
  • Demonstrated ability to operate with a high degree of autonomy, self-direct work, and lead cross-functional technical teams through complex authorization lifecycles.
Desired Qualifications
  • Ability to work effectively in a team-focused, dynamic, high-tempo operational environment.
  • Experience using STIG Viewer and automated compliance tools.
  • Prior experience participating in Change Advisory Boards (CABs).

Target salary range $80,001 - $120,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Risk Management Framework Analyst
Risk Management Framework Analyst

RiseMe • Colorado Springs (CO)

On-site
USD 110,000 - 150,000
Cyber Analyst-RMF Specialist
Cyber Analyst-RMF Specialist

Saic • Colorado Springs (CO)

On-site
USD 120,000 - 160,000
RMF Cyber Security Analyst Senior
RMF Cyber Security Analyst Senior

Saic • Quantico (VA)

On-site
USD 120,000 - 160,000
Cybersecurity Analyst / RMF (ISSO)
Cybersecurity Analyst / RMF (ISSO)

Paycom • Maryland

On-site
USD 111,000 - 126,000
RMF ISSO Lead — On‑Site (TS/SCI) NORAD/NORTHCOM
RMF ISSO Lead — On‑Site (TS/SCI) NORAD/NORTHCOM

SAIC • Colorado Springs (CO)

On-site
USD 80,000 - 120,000
Principal Engineer, Cybersecurity RMF (Onsite - Largo, FL) TS/SCI clearance required
Principal Engineer, Cybersecurity RMF (Onsite - Largo, FL) TS/SCI clearance required

Collins Aerospace • Largo (FL)

On-site
USD 120,000 - 180,000
Restaurant d'entreprise
Indemnités de stage/alternance
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Noblis • Huntsville (AL)

On-site
USD 90,000 - 150,000
RMF Analyst: End-to-End Cyber Risk & ATO Lead
RMF Analyst: End-to-End Cyber Risk & ATO Lead

RiseMe • Colorado Springs (CO)

On-site
USD 110,000 - 150,000
Principal Engineer, Cybersecurity RMF (Onsite - Largo, FL) TS/SCI clearance required
Principal Engineer, Cybersecurity RMF (Onsite - Largo, FL) TS/SCI clearance required

RTX • Largo (FL)

On-site
USD 130,000 - 170,000
DoD RMF Cybersecurity Engineer
DoD RMF Cybersecurity Engineer

Systems Planning & Analysis • Huntsville (AL)

On-site
USD 90,000 - 130,000