RMF Cybersecurity Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
-
Manage the security authorization lifecycle for one or more information systems in accordance with Federal Risk Management Framework (RMF) requirements.
-
Coordinate activities required to obtain and maintain program office Authorization to Operate (ATO) approvals.
-
Assess and track implementation of NIST SP 800-53 security controls and associated compliance requirements.
-
Input and maintain all documentation in Enterprise Mission Assurance Support Service (eMASS)
Develop, review, update, and maintain authorization package documentation, including:
o System Security Plans (SSPs)
o Security Assessment Plans (SAPs)
o Security Assessment Reports (SARs)
o Plan of Action and Milestones (POA&Ms)
o Risk Assessments
o Continuous Monitoring documentation
o Security-related policies and procedures
o Security Technical Implementation Guides (STIGs)
o Assured Compliance Assessment Solution (ACAS)
o IV&V (Independent, Verification and Validation)
-
Manage POA&M activities by tracking findings, monitoring remediation progress, validating corrective actions, and supporting closure efforts.
-
Provide technical guidance and compliance recommendations to system owners, engineers, administrators, and security stakeholders to facilitate POA&M remediation and closure.
-
Coordinate with technical teams to gather evidence supporting security control implementation and compliance requirements.
-
Review vulnerability scan results, assessment findings, and security documentation to identify compliance gaps and areas requiring remediation.
-
Support continuous monitoring activities by tracking security posture, compliance status, and ongoing control effectiveness.
-
Participate in security assessments, audits, and compliance reviews conducted by internal and external stakeholders.
-
Assist in the development of risk mitigation strategies and recommendations for addressing identified security weaknesses.
-
Track authorization milestones, compliance deadlines, and remediation activities to ensure timely completion.
-
Communicate compliance status, risks, findings, and recommendations to both technical and non-technical stakeholders.
-
Support audits and reporting activities related to cybersecurity requirements and organizational security programs.
Requirements
Required:
-
U.S. Citizenship.
-
Active Secret Security Clearance, or the ability to obtain one.
-
Bachelor’s degree in Cybersecurity, Information Technology, Computer Sciences or a related field, or minimum 5 years of closely related experience working with Navy or DoD weapon systems, equipment, or programs.
-
Experience working with the NIST Risk Management Framework (RMF).
-
Understanding of cybersecurity principles, security controls, vulnerability management, and risk management concepts.
-
Experience supporting cybersecurity compliance, security authorization, risk management, or information security programs.
-
Experience in maintaining all documentation in the DoD Enterprise Mission Assurance Support Service (eMASS).
-
Subject matter expertise with NIST SP 800-53 security controls and cybersecurity compliance requirements.
-
Experience supporting the development, maintenance, or review of authorization package documentation, including SSPs, SARs, POA&Ms, and Risk Assessments.
-
Understanding of the Authorization to Operate (ATO) process and continuous monitoring requirements.
-
Experience tracking and managing POA&M findings through remediation and closure.
-
Ability to review technical security information and translate findings into compliance documentation and actionable recommendations.
-
Strong organizational skills with the ability to manage multiple systems, priorities, and compliance activities simultaneously.
-
Strong written and verbal communication skills, including the ability to develop and review formal security documentation.
-
Proficiency with MS Office applications, Excel, Word, and PowerPoint.
Desired :
-
Demonstrated experience providing cyber security support for complex military systems, preferably U.S. Navy Gun Weapon Systems.
-
Relative Certifications such as COMPTIA Security +, CISCO Certified Network Associate (CCNA).
Benefits & conditions
There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.
The proposed salary range for this position is: $86,600 - $181,800
About the company
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose - to ensure the safety of our nation.
An environment of trust.
CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
A focus on continuous growth.
Together, we will advance our nation’s most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks