RMF Analyst

Semper Valens Solutions

Canyon Lake (TX)

On-site

USD 90,000 - 130,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Semper Valens Solutions is seeking an RMF Analyst to support the assessment, authorization, and continuous monitoring of information systems in line with the NIST RMF and DoD guidance. You will help categorize, select, implement, assess, authorize, and monitor security controls, producing SSPs, SARs, POA&Ms, and RARs.

Responsibilities include control assessments, vulnerability tracking, and supporting ATO/ATT/IATO packages.

Qualifications

  • Bachelor's degree or equivalent experience in cybersecurity or related field.
  • 3+ years supporting RMF, C&A/A&A in federal/DoD environments.
  • Familiarity with NIST SP 800-37/53/53A/60 and FIPS 199/200.
  • Experience developing SSPs, SARs, POA&Ms, and RARs.
  • Active DoD 8570/8140-compliant certification or attainable within 6 months.
  • US Citizenship with eligibility for security clearance.

Responsibilities

  • Support RMF six-step process: Categorize, Select, Implement, Assess, Authorize, Monitor.
  • Develop and maintain SSPs, SARs, POA&Ms, and RARs.
  • Assess controls per NIST 800-53/53A; document findings.
  • Coordinate with system owners and ISSOs/ISSMs to remediate vulnerabilities.
  • Prepare ATO/IATO/ATT packages and monitor authorization lifecycles.
  • Use GRC tools to track compliance status and generate risk briefs.

Skills

RMF
DoD RMF Process
Cybersecurity
Security clearance
Strong writing

Education

Bachelor's degree in Cybersecurity or related

Tools

eMASS
Xacta
CSAM
Archer
ACAS/Nessus

Job description

RMF Analyst

Full Time, Remote, San Antonio, TX area

Secret Clearance

This position is contingent upon contract award

Overview:

Semper Valens Solutions is seeking a detail-oriented RMF Analyst to support the assessment, authorization, and continuous monitoring of information systems in accordance with the NIST Risk Management Framework (RMF) and applicable federal cybersecurity guidelines (NIST SP 800-37, 800-53, 800-53A, FISMA, DoD 8510.01, and CNSSI 1253, as applicable). This role is critical to ensuring organizational systems achieve and maintain an Authorization to Operate (ATO) by supporting security categorization, control selection, implementation, assessment, and continuous monitoring activities throughout the system lifecycle.

Key Responsibilities
  • Support execution of the RMF process across all six steps: Categorize, Select, Implement, Assess, Authorize, and Monitor
  • Develop, review, and maintain security authorization documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports (RARs)
  • Conduct security control assessments against NIST SP 800-53/800-53A control baselines and document findings
  • Perform security categorization of information systems using FIPS 199/200 and NIST SP 800-60
  • Coordinate with system owners, ISSOs, and ISSMs to identify, track, and remediate security vulnerabilities and control deficiencies
  • Support continuous monitoring activities, including periodic control assessments, vulnerability scanning review, and configuration compliance checks
  • Assist in the preparation and submission of Authorization to Operate (ATO), Interim ATO (IATO), and Authorization to Test (ATT) packages
  • Utilize GRC tools (e.g., eMASS, Xacta, CSAM, Archer) to manage authorization packages and track compliance status
  • Review and analyze security assessment results, audit logs, and scan reports (e.g., ACAS/Nessus, STIG checklists) to identify risks
  • Support development and tracking of POA&Ms, ensuring timely remediation of identified weaknesses
  • Ensure compliance with applicable frameworks, including FISMA, DoD RMF, CNSSI 1253, and agency-specific cybersecurity policies
  • Prepare risk briefings and status reports for leadership, Authorizing Officials (AOs), and government stakeholders
  • Stay current on evolving NIST guidance, DoD/agency policy updates, and emerging cybersecurity threats affecting authorization requirements
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field (or equivalent experience)
  • 3+ years of experience supporting RMF, C&A/A&A processes within federal, DoD, or Intelligence Community environments
  • Working knowledge of NIST SP 800-37, 800-53, 800-53A, 800-60, and FIPS 199/200
  • Experience developing or reviewing SSPs, SARs, POA&Ms, and RAR documentation
  • Familiarity with DoD or agency-specific implementation guides (e.g., DoDI 8510.01, ICD 503, CNSSI 1253)
  • Hands-on experience with GRC/eMASS or equivalent RMF tracking tools
  • Understanding of vulnerability management and STIG/SCAP compliance processes
  • Active DoD 8570/8140-compliant certification (e.g., Security+, CySA+, or equivalent) - required or attainable within 6 months of hire
  • Strong written communication skills for technical documentation and stakeholder reporting
  • U.S. Citizenship required; active security clearance or eligibility to obtain one, per position requirements
Preferred Qualifications
  • Active Secret clearance
  • CISSP, CAP (Certified Authorization Professional), or CISM certification
  • Experience with cloud authorization processes (FedRAMP, DoD Cloud Computing SRG)
  • Familiarity with vulnerability scanning tools (ACAS/Nessus, Tenable) and SCAP compliance checkers
  • Experience supporting Cybersecurity Service Provider (CSSP) or SOC operations
  • Knowledge of Zero Trust Architecture principles and their application to RMF
  • Experience working within Intelligence Community (IC) or Defense Industrial Base (DIB) environments
About Semper Valens Solutions:

Semper Valens Solutions, Inc. (SVS) is a Service-Disabled Veteran Owned Small Business (SDVOSB) providing Cost Effective Software and Systems Engineering, Field Support, Training and Full Life cycle Support Management to the DOD and VA community.

At Semper Valens, our vision is to remain a creative, cutting edge and cost-effective solutions provider where our shared intellect, industry experience, and technology excellence, make a positive difference in our customer's success. Our solutions help bridge the gap between IT and business prioritizations to optimize budgets, risks and operational processes.

We search for outstanding technical professionals, hiring at all levels of the experience spectrum; intermediate, journeyman and senior. Consider us for your career plan.

Semper Valens Solutions is an Equal Opportunity Employer

Semper Valens Solutions proactively fulfills its role as an equal opportunity employer. We do not discriminate against any employee or applicant for employment because of race, color, sex, religion, age, sexual orientation, gender identity and expression, national origin, marital/parental status, pregnancy/childbirth, or related conditions, physical or mental disability, genetic information, status as a Disabled Veteran, Recently Separated Veteran, Active-Duty Wartime or Campaign Badge Veteran, Armed Forces Services Medal, or any other characteristic protected by law.

If you require a reasonable accommodation to apply for a position with Semper Valens Solutions through its online applicant system, please contact Semper Valens Solutions Human Resources Department at (830) 899-6870.

Semper Valens Solutions is an affirmative action/equal opportunity employer - minorities, females, disabled, and protected veterans are urged to apply. Applicants have rights under Federal Employment Laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote RMF Analyst with Secret Clearance
Remote RMF Analyst with Secret Clearance

Semper Valens Solutions • Canyon Lake (TX)

On-site
USD 90,000 - 130,000
RMF Engineer - Intermediate
RMF Engineer - Intermediate

Xcelerate-Solutions-5 • Seaside (CA)

On-site
USD 94,000 - 127,000
RMF Cybersecurity Analyst
RMF Cybersecurity Analyst

ASRC Federal • Virginia (IL), Northern (KY)

Hybrid
USD 90,000 - 120,000
Health care
Dental
Vision
+4
RMF Cyber Security Analyst - 306210
RMF Cyber Security Analyst - 306210

DNI (Delaware Nation Industries) • Virginia Beach (VA)

On-site
USD 110,000 - 115,000
Covers 100% of employee premiums (Medi
Matching 401K
Short- and Long-Term Disability
+3
Information System Security Officer, RMF Specialist
Information System Security Officer, RMF Specialist

Boston Government Services, LLC (BGS) • Knoxville (TN)

Hybrid
USD 136,000 - 161,000
Health Insurance
Dental Insurance
Vision Insurance
+4
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

P3S CORPORATION • Dayton (OH)

On-site
USD 95,000 - 120,000
RMF Engineer
RMF Engineer

VMD Corp • Alexandria (VA)

On-site
USD 90,000 - 130,000
Risk Management Framework (RMF) Analyst
Risk Management Framework (RMF) Analyst

FEDITC • Shiloh (IL)

On-site
USD 95,000 - 105,000
Medical
Vision
401K with 4% match
+9
RMF Information System Security Officer (ISSO)
RMF Information System Security Officer (ISSO)

Colsa-5 • Albany (GA)

On-site
USD 110,000 - 150,000
Risk Management Framework Cyber SME
Risk Management Framework Cyber SME

TMC TECHNOLOGIES • Albuquerque (NM)

On-site
USD 90,000 - 130,000