RMF IT Security Analyst

System One

Bethesda (MD)

Hybrid

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
401(k) plan
Dental insurance
Vision insurance
Life insurance

Job summary

System One in Bethesda, Maryland is seeking a mid-level RMF IT Security Analyst to support RMF lifecycle activities, security assessments, continuous monitoring, and compliance initiatives. You will work under Lead and Senior RMF personnel, mentoring junior staff, with a largely remote schedule and occasional on-site meetings.

The role emphasizes collaboration with NIH, HHS, OIG, GAO, and other oversight bodies, and involves developing SSPs, SARs, POA&Ms, and authorization packages while

Qualifications

  • Bachelor's degree in a related technical field or equivalent experience.
  • 3–5 years supporting RMF, cybersecurity compliance, or information security programs.

Responsibilities

  • Support RMF lifecycle activities, security assessments, continuous monitoring, and compliance initiatives.
  • Develop, review, and maintain RMF documentation including SSPs, SARs, POA&Ms, and authorization packages.
  • Support system categorization, security control selection, assessments, authorization, and continuous monitoring.
  • Maintain the Risk Management Register and track remediation activities.
  • Coordinate contingency plan testing and document results and corrective actions.
  • Communicate risk posture and compliance status with system owners, ISSOs, and technical teams.

Skills

RMF processes
Documentation
Cybersecurity compliance
Analytical skills
Communication
Team collaboration

Education

Bachelor's degree

Tools

eMASS
GRC platforms

Job description

Job Title: RMF IT Security Analyst
Location: Bethesda, Maryland
Type: Direct Hire / Perm
Work Model: 99% remote with occasional onsite for meetings
Security Clearance: Public Trust

Position Summary

The RMF IT Security Analyst serves as a mid-level cybersecurity professional. Working under Lead and Senior RMF personnel, the analyst independently supports RMF lifecycle activities, security assessments, continuous monitoring, and compliance initiatives while mentoring junior staff. Work is primarily remote with occasional on-site meetings.

Key Responsibilities
  • Support the implementation and maintenance of the NIST RMF program.
  • Develop, review, and maintain RMF documentation including SSPs, SARs, POA&Ms, and authorization packages.
  • Support system categorization, security control selection, assessments, authorization, and continuous monitoring.
  • Maintain the Risk Management Register and track remediation activities.
  • Support cybersecurity audits and assessments conducted by NIH, HHS, OIG, GAO, and other oversight organizations.
  • Support Cybersecurity Supply Chain Risk Management (C-SCRM) activities, including vendor documentation and SBOM reviews.
  • Manage or assist with Risk Mitigation Waivers, documentation, approvals, annual reviews, and tracking.
  • Coordinate contingency plan testing and document results and corrective actions.
  • Communicate risk posture and compliance status while collaborating with system owners, ISSOs, and technical teams.
  • Provide technical guidance and mentoring to junior analysts.
Required Qualifications

Bachelor's degree in a related technical field (or equivalent experience) and 3–5 years supporting RMF, cybersecurity compliance, or information security programs.

Preferred Qualifications
  • Experience supporting federal civilian agencies, including NIH, HHS, or other Federal agencies.
  • Familiarity with NIST RMF, NIST SP 800-37, NIST SP 800-53 Rev. 5, and the Joint Cybersecurity Assessment Methodology (JCAM).
  • Experience using eMASS or similar Governance, Risk, and Compliance (GRC) platforms.
  • Experience supporting cybersecurity audits, POA&Ms management, continuous monitoring, and contingency planning.
  • Knowledge of Cybersecurity Supply Chain Risk Management (C-SCRM).
  • Experience developing or reviewing SSPs, SARs, SAPs, POA&Ms, and Authorization Packages.
Desired Certifications
  • ISC2 Certified in Cybersecurity (CC)
  • CompTIA Security+
  • CompTIA CySA+
  • CompTIA SecurityX (formerly CASP+)
  • CompTIA PenTest+
  • CAP/CGRC
  • CISSP
  • CISM
Knowledge, Skills, and Abilities

Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity compliance. Ability to collaborate with system owners, ISSOs, and technical teams.

Work Environment

This position is primarily remote with occasional on-site meetings or support activities as required.

System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote RMF IT Security Analyst | Public Trust
Remote RMF IT Security Analyst | Public Trust

System One • Bethesda (MD)

Hybrid
USD 90,000 - 130,000
Health benefits
401(k) plan
Dental insurance
+2
Mid-Level Security Control Assessor
Mid-Level Security Control Assessor

System One • Bethesda (MD)

Hybrid
USD 135,000 - 145,000
Health and welfare benefits
401(k) plan
RMF Engineer
RMF Engineer

Innovatus Technology Consulting • San Diego (CA), Northern (KY)

Hybrid
USD 110,000 - 160,000
Mostly remote hybrid
Mission impact in DoD programs
SDVOSB veteran-friendly environment
+1
Senior Cybersecurity Analyst / RMF Lead
Senior Cybersecurity Analyst / RMF Lead

chameleonintegratedservices • South Dakota

On-site
USD 120,000 - 160,000
Health insurance
Vision plan
401K with match
+4
Mid-Level Cybersecurity Incident Response Analyst
Mid-Level Cybersecurity Incident Response Analyst

System One • Bethesda (MD)

Hybrid
USD 120,000
Medical insurance
Dental insurance
Vision insurance
+3
Information System Security Officer, RMF Specialist
Information System Security Officer, RMF Specialist

Boston Government Services • Oak Ridge (TN)

Hybrid
USD 136,000 - 161,000
Health Insurance
Dental Insurance
Vision Insurance
+4
Information System Security Officer, RMF Specialist
Information System Security Officer, RMF Specialist

Boston Government Services, LLC (BGS) • Knoxville (TN)

Hybrid
USD 136,000 - 161,000
Health Insurance
Dental Insurance
Vision Insurance
+4
Mid-Level Vulnerability Management Analyst
Mid-Level Vulnerability Management Analyst

System One • Bethesda (MD)

Hybrid
USD 90,000 - 120,000
Health and welfare benefits
401(k) plan
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

P3S CORPORATION • Dayton (OH)

On-site
USD 95,000 - 120,000
Risk Management Framework (RMF) Analyst
Risk Management Framework (RMF) Analyst

FEDITC • Shiloh (IL)

On-site
USD 95,000 - 105,000
Medical
Vision
401K with 4% match
+9