> Markdown version of [/jobs/ext/601832-rmf-cyber-security-analyst-306210](https://www.wearedevelopers.com/jobs/ext/601832-rmf-cyber-security-analyst-306210). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF Cyber Security Analyst - 306210 - **Company:** DNI Delaware Nation Industries - **Location:** Virginia Beach, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Computer Networks, Federal Information Processing Standards (FIPS), Identity and Access Management, Information Security Management, Microsoft Project, Microsoft Visio, Software Vulnerability Management, Computer Networking Systems, Information Security Management System, Navsea, Vulnerability Analysis - **Published:** June 19, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8985153/rmf-cyber-security-analyst-306210 ## About the Role * DoD Top Secret Security Clearance * 5+ Years of Experience in Cyber Security * Cyber Security Workforce level IAM II/III CASP,CISM, or CISSP required * Bachelor Degree or Equivalent Work Experience * Familiarity with NIST IT Security Special Publication (SP) 800 Series with emphasis on NIST SP 800-37 and NIST SP 800-53 rev 4/5 * Forensics analysis familiarity * Experienced STIG reviewer * Microsoft Visio and Microsoft Project user Desired: * Navy Qualified Validator (NQV) Level II * Familiarity with ACAS, RedSeal, and Carbon Black * Familiarity with the Vulnerability Remediation Asset Manager (VRAM) web tool * Familiarity with the Continuous Monitoring and Risk Scoring (CMRS) web tool ## Description Delaware Nation Industries is supporting the Naval Surface Warfare Center Dahlgren Division Dam Neck Activity (NSWCDD DNA). We are providing enterprise management and technical support of the Naval Surface Warfare Center Dahlgren Division Dam Neck Activity (NSWC DD DNA) by providing assistance in policy, procedures, seat refresh, engineering/technical solutions, ordering to Next Generation Enterprise Network (NGEN) and the Naval Networking Environment (NNE) strategy., Job Summary: The RMF Analyst will assist in developing RMF accreditation packages and assist in maintaining Authorization to Operate (ATO) certifications for networked systems and applications used by the organization. The RMF Analyst will assist in the development of information system documentation and the provision of a designated set of common controls for the authorization package, including the executive summary, system security plan, privacy plan, security control assessment, privacy control assessment, and any relevant plans of action and milestones. This system certification documentation must comply with DoD and Civilian Agency policy focused on NIST 800-37, NIST 800-53 rev 4., * Monitor and assess existing Information Security Management and Security Technical Architecture, regulations, and controls (FIPS, NIST, DISN Connection Process Guide(CPG), Navy RMF Process Guide (RPG), Navy Testing Guidance) * Assess proposed Information Security Management and Security Technical Architecture, regulations, and controls (FIPS, NIST, DISN CPG, Navy RPG, Navy Testing Guidance) * Maintain regular meetings/notes and informal dialog with RDT&E CORE/LAB managers and ISSOs to keep them abreast of upcoming Information System Security Manager (ISSM) requirements and to gather specifics on their capability and core support requirements and trends * Maintain records in the Enterprise Mission Assurance Support Service (eMASS) * Evaluating technical testing from Assured Compliance Assessment Solution (ACAS) scans, Evaluate STIG, eMASSter), and Security Technical Implementation Guide Viewer tool using FMATS or other NAVSEA or DoD-approved toolset. * Monitor security access, passwords, badges, log-ins, to keep a site or system safe * Use firewalls and information security standards to keep their organization secure * Perform security assessments, vulnerability testing and risk analysis * Conduct security audits internal and external * Identify the cause of security breaches ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)