> Markdown version of [/jobs/ext/3563985-rmf-cyber-security-analyst-senior](https://www.wearedevelopers.com/jobs/ext/3563985-rmf-cyber-security-analyst-senior). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF Cyber Security Analyst Senior - **Company:** Science Applications International Corporation - **Location:** Quantico, VA, United States - **Experience:** Expert - **Salary:** $120,001.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, Communications Protocols, Cyber Security, Information Systems, Firmware, Information Security Management, Microsoft Office, Software Security, SC Clearance, Information Technology, Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** October 3, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3417342408&tx=JT10698UHD&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Secret clearance. * Bachelor's degree in information technology, Information Systems Management, Cyber Security, or some other related field. * Five (5) or more years of hands-on technical Cyber Security Experience. Additional years of experience may be considered in lieu of a degree. * Knowledge with DISA Security Technical Information Guides, DoD A&A Process, NIST SP800-53, IA Technical Framework, and applicable DoD Cyber Security / Risk Management policies (must have DoD or eMASS experience). * At least one (1) year of the knowledge of current security tools, hardware/software security implementation, communication protocols, and Microsoft Office suite. * Must meet DoD 8570-M/8140-M IAT Level II. ## Description The RMF Cyber Security Analyst Senior will provide support for a program, an organization, system, or an enclave; provides support for proposing, coordinating, implementing, and enforcing information systems or enclave cybersecurity policies, standards, and methodologies; maintains operational security posture for an information system, program, or enclave to ensure cybersecurity standards, and procedures are established and followed; performs day-to-day security operations of the system or enclave; perform IT security control assessments; provide configuration management (CM) for information system security software, hardware, and firmware; manage changes to system and assess the security impact of those changes; prepare and review documentation to include Systems Security Plans (SSPs) and Security Assessment & Authorization (SA&A) packages in accordance with DoD Risk Management Framework (RMF) procedures., * Interface with Project/Program Managers, Subject Matter Experts (SME) and Information System Security Managers (ISSM) on Major Application / General Enclave issues and updates. * Drive the 7 steps of the RMF lifecycle (Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor). * Create and maintain security packages in eMASS. * Review vulnerability scan results (using tools like ACAS or Nessus) and coordinate remediation. * Act as a bridge between technical engineers, Information System Security Officers (ISSOs), and executive leadership. * Track and report on Plan of Action and Milestone (POA&M) items; RMF Status, Annual Assessments, Authority to Operate (ATO) and Continuous Monitoring actions. * Responsible for documentation compliance and review to ensure programs receive ATOs for multiple systems. * Prepare briefs and A&A documents for approval in support of RMF reporting and policy development. * Perform ISSO Type duties as defined in DoD 8510 & 8500. * Provide risk mitigation strategies. * Perform quality checks on POA&Ms, risk assessments, and documentation. * Conduct security control and risk assessments to support authorizations. * Review existing documentation bi-annually for accuracy and relevance to current DoD and DCSA mandates. * Assist with research on cybersecurity items of interest. * Perform other duties as related to risk management, communication, and assessments. ## Related Videos - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Physical AI: 5 Things You Can Build That Aren't Another Chatbot](https://www.wearedevelopers.com/videos/100423-physical-ai-5-things-you-can-build-that-aren-t-another-chatbot) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)