> Markdown version of [/jobs/ext/2221999-rmf-csam-analyst](https://www.wearedevelopers.com/jobs/ext/2221999-rmf-csam-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF / CSAM Analyst - **Company:** PINGWIND INC - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $75,000.0 - $104,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Event Logging, Identity and Access Management, Microsoft Office, Data Logging, Plan of Action and Milestones - **Published:** August 25, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9114111/rmf-csam-analyst ## About the Role Strong knowledge of NIST Risk Management Framework (RMF) and CSAM tool - Experience with FedRAMP, FISMA, POA&M management, and security control inheritance - Familiarity with NIST SP 800-63, OMB M-21-31, and cloud security requirements - Ability to analyze scan results, develop corrective action plans, and track remediation - Excellent documentation, organization, and attention to detail skills - Clear communication and collaboration with ISSOs, security teams, and stakeholders - Understanding of data encryption, logging, and compliance reporting - Proficiency with Microsoft Office tools and compliance tracking systems - Ability to work effectively on both routine compliance tasks and urgent security issues - Commitment to maintaining high cybersecurity standards in a federal environment - Detail-oriented with excellent documentation and tracking skills - Good understanding of federal cybersecurity policies and compliance requirements - Team player capable of supporting both routine compliance and urgent security tasks ## Description The RMF / CSAM Analyst is responsible for ensuring the FSA IAM system maintains continuous security authorization and compliance through the Risk Management Framework (RMF) and the Cyber Security Assessment and Management (CSAM) tool. This role supports the secure operation of the new cloud-based IAM solution while meeting all federal standards for identity services., The RMF / CSAM Analyst ensures the IAM solution complies with FedRAMP requirements, OMB M-24-15 guidance, and NIST SP 800-63 Digital Identity Guidelines. They manage event logging to meet OMB M-21-31 standards and oversee proper encryption of data at rest (AES-256 with SHA-256) and data in transit (latest TLS protocols). The analyst supports Security Incident Management, maintains environment support documentation, and handles key user data encryption and protection requirements. In CSAM, they manage security controls and inheritance statements, track and remediate Plan of Action and Milestones (POA&M) items, support FISMA reporting and corrective action plans, address Continuous Diagnostics and Monitoring (CDM) findings, handle Common Vulnerabilities and Exposures (CVE) responses, and maintain the Cybersecurity Framework (CSF) scorecard at the required level or higher. Additional responsibilities include supporting supply chain risk management, data planning, federal records and Controlled Unclassified Information (CUI) handling, IT accessibility (Section 508), technology business management reporting, and project, risk, and schedule documentation needed to sustain the Authority to Operate (ATO). ## Related Videos - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Is your backend a hodgepodge of queues, event stores and cron jobs? Durable Execution to the Rescue.](https://www.wearedevelopers.com/videos/744-is-your-backend-a-hodgepodge-of-queues-event-stores-and-cron-jobs-durable-execution-to-the-rescue) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms)