RMF/Assessment & Authorization (A&A) Analyst
$115k - $135kSkyePoint Decisions
Job Description
Job Description
SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively – anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results.
This is a contingent position based on contract win.
SkyePoint Decisions is seeking a RMF/Assessment & Authorization (A&A) Analyst to support the implementation and maintenance of the Risk Management Framework (RMF) for information systems and applications. The Analyst works closely with System Owners, Information System Security Officers (ISSOs), cybersecurity teams, and Government stakeholders to ensure systems achieve and maintain Authorization to Operate (ATO) status in compliance with Federal cybersecurity requirements.
The position is responsible for developing and maintaining authorization documentation, supporting security assessments, tracking remediation activities, facilitating continuous monitoring activities, and contributing to ongoing cybersecurity compliance efforts.
This position is fully remote.
Responsibilities:
- Support development, maintenance, validation, and closure tracking of Plans of Action and Milestones (POA&Ms).
- Coordinate remediation tracking activities and validate corrective-action evidence supporting POA&M closure recommendations.
- Coordinate with Privacy Officials to support Privacy Threshold Analyses (PTAs), Privacy Impact Assessments (PIAs), and integration of privacy requirements into authorization activities.
- Support RMF activities across the system development lifecycle.
- Assist with system categorization, boundary definition, and security control implementation efforts.
- Maintain authorization documentation and supporting artifacts.
- Ensure security documentation remains current and compliant with applicable standards.
- Coordinate with stakeholders to collect and validate required security evidence.
- Develop, update, and maintain authorization package documentation.
- Assist in assembling complete authorization packages for review and approval.
- Support reauthorization and decommissioning activities.
- Participate in quality control reviews of security documentation.
- Work closely with ISSOs, System Owners, Security Engineers, Privacy Officials, and Program Management teams.
- Participate in authorization working groups and compliance meetings.
- Provide status updates and reporting to project leadership.
- Support cybersecurity awareness and compliance initiatives.
Required Qualifications:
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or related discipline.
- Minimum 5 years of cybersecurity, information assurance, or RMF experience supporting Federal information systems.
- Experience supporting Assessment & Authorization (A&A) efforts and RMF processes.
- Familiarity with: NIST Risk Management Framework (SP 800-37), NIST SP 800-53 Rev. 5, and FISMA
- Experience preparing or maintaining security documentation and authorization artifacts.
- Strong analytical, organizational, and communication skills.
- U.S. Citizenship required.
- Ability to obtain and maintain a Public Trust.
Preferred Qualifications:
- One or more of the following certifications:
- GCIH (GIAC Certified Incident Handler)
- ECIH (EC-Council Certified Incident Handler)
- Security+
- CEH
- CySA+
- GCFA
- CISSP
- OSCP
- Experience supporting HHS or other Federal civilian agencies.
- Experience using governance, risk, and compliance (GRC) platforms such as eMASS, Xacta, Archer, or ServiceNow GRC.
- Experience supporting cloud-based environments (AWS, Azure, or GCP).
- Knowledge of Zero Trust Architecture, CDM, and FedRAMP requirements.
- Experience working in a FISMA-compliant environment.
Compensation:
Salary Range: $115,000 - $135,000
The SkyePoint Decisions salary range for this position is a general guideline only. It represents an estimated range for this position and is just one piece of our total compensation package.
Salary at SkyePoint is determined by various factors, including but not limited to location, work schedule, the candidate's combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, market data and business considerations.
In addition to a competitive salary, SkyePoint offers benefits including a certification incentive program, PTO, floating federal holiday options, several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, Vision, ST/LT Disability, Life Insurance, and 401k matched.
What We Can Offer You:
- At SkyePoint, we go B.I.G. (beginning in GRATITUDE) by recognizing all we have and giving back to our employees, families, and communities. It instills a positive mindset that permeates all we do. By beginning in gratitude, SkyePoint can continue to spread living in gratitude each day.
- Great Benefits: Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, ST/LT Disability, Life Insurance, floating federal holiday options, and 401k matched
- Certificate Incentive Program: To promote professional development, we recognize and reward employees who obtain new certifications aligned with business needs.
- Flexible Work Environment
SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives.
SkyePoint Decisions is a participating E-Verify Employer.
U.S. Citizenship is required for most positions.
Equal Opportunity Employer/Veterans/Disabled.
CCPA Disclosure Notice Here
- ...SkyePoint Decisions is seeking an RMF/Assessment & Authorization (A&A) Analyst to support the implementation and maintenance of the RMF for information systems and applications. The Analyst works closely with System Owners, ISSOs, cybersecurity teams, and Government stakeholders...Suggested
- ...timeDescriptionClient Solution Architects (CSA) is currently seeking an Analyst I to support onsite in the Arlington, VA area.For... ..., including preparation of Risk Management Framework (RMF) Assessment and Authorization (A&A) packages and Enterprise Privacy Inspection Reports in...SuggestedContract workFor subcontractorWork at officeRemote work
- ...specialist to mitigate complex cybersecurity threats. This role requires collaboration with stakeholders to assess cybersecurity postures, leveraging eMASS and RMF for effective risk management. The ideal candidate will have a bachelor's degree and at least 3 years of...SuggestedRemote work
$187k - $253k
...Skills: Information Technology (IT) Security Assessments, IT Security Auditing, IT Security... ...activities. Coordinate with technical teams and authorizing agencies to anticipate and address... ...with Risk Management Framework (RMF) processes and associated security documentation...SuggestedContract workTemporary workImmediate startRemote workWorldwideFlexible hours$100k - $120k
...hire a Senior Information Security Risk Analyst to our team. If you enjoy problem... ...stakeholders. Performs technical risk assessments of third party suppliers' security and... ...current or future sponsorship for employment authorization. _____________________________________...SuggestedFull timeLocal area$125k - $140k
...cyber for 25 years! TDI is seeking a Junior Cloud RMF Analyst to support RMF and security execution for a... ...organize, and maintain evidence needed to support assessments, audits, Continuous Monitoring, and authorization activities. Support POA&M management with discipline...Permanent employmentFull timeContract work$65k - $80k
...The Information Assurance (IA) Analyst will be responsible for assessing the risks associated with EAB technology... ...(ISO 27001, NIST CSF, NIST RMF, FAIR, COBIT, NIST SP 800‑53, SSAE... ...growth opportunities Visa and Work Authorization: This opening is not eligible for visa...Immediate startFlexible hours$230.4k - $328.4k
...currently seeking an Operations Research Analyst SME. This position is a full-time... ...analyzing data from all test phases to assess Critical Operating Issues, systems under... ...statement herein is intended to imply any authorities to commit Battelle unless special written...Full timeTemporary workWork experience placementWork at officeLocal areaRemote workFlexible hours- ...: Top Secret ************CONTINGENT UPON AWARD*************** Duties & Responsibilities: Security Specialist II - Risk Assessment Specialist will manage the Position Description (PD) database containing all FCC positions. Security Specialist II identify PDs...Full timeFor contractorsLocal areaRelocation
- ...MD. Position Overview The Performance Analyst supports the analysis of user performance... ...requirements are comprehensively assessed, traceable, and clearly communicated to... ...requirements, including FISMA assessment and authorization (A&A) testing processes Experience with load...Temporary workLocal area
$340 per month
Missile Defense and Space Systems Research Analyst OverviewApply your analytical skills to... ...the Department of War’s operational assessment of missile defense and space systems. As... ...firsthand system knowledge.High-Level Briefing: Author written reports and deliver oral...Local areaRelocation packageFlexible hours- ...Processes, LLC is seeking a Cybersecurity Analyst V (Senior) based in Washington, DC. The... .... Responsibilities include leading RMF lifecycle execution, coordinating Security Authorization Packages, and conducting control assessments. An active Secret clearance and NQV certification...
- ...Description Job Title: Cyber & A&A Security Specialist... ...least 5 years of performing assessments of Federal Information Systems... ...Security Control Assessments and Authorization (A&A) activities for NWS FIPS... ...NIST Risk Management Framework (RMF), NWS policy, NOAA, and DOC...Remote jobTemporary work
- ...Vulnerability Management Analyst Location - Joint Base Andrews, MD... ...by performing vulnerability assessments, reviewing DISA STIG compliance... ...Risk Management Framework (RMF) compliance across Department... ...accreditation activities, and system authorization efforts by providing required...Temporary workLocal areaFlexible hours
- ...Job Title: RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm... ...RMF lifecycle activities, security assessments, continuous monitoring, and compliance... ...documentation including SSPs, SARs, POA&Ms, and authorization packages. Support system...Permanent employmentLocal areaRemote work
- ...looking for a talented Information Security Analyst - SME to provide specialized... ...management operations, conduct security assessments, implement continuous monitoring solutions... ...assessment and analysis ~ NIST frameworks (RMF, CSF, 800-53) implementation ~ Vulnerability...Remote jobFull timeContract work
$220k - $240k
GovCIO is hiring a Cybersecurity Engineer (RMF / Zero Trust) with an active Secret clearance to design, implement, and maintain... ...controls aligned with RMF and NIST standards.Support system authorization, assessment, and continuous monitoring activities.Design Zero Trust...Remote work- ...makpar.com/careers . The Senior Information Security Analyst will perform the core cybersecurity assessment and compliance work for IRS Safeguards. The role... ...5, CIS Benchmarks, DISA STIGs, FIPS, OMB A-130, and RMF guidance. Required Qualifications • High school...Full timeStart working todayFlexible hours
$158k - $178k
...seeking a Senior Operations Research Analyst . This position is a full-time opportunity... ...process control, organizational assessment, and regulatory compliance activities... ...statement herein is intended to imply any authorities to commit Battelle unless special written...Full timeWork experience placementWork at officeLocal areaRemote workFlexible hours$64k - $109.4k
...The Government Security Personnel Analyst is responsible for providing personnel security... ...; able to identify data discrepancies, assess risk indicators, and propose mitigations... ...for employment in the US must have work authorization that does not now or in the future require...Contract workLive inWork at officeLocal area$33.66 per hour
...discussions, technical support for Purchasing for all quality-related questions, risk assessment of products, analytics results, supplier notifications, notifications from authorities and general product problems Monitor and implement legal requirements including importation...Work at office- ...team of acquisition experts, financial analysts, engineers, logisticians, IT... ...Certification & Accreditation (C&A) and/or Assessment & Authorization (A&A) process. The specialist should demonstrate... ...of the Risk Management Framework (RMF) process and/or include prior...For contractors
$118.1k - $200.76k
...Information Assurance / Cybersecurity Analyst to support our work as a... ..., IAVMs, etc. Conduct risk assessments and discuss mitigation... ...Enterprise systems Assessment and Authorization (A&A) packages; topologies; ports... ...preparing and reviewing RMF packages. Experience with...Full timeFor contractorsWork experience placementLocal area- ...Governance, Risk & Compliance (GRC) Analyst to support a cybersecurity... ...decision-making and authorization activities. Collaborates with... ...reviews, updates, and compliance assessments. * Maintain and update cybersecurity... ...Risk Management Framework (RMF) * NIST SP 800-53 Rev. 5 *...Contract workRemote work
$86.6k - $181.8k
...is seeking a Network and Cyber Test Data Analyst to support Joint Interagency Task Force 4... ...network, cyber, and operational test data to assess the performance, interoperability,... ...cybersecurity frameworks including NIST RMF, Zero Trust Architecture, DoD cybersecurity...Contract workWork experience placementWork at officeFlexible hours$194.5k - $209.1k
...highly organized and motivated ERP Business Analyst to join our team in support of a NAVSEA... ...IT development, execution, and release assessments, including effectiveness and lessons... ...Secret Security ClearanceMust have authorization to work in the United States as defined...Work at officeLocal area$180k - $215k
...Data and Artificial Intelligence Analyst This position requires an active TS/Sensitive... ...development analysis. Researches and assesses data, Artificial Intelligence (AI),... ...collaboration across Title 10/Title 50 authorities. Compensation & Benefits: Estimated...Permanent employmentFull timeContract workLocal area$110k - $130k
...Vulnerability Management Analyst to support a cybersecurity... ...owners, security engineers, RMF personnel, and operational... ...are properly assessed, prioritized, remediated,... .... Collaborate with RMF/A&A teams to support Authorization to Operate (ATO) activities...Contract workRemote work- ...and FISMA Compliance. Analyze reports from vulnerability assessment scanners, patch management tools, and emerging threat information... ...of security weaknesses. Conduct reviews: security authorization documents, event logs, security incidents. Report on security...
- ...Systems is seeking an Information Security Analyst to join our work supporting our DHS... ...Model (TRM) for software products Lead Authority to Operate efforts for assigned Air and... ...update System Security Plan (SSP), Risk Assessment (RA), Privacy Threshold Analysis (PTA),...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to RMF/Assessment & Authorization (A&A) Analyst. Be the first to apply!
- recovery analyst Washington DC
- proposal analyst Washington DC
- client delivery analyst Washington DC
- transportation analyst Washington DC
- growth analyst Washington DC
- entry level program analyst Washington DC
- development analyst Washington DC
- merchandising analyst Washington DC
- behavioral analyst Washington DC
- category analyst Washington DC



