> Markdown version of [/jobs/ext/465223-rmf-cybersecurity-analyst-15-43](https://www.wearedevelopers.com/jobs/ext/465223-rmf-cybersecurity-analyst-15-43). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF Cybersecurity Analyst (15.43) - **Company:** OCT Consulting LLC - **Location:** Hyattsville, MD, United States (Remote available) - **Experience:** Experienced - **Salary:** $90,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Access Network, Cyber Security, Federal Information Processing Standards (FIPS), Information Systems Security Architecture Professional, Software Vulnerability Management, Information Technology - **Published:** June 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ea58feba6c7e6d87 ## About the Role Do you have experience in Technical writing within technology?, Do you have a Bachelor's degree?, * Must be a U.S. Citizen. * Minimum of 3-5 years of experience in federal information security, RMF implementation, or cybersecurity compliance. * Demonstrated experience with NIST SP 800-37, 800-30, 800-53/53A, 800-60, and FIPS 199/200. * Experience supporting FISMA compliance and reporting activities for a federal civilian agency. * Experience developing, reviewing, and maintaining SA&A documentation artifacts (SSPs, RARs, POA&Ms, Contingency Plans). * Proficiency with Governance, Risk, and Compliance (GRC) platforms such as Archer or comparable tools. * Strong technical writing skills sufficient to independently produce clear, accurate, and professionally formatted security and compliance documentation. * Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field (or equivalent work experience). * Ability to obtain a Public Trust (Moderate Risk - Level 5 or higher) background investigation; an HSPD-12/PIV card will be required for facility and network access. * Work will be performed primarily at the agency facility in Hyattsville, MD, with authorized telework on a situational basis. Must be able to commute to the Hyattsville, MD location. Preferred Qualifications: * Certified Information Systems Security Professional (CISSP), Certified Authorization Professional (CAP), Certified Information Security Manager (CISM), or equivalent certification. * Experience supporting HHS or other Federal civilian agency environments. * Experience with CIPSEA, Privacy Act compliance, and handling of sensitive health statistics data. * Familiarity with FedRAMP authorization activities and cloud migration security governance. * Experience with continuous monitoring programs and vulnerability remediation in federal environments. ## Description * Assist the ISSO/SSPO in interfacing with federal staff, contractors, and business partners to execute information security aspects of the agency's CIPSEA obligations, IT modernization, and cloud migration efforts. * Support Security Assessment and Authorization (SA&A) activities including agency-hosted, contractor-hosted, cloud-hosted, and FedRAMP SA&As; assist with interpretation of regulations and policy guidance. * Develop, track, and update Plans of Action and Milestones (POA&Ms) for identified vulnerabilities and risks; report remediation status monthly. * Prepare and maintain System Security Plans (SSPs) in accordance with NIST SP 800-18 and NIST SP 800-53. * Conduct and document Risk Assessment Reports (RARs) consistent with NIST SP 800-30 and applicable agency policies. * Support FISMA reporting to the Department of Homeland Security and OMB; prepare gap reports of agency practices against evolving federal, HHS, and agency requirements. * Assist with Privacy Threshold Analyses (PTAs) and Privacy Impact Assessments (PIAs) in accordance with HHS policy and OMB M-03-22. * Prepare weekly project management/status reports and monthly RMF status reports for the COR and Program POC. * Develop and maintain reusable templates, standard operating procedures (SOPs), and process documentation (e.g., SSP templates, risk assessment templates, process flow diagrams). * Coordinate with agency Security, Business, and Technical Stewards; provide stakeholder advisory support and training as required. * Support EPLC security reviews, IT acquisition security reviews, and security governance coordination activities. * Assist in applying CIPSEA oversight in coordination with the agency Confidentiality Officer. * Maintain compliance with all agency security training requirements including annual Security Awareness Training (SAT) and role-based training (RBT). ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)