> Markdown version of [/jobs/ext/3048633-data-scientist-rmf-analyst](https://www.wearedevelopers.com/jobs/ext/3048633-data-scientist-rmf-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Data Scientist/RMF Analyst - **Company:** Tamayo Federal Solutions LLC - **Location:** United States - **Experience:** Expert - **Salary:** $100,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Data Analysis, Cyber Security, Intrusion Detection Systems, Microsoft OneNote, Team Foundation Server, Microsoft PowerPoint, Data Driven Tests, Technical Data Management Systems, Office365, Firewalls (Computer Science), Information Technology, Process Control Systems, Data Analytics, Vulnerability Analysis - **Published:** September 24, 2026 - **Apply:** https://www.thejobnetwork.com/job/data-scientistrmf-analyst-509977600 ## About the Role · Integrity Always · Accountability in Action · Mission-Focused Leadership · Continuous Improvement Requirements Required Qualifications · Bachelor's degree in computer science, information assurance, cybersecurity, engineering, or related technical field. · 7-10+ years of related or applicable professional experience executing RMF lifecycle activities, including control selection, implementation, assessment preparation, and A&A support. · Experience managing eMASS packages, artifacts, and workflows. · Strong understanding of NIST RMF, CNSSI 1253, FISMA, and Department of Navy/Department of Defense-aligned cybersecurity directives. · Experience reviewing vulnerability assessments, cyber test plans, audits, and security hardening artifacts for complex systems or networks. · Ability to translate engineering diagrams, Technical Data Packages, and technical documentation into cybersecurity findings and recommendations. · Experience conducting configuration and hardening reviews using STIGs/SRGs for networks, applications, or industrial control systems. · Ability to work independently in a senior-level environment with minimal oversight and manage multiple concurrent technical tasks. · Active DOD Security Clearance. · High proficiency in Microsoft 365 applications, including Word, Excel, PowerPoint, Teams, and OneNote. · Ability to interface efficiently with team members and technical leads. Desired Qualifications · Experience shaping cybersecurity policy, risk processes, and data-driven decision frameworks that enhance cyber survivability across maritime systems. · Experience developing, revising, and maintaining cybersecurity policies, SOPs, and business rules aligned with NIST RMF, CNSSI 1253, FISMA, and Department of Navy/Department of Defense directives. · Experience supporting ATO/ATC readiness through continuous compliance, remediation tracking, and monitoring of platform authorization requirements. · Experience reviewing system drawings, modernization packages, Technical Data Packages, and lifecycle documentation to identify cyber risks and propose mitigations. · Experience assessing security boundaries, countermeasures, and protective technologies such as firewalls, IDS/IPS, endpoint protection, and encryption. · Experience coordinating planning inputs for program funding, cyber hardening initiatives, and integration activities across CVN program stakeholders. ## Description TFS is seeking a Data Scientist/RMF Analyst to help strengthen the cybersecurity posture and technical resilience of the Navy's most advanced aircraft carrier platforms. This role performs data-driven analysis, executes Risk Management Framework activities, and supports compliance with Department of Defense cybersecurity requirements while contributing to the protection and modernization of critical CVN systems. What You'll Do In this role, you will support cybersecurity readiness and modernization for DPAE Aircraft Carrier platforms through comprehensive RMF, eMASS, and risk management activities. You will serve as a technical advisor to help ensure CVN systems, networks, and Hull, Mechanical, and Electrical control systems meet Department of Navy and Department of Defense cybersecurity requirements; review engineering, security, and data artifacts; modernize cybersecurity infrastructure and RMF processes; conduct vulnerability and hardening reviews; support ATO/ATC readiness; and develop analytical briefings that communicate program status, risks, and recommended actions. What Success Looks Like in This Role Success in this position means improving cyber survivability across critical maritime systems through disciplined RMF execution, strong technical risk management, accurate eMASS package support, and actionable data analysis. The successful candidate will help integrate cybersecurity considerations into engineering plans, lifecycle documentation, platform processes, cybersecurity policies, and modernization efforts while ensuring confidentiality, integrity, and availability for CVN HM&E control systems, critical shipboard networks, and associated enclaves. ## Related Videos - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Innovation Formula: Fast Prototyping, Data Analysis, and Real User Insights](https://www.wearedevelopers.com/videos/1421-the-innovation-formula-fast-prototyping-data-analysis-and-real-user-insights) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)