Senior RMF Security Analyst

Assurit

Fairfax (VA)

Hybrid

USD 110,000 - 140,000

Full time

37 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical and dental coverage
Paid time off
Competitive compensation

Job summary

Assurit is seeking an experienced Senior RMF Security Analyst to support one of our federal clients. You will develop and maintain security documentation to achieve and renew system Authorities to Operate (ATO).

The role requires extensive federal A&A experience and the ability to independently craft RMF documentation across multiple information systems. The ideal candidate will work with government cybersecurity stakeholders, perform RMF steps, and ensure compliance with NIST SP 800-53

Qualifications

  • U.S. citizenship is required.
  • Bachelor’s degree and at least six years of relevant cybersecurity experience.
  • Experience with the NIST RMF for federal information systems.
  • Experience developing SSPs, contingency plans, incident response plans, and privacy documentation.
  • Strong technical-writing skills and ability to produce accurate, complete documentation.

Responsibilities

  • Categorize the system and maintain system records in CSAM.
  • Select and tailor security controls; develop compliance descriptions.
  • Implement plans and support RMF reviews with stakeholders.
  • Coordinate RMF activities across multiple federal information systems.

Skills

Technical writing
Regulatory compliance
Federal cybersecurity
Document management

Education

Bachelor’s degree

Tools

CSAM

Job description

About Us
  • Our Company Our mission is simple, our vision is clear, and our values are strong.
  • Our Team Our people are our greatest asset — they will be one of yours as well.
  • Our Joint Venture AdvanceX combines Noblis ESI R&D with Assurit cybersecurity expertise.
  • Our Clients We are a nationwide trusted partner to the public and private sectors.
  • Awards & Accomplishments Follow our journey as we work for the advancement of cybersecurity.
  • Press Contract awards, strategic partnerships, and mission-driven milestones.
What We Do
  • Implementation & Advisory Develop and implement sustainable security strategies
  • Governance & Cyber Program Development
  • Third-Party Security
  • Privacy & Data Protection
  • Assessment & Compliance Anticipate and alleviate risks that can threaten your business
  • Audit Readiness
  • Penetration Testing
  • Vulnerability Scanning & Assessments
  • Security Assessment & Authorization (SA&A)
  • Incident & Threat Management Prevent, manage and recover from security incidents
  • Data Breach Readiness
  • Tabletop & Simulated Exercises
  • Incident Response
  • Threat Hunting
  • Security Architecture & Engineering Build, deploy and monitor effective cyber safeguards
  • Cloud Security
  • Continuous Monitoring
  • Business Continuity & Disaster Recovery
  • Enterprise Mobility
Capabilities
  • Our Capabilities Discover Assurit’s ability to deliver tailored and effective solutions to your most complex cybersecurity challenges.
  • Small Business Certifications
  • Quality Initiatives
  • NAICS / Product & Service Codes
  • Certifications & Contract Vehicles
  • Core Capabilities & Staff Qualifications
  • Our Capabilities Our proven methodologies will tackle your most complex challenges.
  • Case Studies Our extensive experience demonstrates our ability to drive measurable impact.
  • Capability Statement (PDF) Download our PDF Capability Statement
Contract Vehicles
  • SBA 8(a) Certified SBA 8(a) Sole-Source and Competitive
  • GSA Schedule GSA Multiple Award Schedule (MAS)
  • NASA SEWP VI Solutions for Enterprise-Wide Procurement
  • GSA 8(a) STARS III GSA 8(a) STARS III
  • NASPO ValuePoint NASPO ValuePoint
  • MDA SHIELD IDIQ MDA SHIELD
  • SeaPort NxG Navy SeaPort Next Generation (NxG)
  • eFAST FAA eFAST
  • Maryland CATS+ Maryland CATS+
Contact
  • Contact
  • CMMC L2
  • SBA 8(a)
  • ISO 9001
  • ISO 27001
  • ISO 20000-1
  • CMMI-SVC ML3 v2.0
  • CAGE 6VE87
  • UEI DL3JL6J1XG98
Senior RMF Security Analyst

Hybrid (Beltsville, Maryland)

Posted on September 18, 2026

Job Summary

Assurit is currently seeking an experienced Senior RMF Security Analyst to support one of our clients. The analyst will work closely with government cybersecurity stakeholders to develop and maintain the security documentation required to achieve, maintain, and renew system Authorities to Operate (ATOs). The ideal candidate will have extensive federal A&A experience and the ability to independently develop high-quality RMF documentation across multiple information systems.

Responsibilities
RMF Step 1 – Categorize the System
  • Collect and update general system information.
  • Create and maintain system records in CSAM, including system identification information, system descriptions, and technical narratives.
  • Prepare and update Privacy Threshold Analyses (PTAs) and Privacy Impact Assessments (PIAs).
  • Perform and update FIPS 199 security categorizations.
  • Perform and update E-Authentication Risk Assessments.
RMF Step 2 – Select Security Controls
  • Identify common and inherited security controls, including controls inherited from FedRAMP-authorized services.
  • Develop and update compliance descriptions for applicable NIST SP 800-53 controls, including tailoring decisions.
  • Develop compensating controls when required.
  • Develop and update Contingency Plans and related testing and training documentation.
  • Develop and update System of Records Notices, Configuration Management Plans, Incident Response Plans, Business Impact Assessments, and Interconnection Security Agreements.
RMF Step 3 – Implement and Support Review
  • Finalize System Security Plan compliance descriptions.
  • Finalize Contingency Plans, Configuration Management Plans, Incident Response Plans, and Disaster Recovery Plans, as required.
  • Assist government stakeholders in addressing findings and updating documentation during concurrence and authorization reviews.
  • Coordinate with technical and business stakeholders to ensure RMF documentation is accurate, complete, consistent, and ready for authorization review.
Required Qualifications
  • U.S. citizenship.
  • Bachelor’s degree and at least six years of relevant cybersecurity experience.
  • Experience completing all aspects of the NIST Risk Management Framework for federal information systems.
  • Hands-on experience developing and maintaining federal A&A and authorization packages.
  • Hands-on experience using the Cybersecurity Assessment and Management System (CSAM).
  • Experience supporting ATOs involving FedRAMP-authorized products, solutions, or platforms.
  • Experience developing SSPs, contingency plans, incident response plans, configuration management plans, business impact assessments, interconnection security agreements, and privacy documentation.
  • Strong technical-writing skills and the ability to produce accurate, complete, and Section 508-compliant documentation.
  • Ability to appropriately handle Controlled Unclassified Information and other sensitive government information.
  • Ability to successfully obtain and maintain the required federal background investigation, suitability determination, facility access, and PIV credential.
  • Working knowledge of:
    • NIST Risk Management Framework
    • FIPS PUB 199
    • NIST SP 800-53 Rev. 4 and/or Rev. 5
    • Other publications and guidance related to the federal RMF process
Preferred Qualifications
  • Prior federal civilian-agency A&A experience.
  • Prior USDA cybersecurity or RMF experience is a plus.
  • Experience with the USDA Six-Step RMF Process or USDA CSAM instance is a strong plus.
  • Experience independently supporting RMF activities across multiple federal information systems.
  • Active certification such as CISSP, CGRC (formerly CAP), or CISM.
  • Current or prior federal Public Trust investigation.
Benefits
  • We offer a highly competitive compensation and benefits package inclusive of medical and dental coverage, as well as paid time off.
Equal Opportunity

Assurit is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior RMF Security Analyst
Senior RMF Security Analyst

AssurIT • Beltsville (MD)

Hybrid
USD 110,000 - 160,000
Medical coverage
Dental coverage
Paid time off
Senior RMF Security Analyst
Senior RMF Security Analyst

Hirebridge • Gaithersburg (MD)

On-site
USD 120,000 - 180,000
Security Analyst – Risk Management Framework (RMF) / Assessment & Authorization
Security Analyst – Risk Management Framework (RMF) / Assessment & Authorization

Wintrio LLC • United States

Hybrid
USD 110,000 - 160,000
Healthcare
FSA/HSA options
401(k) Retirement Plan
+4
Senior RMF Security Analyst — Federal A&A Expert
Senior RMF Security Analyst — Federal A&A Expert

Assurit • Fairfax (VA)

Hybrid
USD 110,000 - 140,000
Medical and dental coverage
Paid time off
Competitive compensation
RMF Cybersecurity Analyst
RMF Cybersecurity Analyst

ASRC Federal • Virginia (IL), Northern (KY)

On-site
USD 90,000 - 120,000
Health care
Dental
Vision
+4
Cybersecurity Compliance Analyst
Cybersecurity Compliance Analyst

Reston Consulting Group, Inc. • Suitland (MD)

Hybrid
USD 115,000 - 125,000
RMF Cybersecurity Analyst II - 505767
RMF Cybersecurity Analyst II - 505767

Delaware Nation Industries • Bath Township (OH)

On-site
USD 70,000 - 100,000
Benefits coverage
401K match
Disability insurance
+3
Security Analyst – Risk Management Framework (RMF) / Assessment & Authorization
Security Analyst – Risk Management Framework (RMF) / Assessment & Authorization

WINTrio, LLC • Northern (KY)

Hybrid
USD 85,000 - 120,000
Health insurance
401(k) Retirement Plan
Paid time off
+1
RMF Cybersecurity Analyst
RMF Cybersecurity Analyst

ASRC Federal • Quantico (VA)

Hybrid
USD 70,000 - 100,000
Health care
Dental
Vision
+4
Risk Management Framework (RMF) Analyst
Risk Management Framework (RMF) Analyst

FEDITC • Shiloh (IL)

On-site
USD 95,000 - 105,000
Medical
Vision
401K with 4% match
+9