Senior RMF Security Analyst

Hirebridge

Gaithersburg (MD)

Hybrid

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Hirebridge seeks a senior RMF Security Analyst to support federal information systems, guiding RMF Steps 1–3 and developing essential security documentation for Authorities to Operate. The role requires extensive federal A&A experience and the ability to produce high-quality RMF artifacts across multiple information systems.

The candidate will collaborate with government stakeholders to finalize system security plans, contingency and incident response plans, and related documentation, ensuring

Qualifications

  • Citizenship in the U.S. is required.
  • At least eight years of cybersecurity experience.
  • Experience applying the NIST RMF for federal systems.
  • Hands-on A&A and authorization package development.
  • Strong ability to produce Section 508-compliant docs.

Responsibilities

  • Categorize systems per RMF Step 1.
  • Select and tailor controls per RMF Step 2.
  • Implement and support review per RMF Step 3.
  • Develop and update SSPs, contingency, and incident response plans.
  • Coordinate with stakeholders for accurate RMF documentation.

Skills

NIST RMF
Technical writing
Security documentation

Education

Bachelor's degree

Tools

CSAM

Job description

ITLE: Senior RMF Security Analyst
LOCATION: Hybrid (Beltsville, Maryland)
Position Overview

We are seeking a senior, hands‑on RMF Security Analyst to support federal information systems through RMF Steps 1–3. The analyst will work closely with government cybersecurity stakeholders to develop and maintain the security documentation required to achieve, maintain, and renew system Authorities to Operate (ATOs).

The ideal candidate will have extensive federal A&A experience and the ability to independently develop high‑quality RMF documentation across multiple information systems.

Responsibilities
RMF Step 1 – Categorize the System
  • Collect and update general system information.
  • Create and maintain system records in CSAM, including system identification information, system descriptions, and technical narratives.
  • Prepare and update Privacy Threshold Analyses (PTAs) and Privacy Impact Assessments (PIAs).
  • Perform and update FIPS 199 security categorizations.
  • Perform and update E-Authentication Risk Assessments.
RMF Step 2 – Select Security Controls
  • Identify common and inherited security controls, including controls inherited from FedRAMP-authorized services.
  • Develop and update compliance descriptions for applicable NIST SP 800-53 controls, including tailoring decisions.
  • Develop compensating controls when required.
  • Develop and update Contingency Plans and related testing and training documentation.
  • Develop and update System of Records Notices, Configuration Management Plans, Incident Response Plans, Business Impact Assessments, and Interconnection Security Agreements.
RMF Step 3 – Implement and Support Review
  • Finalize System Security Plan compliance descriptions.
  • Finalize Contingency Plans, Configuration Management Plans, Incident Response Plans, and Disaster Recovery Plans, as required.
  • Assist government stakeholders in addressing findings and updating documentation during concurrence and authorization reviews.
  • Coordinate with technical and business stakeholders to ensure RMF documentation is accurate, complete, consistent, and ready for authorization review.
Required Qualifications
  • U.S. citizenship.
  • Bachelor’s degree and at least eight years of relevant cybersecurity experience.
  • Experience completing all aspects of the NIST Risk Management Framework for federal information systems.
  • Hands‑on experience developing and maintaining federal A&A and authorization packages.
  • Working knowledge of:
    • NIST Risk Management Framework
    • FIPS PUB 199
    • NIST SP 800-53 Rev. 4 and/or Rev. 5
    • NIST SP 800-37 Rev. 2
    • NIST SP 800-171 Rev. 2
    • NIST SP 800-47 Rev. 1
    • Other publications and guidance related to the federal RMF process
  • Hands‑on experience using the Cybersecurity Assessment and Management System (CSAM).
  • Experience supporting ATOs involving FedRAMP-authorized products, solutions, or platforms.
  • Experience developing SSPs, contingency plans, incident response plans, configuration management plans, business impact assessments, interconnection security agreements, and privacy documentation.
  • Strong technical‑writing skills and the ability to produce accurate, complete, and Section 508‑compliant documentation.
  • Ability to appropriately handle Controlled Unclassified Information and other sensitive government information.
  • Ability to successfully obtain and maintain the required federal background investigation, suitability determination, facility access, and PIV credential.
Preferred Qualifications
  • Prior federal civilian‑agency A&A experience.
  • Prior USDA cybersecurity or RMF experience is a plus.
  • Experience with the USDA Six‑Step RMF Process or USDA CSAM instance is a strong plus.
  • Experience independently supporting RMF activities across multiple federal information systems.
  • Active certification such as CISSP, CGRC (formerly CAP), or CISM.
  • Current or prior federal Public Trust investigation.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior RMF Security Analyst
Senior RMF Security Analyst

AssurIT • Beltsville (MD)

Hybrid
USD 110,000 - 160,000
Medical coverage
Dental coverage
Paid time off
Security Analyst – Risk Management Framework (RMF) / Assessment & Authorization
Security Analyst – Risk Management Framework (RMF) / Assessment & Authorization

Wintrio LLC • United States

Hybrid
USD 110,000 - 160,000
Healthcare
FSA/HSA options
401(k) Retirement Plan
+4
RMF Security Analyst – A&A & Authorization (Remote)
RMF Security Analyst – A&A & Authorization (Remote)

Wintrio LLC • United States

Hybrid
USD 110,000 - 160,000
Healthcare
FSA/HSA options
401(k) Retirement Plan
+4
Senior RMF Security Analyst — Hybrid (MD), ATO Specialist
Senior RMF Security Analyst — Hybrid (MD), ATO Specialist

AssurIT • Beltsville (MD)

On-site
USD 110,000 - 160,000
Medical coverage
Dental coverage
Paid time off
Senior RMF Security Analyst — Federal ATO Expert (Hybrid)
Senior RMF Security Analyst — Federal ATO Expert (Hybrid)

Hirebridge • Gaithersburg (MD)

On-site
USD 120,000 - 180,000
RMF Cybersecurity Analyst II - 505767
RMF Cybersecurity Analyst II - 505767

Delaware Nation Industries • Bath Township (OH)

On-site
USD 70,000 - 100,000
Benefits coverage
401K match
Disability insurance
+3
Sr. Information Assurance Specialist
Sr. Information Assurance Specialist

NR Labs LLC • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

P3S CORPORATION • Dayton (OH)

On-site
USD 95,000 - 120,000
RMF Cyber Security Analyst Senior
RMF Cyber Security Analyst Senior

Saic • Quantico (VA)

On-site
USD 120,000 - 160,000
Cybersecurity Specialist
Cybersecurity Specialist

Sarela Technology Solutions • Fort Belvoir (VA)

On-site
USD 120,000 - 180,000
401(k)
401(k) matching
Dental insurance
+6