> Markdown version of [/jobs/ext/3571235-information-security-analyst-senior-rmf](https://www.wearedevelopers.com/jobs/ext/3571235-information-security-analyst-senior-rmf). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst-Senior (RMF) - **Company:** CACI International Inc. - **Location:** Cumberland County, NC, United States - **Experience:** Expert - **Salary:** $71,500.0 - $150,200.0 - **Contract:** Permanent contract - **Skills:** Systems Engineering, Cyber Security, Information Systems, Computer Programming, Server Administration, PL-SQL, Software Vulnerability Management, Automated Information System (AIS), Information Security Management System, Software Security, Information Technology, Database Tools and Utilities, Plan of Action and Milestones, Vulnerability Analysis - **Published:** October 3, 2026 - **Apply:** https://www.dice.com/job-detail/483948f1-f358-4c43-9637-a2980546e5e9 ## About the Role * A DOD Top Secret Security Clearance with DCID 6/4 eligibility * Current DOD 8570 IAT Level II certification * 4-6 years' experience in Cybersecurity (Information Assurance) compliance and vulnerability testing * Experience with COTS/GOTS/DOD CS Tools for security analysis and network scanning * Vulnerability tool administration and execution * Proficient with MS Office products * Exceptional organizational, presentation and communication skills (verbal and written) * Excellent listening and comprehension skills. Ability to extract and clearly articulate key concepts and requirements from verbal discussions, documentation and transcripts * Familiar with handling and marking of classified information * Familiarity with Security policies governing the storage of, access to, and transmittal, of classified information * Must be self-starter, self-managed, responsive and dedicated, with a proven track record of exceptional performance, high productivity and meeting deadlines * Must have customer service and team player skills * Must maintain high levels of initiative and think outside the box * Able to develop innovative methods to solve challenging problems with available manpower and tools * Flexible, able to maintain a positive attitude in a fast-paced constantly changing environment * Ability to work cooperatively and proactively with personnel at various levels within the organization Desired: * Military background and experience with SOF * Application security * Software programming experience * Current DOD 8570 IAT III certification * B.S. or M.S. in Computer Science, Information Security, Mathematics, or IT related field ## Description CACI has an exciting job opportunity for a Cyber Security Control Assessor at an exciting client located at Ft. Liberty, NC. The Opportunity: Manages, maintains and reviews Certifications and Accreditation documents for supported Automated Information Systems to ensure compliance with DoD and Intelligence Community Risk Management Framework (RMF) standards. Maintains comprehensive knowledge of DoD and other associated directives that govern DoD RMF and Intelligence Directive 503. Conducts security reviews, scans, evaluations and risk assessments to identify security risks and impact of potential Cyber vulnerabilities. Evaluates security procedures to implement and ensures potential users are aware of and comply with command Cyber Security policies and procedures to generate and maintain required documentation for supported information systems to include the System Security Plan, the Risk Assessment, the Plan of Action and Milestones and the Authority to Operation (Operate) or to Connect., * Ability to identify systemic security issues based on the analysis of vulnerability and configuration data * Reconcile customer requirements within acceptable risks determined by DOD policies, command policies and generally accepted practices. Make recommendations for tools and processes to improve CS initiatives. * Knowledge of Risk Management Framework (RMF) requirements * Respond to daily inquiries via email, phone, or in-person from organization members * Demonstrate appropriate discretion when handling classified/sensitive information * Skill in conducting vulnerability scans and recognizing vulnerabilities in security systems * Knowledge of new and emerging information technology (IT) and information security technologies * Knowledge of system lifecycle management principles, including software security and usability * Conduct continuous analysis to identify network and system vulnerabilities * Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code) * Prepare audit reports that identify technical and procedural findings, and provide recommended remediation strategies/solutions * Knowledge of server administration and systems engineering theories, concepts, and methods * Administer, operate, and maintain multiple vulnerability management servers/applications and RMF web database tool ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)