> Markdown version of [/jobs/ext/2293623-rmf-and-poam-analyst](https://www.wearedevelopers.com/jobs/ext/2293623-rmf-and-poam-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF and POAM Analyst - **Company:** Guidehouse Inc. - **Location:** Tysons, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Agile Methodology, Cloud Computing, CompTIA Security+, Cyber Security, Data Integrity, Data Security, Internet Security, Scrum Methodology, Cloud Services, SARS Software Products, Data Ingestion, RSA Archer Platform, Servicenow - **Published:** August 29, 2026 - **Apply:** https://www.careerbuilder.com/job-details/rmf-and-poam-analyst-tysons-corner-va--0bbdd880-4911-4ff7-a6c4-c1e69b1435ec ## About the Role * An ACTIVE and CURRENT Federal or DoD Public Trust * Bachelor's Degree AND Five (5) years of relevant cybersecurity experience, OR a Master's Degree AND Three (3) years of relevant experience * Experience as an RMF or POAM Analyst (current or past) * Excellent verbal and written communication skills, specifically in report writing * Ability to commute to client office as needed per week, * Security+, CAP, or equivalent certification, and strong working knowledge of NIST SP 800 37, 800 53, FISMA, and FedRAMP. * Familiarity with ServiceNow, GRC platforms, or audit tracking tools. * Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department of Homeland Security related to GRC implementations * Demonstrated experience in the areas of external client-facing management and/or consulting for large firms, Agile Programming Methodologies, Analysis Skills, Backlog Prioritization, Banking Services, Childcare, Cloud Computing, Communication Skills, CompTIA Security+, Consulting, Corporate Funding, Customer Relations, Data Quality, Dental Insurance, Documentation, FISMA - Federal Information Security Management Act, Federal Government, Flexible Spending Accounts, Homeland Security, Information/Data Security (InfoSec), Internet Security, Legal, Machine Tool, Maintain Compliance, Management Consulting, Prescription Drugs, Presentation/Verbal Skills, Recruiting/Staffing Agency, Regulations, Reporting Dashboards, Reporting Skills, Risk, ServiceNow, Sprint Planning, Tuition Reimbursement, U.S. National Institute of Standards and Technology (NIST), United States Department of Defense (DoD), Vision Plan, Willing to Travel, Writing Skills ## Description * Lead and/or support the developmentof RMF and A&A documentation including SSPs, control implementation matrices, SARs, POA&Ms, and risk acceptance materials. * Support authorization of on premise and cloud services leveraging FedRAMP packages, considering agency specific control requirements, and support 3PAO readiness assessments and SAR development for cloud platforms. * Interpret and operationalize FISMA, NIST RMF, FedRAMP, and OSCAL standards to guide application enhancements, evidence automation, and RMF workflow modernization across a GRC platform. * Ensuring consistency and compliance across multi-tenant GRC environments, helping Components and customer agencies implement security controls, maintain accurate documentation, and sustain reliable continuous monitoring. * Collaborating across Agile teams to embed RMF discipline, support backlog refinement, and validate that modernization activities remain compliant with Federal requirements. * Coordinate A&A activities and requirements with System Owners, ISSOs, IAMs, and third-party assessors, reducing manual burden for ISSOs and system owners by shaping automated workflows, improving evidence pathways, and strengthening data integrity used for scoring, dashboards, and compliance reporting. * Providing compliance and RMF subject matter guidance throughout sprint cycles, planning, testing activities, and release readiness processes, ensuring enhancements align with RMF control requirements and governance expectations. * Supporting continuous authorization (cATO) goals through integration of automated control validation, vulnerability data ingestion, security tooling alignment, and machine-readable artifacts (OSCAL). ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [SRE Methods In an Agency Environment](https://www.wearedevelopers.com/videos/348-sre-methods-in-an-agency-environment) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)