> Markdown version of [/jobs/ext/2721716-rmf-cybersecurity-analyst-ii-505767](https://www.wearedevelopers.com/jobs/ext/2721716-rmf-cybersecurity-analyst-ii-505767). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF Cybersecurity Analyst II - 505767 - **Company:** DNI Delaware Nation Industries - **Location:** Wright-Patterson Air Force Base, OH, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Microsoft Project, Microsoft Visio, Software Vulnerability Management, Cyber Warfare, Plan of Action and Milestones - **Published:** September 4, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9143002/rmf-cybersecurity-analyst-ii-505767 ## About the Role * Bachelor's degree or equivalent work experience * 3-5 years of relevant experience in cybersecurity, RMF, cyber compliance, incident response support, vulnerability management, or related cyber operations * Must possess an active DoD 8570.01-M IAT Level II certification, such as Security+ * Familiarity with NIST SP 800-37 and NIST SP 800-53 Revision 5 * Experience maintaining cybersecurity documentation, supporting artifacts, and records in eMASS or similar compliance environments * Familiarity with ACAS, Trellix ePO, STIG compliance, and cyber-related ticket workflows * Ability to work effectively with technical staff, compliance personnel, and stakeholders in a regulated environment * Must possess or be able to obtain any required security clearance or access required for the position Preferred Qualifications * Experience supporting RMF packages, POA&M updates, security control documentation, or audit follow-up activities * Experience supporting laboratory, research, or other regulated IT environments * Familiarity with incident documentation, vulnerability tracking, forensics concepts, or Department of War cybersecurity compliance processes * Experience maintaining hardware/software inventories, system lists, topology documentation, or proficiency with Microsoft Visio or Microsoft Project ## Description The RMF Cybersecurity Analyst II supports Risk Management Framework (RMF) compliance activities, cyber compliance processes, and incident response efforts for networked systems and applications used by the organization. This role is responsible for maintaining RMF documentation and supporting records, supporting audit and review activities, tracking cyber-related workflows, and assisting with software and license compliance activities. The ideal candidate is an experienced cyber professional with knowledge of RMF processes, cybersecurity documentation, and compliance tools who can work effectively with technical staff, compliance personnel, and stakeholders in a regulated environment., * Support RMF compliance activities, including review of policy documents, package materials, supporting records, and maintenance of RMF artifacts and eMASS records * Support RMF package reviews, laboratory audit activities, and follow-up documentation requirements * Review, monitor, and track cyber-related tickets, incident response actions, and associated workflows * Support cyber compliance activities related to software and license records, unit-level audits, STIG remediation, and documentation updates * Work with technical staff, compliance personnel, and stakeholders to collect required information, identify documentation gaps, and support follow-up actions ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)