Senior RMF Security Analyst

Assurit Consulting Group, LLC
Beltsville, MD, United States
6 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Configuration Management Cyber Security Information Systems Federal Information Processing Standards (FIPS) Information Security Management System

Job description

Assurit is seeking a senior, hands-on RMF Security Analyst to support federal information systems through RMF Steps 1-3. The analyst will work closely with government cybersecurity stakeholders to develop and maintain the security documentation required to achieve, maintain, and renew system Authorities to Operate (ATOs)., RMF Step 1 - Categorize the System

  • Collect and update general system information.
  • Create and maintain system records in CSAM, including system identification information, system descriptions, and technical narratives.
  • Prepare and update Privacy Threshold Analyses (PTAs) and Privacy Impact Assessments (PIAs).
  • Perform and update FIPS 199 security categorizations.
  • Perform and update E-Authentication Risk Assessments.

RMF Step 2 - Select Security Controls

  • Identify common and inherited security controls, including controls inherited from FedRAMP-authorized services.
  • Develop and update compliance descriptions for applicable NIST SP 800-53 controls, including tailoring decisions.
  • Develop compensating controls when required.
  • Develop and update Contingency Plans and related testing and training documentation.
  • Develop and update System of Records Notices, Configuration Management Plans, Incident Response Plans, Business Impact Assessments, and Interconnection Security Agreements.

RMF Step 3 - Implement and Support Review

  • Finalize System Security Plan compliance descriptions.
  • Finalize Contingency Plans, Configuration Management Plans, Incident Response Plans, and Disaster Recovery Plans, as required.
  • Assist government stakeholders in addressing findings and updating documentation during concurrence and authorization reviews.
  • Coordinate with technical and business stakeholders to ensure RMF documentation is accurate, complete, consistent, and ready for authorization review.

Requirements

The ideal candidate will have extensive federal A&A experience and the ability to independently develop high-quality RMF documentation across multiple information systems., * U.S. citizenship.

  • Bachelor’s degree and at least eight years of relevant cybersecurity experience.
  • Experience completing all aspects of the NIST Risk Management Framework for federal information systems.
  • Hands-on experience developing and maintaining federal A&A and authorization packages.
  • Hands-on experience using the Cybersecurity Assessment and Management System (CSAM).
  • Experience supporting ATOs involving FedRAMP-authorized products, solutions, or platforms.
  • Experience developing SSPs, contingency plans, incident response plans, configuration management plans, business impact assessments, interconnection security agreements, and privacy documentation.
  • Strong technical-writing skills and the ability to produce accurate, complete, and Section 508-compliant documentation.
  • Ability to appropriately handle Controlled Unclassified Information and other sensitive government information.
  • Ability to successfully obtain and maintain the required federal background investigation, suitability determination, facility access, and PIV credential.
  • Working knowledge of:
  • NIST Risk Management Framework
  • FIPS PUB 199, * Prior federal civilian-agency A&A experience.
  • Prior USDA cybersecurity or RMF experience is a plus.
  • Experience with the USDA Six-Step RMF Process or USDA CSAM instance is a strong plus.
  • Experience independently supporting RMF activities across multiple federal information systems.
  • Active certification such as CISSP, CGRC (formerly CAP), or CISM.
  • Current or prior federal Public Trust investigation.

About the company

Assurit is an award winning, certified small business headquartered in Fairfax, VA. We offer a highly competitive compensation and benefits package inclusive of medical and dental coverage, as well as paid time off.

Founded in 2013, Assurit has become a trusted provider of cybersecurity expertise to customers across federal, state and local governments, as well as the commercial sector. We are an employee-centric organization that focuses on the growth and development of our greatest asset - our people. We believe that if our Team is trained and educated, we will always be able to deliver our promise of customer success. If you enjoy work environments focused on continuous learning and growth, Assurit will be a great fit for you.

Whether you saw a specific job opening of ours or are simply interested in learning more about building your career at Assurit, feel free submit your resume. Based on your request, the appropriate individual within our organization will get back to you within 2 business days.

Assurit is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:07 min

Technical components of internal developer platforms

Christian Strack · LIVE

1:55 min

Executing secure deployments with verified compliance and data residency

Alex Laubscher Alex Laubscher · World Congress 2025

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all