> Markdown version of [/jobs/ext/3563929-descriptionrmf-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/3563929-descriptionrmf-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DescriptionRMF Cyber Security Analyst - **Company:** Nationwide IT Services, Inc - **Location:** Stafford, VA, United States - **Salary:** $100,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, Communications Protocols, Cyber Security, Information Systems, Firmware, Information Security Management, Microsoft Office, Software Security, Information Technology, Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** October 3, 2026 - **Apply:** https://www.thejobnetwork.com/job/9d417054-ab10-44dd-8023-575403b661eb/rmf-cyber-security-analyst ## About the Role * Secret clearance * Bachelor's degree in information technology, Information Systems Management, Cyber Security, or some other related field, or additional years of experience in lieu of a degree * A minimum of 5 years of hands-on technical Cyber Security Experience and knowledge with DISA Security Technical Information Guides, DoD A&A Process, NIST SP 800-53, IA Technical Framework, and applicable DoD Cyber Security / Risk Management policies (must have DoD or eMASS experience) * A minimum of (1) year of knowledge of current security tools, hardware/software security implementation, communication protocols, and Microsoft Office suite * Must meet DoD 8570-M/8140-M IAT Level II ## Description Nationwide IT Services, NIS, seeks a Cybersecurity Analyst who will: * Provide support for a program, an organization, system, or an enclave. * Provide support for proposing, coordinating, implementing, and enforcing information systems or enclave cybersecurity policies, standards, and methodologies. * Maintain operational security posture for an information system, program, or enclave to ensure cybersecurity standards and procedures are established and followed. * Perform day-to-day security operations of the system or enclave. * Perform IT security control assessments. * Provide configuration management (CM) for information system security software, hardware, and firmware; manage changes to the system and assess the security impact of those changes. * Prepare and review documentation to include Systems Security Plans (SSPs) and Security Assessment & Authorization (SA&A) packages in accordance with DoD Risk Management Framework (RMF) procedures. Duties: * Interface with Project/Program Managers, Subject Matter Experts (SME), and Information System Security Managers (ISSM) on Major Application / General Enclave issues and updates. * Drive the 7 steps of the RMF lifecycle (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor). * Create and maintain security packages in eMASS. * Review vulnerability scan results (using tools like ACAS or Nessus) and coordinate remediation. * Act as a bridge between technical engineers, Information System Security Officers (ISSOs), and executive leadership. * Track and report on Plan of Action and Milestone (POA&M) items; RMF Status, Annual Assessments, Authority to Operate (ATO) and Continuous Monitoring actions. * Responsible for documentation compliance and review to ensure programs receive ATOs for multiple systems. * Prepare briefs and A&A documents for approval in support of RMF reporting and policy development. * Perform ISSO Type duties as defined in DoD 8510 & 8500. * Provide risk mitigation strategies. * Perform quality checks on POA&Ms, risk assessments, and documentation. Conduct security control and risk assessments to support authorizations. * Review existing documentation bi-annually for accuracy and relevance to current DoD and DCSA mandates. * Assist with research on cybersecurity items of interest. * Perform other duties as related to risk management, communication, and assessments. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Physical AI: 5 Things You Can Build That Aren't Another Chatbot](https://www.wearedevelopers.com/videos/100423-physical-ai-5-things-you-can-build-that-aren-t-another-chatbot) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)