> Markdown version of [/jobs/ext/2272726-rmf-cybersecurity-analyst-ts-sci-with-ci-poly](https://www.wearedevelopers.com/jobs/ext/2272726-rmf-cybersecurity-analyst-ts-sci-with-ci-poly). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF Cybersecurity Analyst - TS/SCI with CI Poly - **Company:** ENS Solutions, LLC - **Location:** Sterling, VA, United States - **Experience:** Expert - **Salary:** $107,900.0 - $179,400.0 - **Contract:** Permanent contract - **Skills:** Xacta, Systems Engineering, Cyber Security, Information Security Management - **Published:** August 27, 2026 - **Apply:** https://www.careerjet.com/jobad/us91483be12470aae80e25da2d1360ac2f ## About the Role * High School and 10+ years of experience / Associate's Degree and 8+ years of experience/ Bachelors Degree and 6+ years of experience / Master's degree and 4+ years of experience / PHD and 2+ years of experience. * Minimum of 3-years IC (SCI) RMF Assessment and Authorization (A&A) experience and the ability to describe the differences between collateral and SCI authorization requirements as they apply to DoD and IC instructions and guidelines. * Ability to speak to the intent of all NIST 800-53 security controls. * Minimum 1-year hands on experience with the Xacta application. * Excellent oral and technical writing skills. * Ability to work both independently and as a member of a team * Must possess an Active Top Secret/SCI Clearance with the ability to obtain a counter-intelligence polygraph. ## Description Our work depends on a Risk Management Framework Cybersecurity Analyst joining our team to support Government activities. As a RMF Cybersecurity Analyst supporting the Federal Government and the Intelligence Community (IC), you will be entrusted with ensuring our IT engineering solutions meet the highest security standards, that they adhere to all applicable standards, guidelines, and mandates; and that all appropriate documentation necessary to make up a Body of Evidence (BoE) is provided to the Chief Information Security Officer (CISO), and Authorizing Official (AO) to successfully justify the issuing an Authority to Operate (ATO). * Acting as an appointed Information System Security Officer (ISSO) for IC cyber systems being developed by the engineering team. * Reporting, documenting, and briefing the status of systems under development while assuring their successful and timely progression through the DIA Risk Management Framework (RMF) to the satisfaction of the appointed Information System Security Manager (ISSM), and/or senior govt leadership. * Providing clear justification describing the satisfaction of all applicable security control implementation as specified by the IC, AO, or NIST-800-53, rev 4 rev 5. * Authoring System Security Plans (SSP). * Authoring System Security Test Plans (SSTP). * Conducting self-assessments of all systems under development * Analyzing security controls and the impact changes would introduce to the environment. * Preparing for and assisting with formal risk assessments conducted by the AO's designated Security Control Assessors (SCA) while acting as a member of the security assessment test team. * Ensuring the remediation of any findings assigned to engineering as documented in the Security Assessment Report (SAR) and its Plan of Actions and Milestones (PO&AM). * Documenting and defending reasoning when waivers are sought, or non-standard remediation solutions are requested for specific security controls. * Assisting with the transition of systems granted an ATO to the Operations branch and the assignment of an operations ISSO. * Researching remediation options for vulnerabilities identified for systems under development or already in production under an ATO. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Model Based Systems Engineering in an Agile Product Development Process](https://www.wearedevelopers.com/videos/68-model-based-systems-engineering-in-an-agile-product-development-process) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Automated Driving - Why is it so hard to introduce](https://www.wearedevelopers.com/videos/628-automated-driving-why-is-it-so-hard-to-introduce) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)