> Markdown version of [/jobs/ext/3017911-senior-rmf-security-analyst](https://www.wearedevelopers.com/jobs/ext/3017911-senior-rmf-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior RMF Security Analyst - **Company:** Assurit Consulting Group, LLC - **Location:** Beltsville, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Systems, Federal Information Processing Standards (FIPS), Information Security Management System - **Published:** September 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f73c72434e990e05 ## About the Role The ideal candidate will have extensive federal A&A experience and the ability to independently develop high-quality RMF documentation across multiple information systems., * U.S. citizenship. * Bachelor's degree and at least eight years of relevant cybersecurity experience. * Experience completing all aspects of the NIST Risk Management Framework for federal information systems. * Hands-on experience developing and maintaining federal A&A and authorization packages. * Hands-on experience using the Cybersecurity Assessment and Management System (CSAM). * Experience supporting ATOs involving FedRAMP-authorized products, solutions, or platforms. * Experience developing SSPs, contingency plans, incident response plans, configuration management plans, business impact assessments, interconnection security agreements, and privacy documentation. * Strong technical-writing skills and the ability to produce accurate, complete, and Section 508-compliant documentation. * Ability to appropriately handle Controlled Unclassified Information and other sensitive government information. * Ability to successfully obtain and maintain the required federal background investigation, suitability determination, facility access, and PIV credential. * Working knowledge of: + NIST Risk Management Framework + FIPS PUB 199, * Prior federal civilian-agency A&A experience. * Prior USDA cybersecurity or RMF experience is a plus. * Experience with the USDA Six-Step RMF Process or USDA CSAM instance is a strong plus. * Experience independently supporting RMF activities across multiple federal information systems. * Active certification such as CISSP, CGRC (formerly CAP), or CISM. * Current or prior federal Public Trust investigation. ## Description Assurit is seeking a senior, hands-on RMF Security Analyst to support federal information systems through RMF Steps 1-3. The analyst will work closely with government cybersecurity stakeholders to develop and maintain the security documentation required to achieve, maintain, and renew system Authorities to Operate (ATOs)., RMF Step 1 - Categorize the System * Collect and update general system information. * Create and maintain system records in CSAM, including system identification information, system descriptions, and technical narratives. * Prepare and update Privacy Threshold Analyses (PTAs) and Privacy Impact Assessments (PIAs). * Perform and update FIPS 199 security categorizations. * Perform and update E-Authentication Risk Assessments. RMF Step 2 - Select Security Controls * Identify common and inherited security controls, including controls inherited from FedRAMP-authorized services. * Develop and update compliance descriptions for applicable NIST SP 800-53 controls, including tailoring decisions. * Develop compensating controls when required. * Develop and update Contingency Plans and related testing and training documentation. * Develop and update System of Records Notices, Configuration Management Plans, Incident Response Plans, Business Impact Assessments, and Interconnection Security Agreements. RMF Step 3 - Implement and Support Review * Finalize System Security Plan compliance descriptions. * Finalize Contingency Plans, Configuration Management Plans, Incident Response Plans, and Disaster Recovery Plans, as required. * Assist government stakeholders in addressing findings and updating documentation during concurrence and authorization reviews. * Coordinate with technical and business stakeholders to ensure RMF documentation is accurate, complete, consistent, and ready for authorization review. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)