RMF / CSAM Analyst [Remote]
$75k - $104kjobgether
- Remote job
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a RMF / CSAM Analyst based in United States.
This role supports the continuous security authorization, compliance, and protection of a cloud-based federal identity and access management environment.
You will help maintain alignment with federal cybersecurity frameworks, regulatory requirements, and security best practices.
The position plays a key role in managing RMF and CSAM activities, security controls, POA&Ms, vulnerability remediation, and continuous monitoring.
You will collaborate with security teams, ISSOs, technical stakeholders, and program leaders to identify risks and drive corrective actions.
The role combines detailed compliance management with hands-on analysis of security findings, documentation, and reporting.
Success requires strong organization, technical understanding, and the ability to respond effectively to both routine compliance activities and emerging security needs.
This is an opportunity to contribute directly to the security and compliance of critical federal identity services in a structured, mission-focused environment.
Accountabilities:
- Manage and maintain Risk Management Framework (RMF) and Cyber Security Assessment and Management (CSAM) activities to support continuous authorization and compliance of the IAM environment.
- Ensure security and compliance alignment with FedRAMP, FISMA, NIST SP 800-63, OMB M-24-15, OMB M-21-31, and applicable federal cloud security requirements.
- Maintain security controls, inheritance statements, authorization documentation, and evidence required to sustain the Authority to Operate (ATO).
- Track, analyze, and support remediation of Plan of Action and Milestones (POA&M) items, vulnerability findings, CDM results, and Common Vulnerabilities and Exposures (CVEs).
- Analyze security scan results, develop corrective action plans, monitor remediation progress, and escalate unresolved risks as appropriate.
- Support security incident management, continuous monitoring, cybersecurity reporting, and maintenance of the required Cybersecurity Framework (CSF) scorecard.
- Oversee compliance requirements related to event logging, encryption of data at rest and in transit, protection of sensitive user information, and secure handling of federal data.
- Support supply chain risk management, federal records requirements, Controlled Unclassified Information (CUI) handling, Section 508 accessibility, and technology business management reporting.
- Maintain accurate project, risk, schedule, compliance, and environment-support documentation needed for ongoing security authorization.
- Collaborate closely with ISSOs, cybersecurity teams, technical stakeholders, and program leadership to communicate risks, requirements, findings, and remediation status.
- Respond effectively to urgent security and compliance issues while maintaining consistent execution of recurring reporting and monitoring activities.
Requirements:
- Bachelor’s degree in cybersecurity, information technology, computer science, or a related discipline, with at least 2 years of relevant professional experience.
- Required Public Trust clearance and ability to operate effectively within a federal government security environment.
- Strong knowledge of the NIST Risk Management Framework (RMF) and experience working with the CSAM tool or comparable security compliance platforms.
- Experience with FedRAMP, FISMA, POA&M management, security control assessments, control inheritance, and continuous monitoring.
- Familiarity with NIST SP 800-63, OMB M-21-31, OMB M-24-15, cloud security requirements, and federal cybersecurity policies.
- Understanding of data encryption, secure logging, vulnerability management, cybersecurity controls, and compliance reporting.
- Ability to analyze vulnerability and security assessment results, develop corrective action plans, and track remediation through completion.
- Strong documentation, organization, recordkeeping, and attention-to-detail skills, particularly when managing security evidence and compliance artifacts.
- Proficiency with Microsoft Office and compliance, security, or project-tracking tools.
- Excellent written and verbal communication skills, with the ability to collaborate effectively with ISSOs, security professionals, technical teams, and other stakeholders.
- Ability to balance recurring compliance responsibilities with urgent security issues and changing priorities.
- Detail-oriented, dependable, collaborative, and committed to maintaining high cybersecurity standards in a federal environment.
Benefits:
- Salary: $75,000–$104,000 USD annually, with final compensation determined by factors such as responsibilities, education, certifications, experience, internal equity, and market considerations.
- Remote work environment.
- 11 federal holidays.
- Paid time off accrued each pay period.
- Paid parental leave.
- Three medical plan options with employer contributions.
- Dental and vision insurance.
- Company-paid short-term and long-term disability coverage.
- Company-paid life and AD&D insurance.
- 401(k) plan with competitive employer matching and vesting.
- Continuing education assistance.
- Medical, dependent care, and commuter Flexible Spending Accounts.
- Employee Assistance Program.
- Wellness benefits, including Calm Health and a WellHub gym subsidy.
- 529 College Savings Plan.
- Legal insurance.
- Pet insurance.
- Veterans are encouraged to apply
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
- ...government collaboration to protect critical DoD information. The role requires 10+ years of experience, a Secret clearance, and DoD RMF knowledge, with hands-on experience in ACAS, STIGs, and related security tooling. #J-18808-Ljbffr General Dynamics Information TechnologySuggested
- Amatriot Group, LLC is seeking an Information Security Analyst to support the US BICES-X team, aiding DoD intelligence sharing on threats... ...partners. The role involves coordinating policy, standards, and RMF activities across government and services, and performing risk...Suggested
- Abacus Technology Corporation is seeking an Information Security Analyst to support security and information assurance activities for... ...security experience, a Bachelor’s degree, Security+ CE certification, RMF/C&A/eMASS knowledge, PKI, and incident response expertise. U.S....SuggestedFull time
$105k - $115k
CALIBRE Systems, Inc. is seeking a Senior Information Security Analyst to support a DoD client with enterprise cybersecurity for a large... ...some required meetings in Alexandria, VA. The candidate will lead RMF/ATO, continuous monitoring, and eMASS, while guiding Zero Trust...Suggested- CALIBRE Systems, Inc. is seeking a Journeyman Information Security Analyst to support a DoD client with enterprise cybersecurity for a... ...and requires an active Secret clearance. Responsibilities include RMF documentation, security control implementation, DISA STIG/ACAS assessments...Suggested
- ...and contract policy. Four or more years of experience in federal RMF operations, continuous monitoring, or security control assessment... .... Experience with enterprise GRC platforms such as JCAM, CSAM, eMASS, or Xacta. Strong analytical writing skills, including the...Contract work
- ...security policies, procedures, and technologies to protect systems, applications, and data across tactical and development networks. The candidate will support RMF A&A using eMASS, provide IA/Cybersecurity services in line with USG/DoD/NSA guidelines, #J-18808-Ljbffr LeidosRemote work
- Booz Allen Hamilton seeks a seasoned RMF Analyst to ensure NIST-based security control implementation for complex DoD information systems. You will support full ATO certification, measure risk, review system documentation, and develop findings reports. Targeted for candidates...
- ...is seeking a Senior Information Security Analyst to support EPA programs in the DC Metro area... ...a hybrid schedule. The role focuses on RMF, NIST controls, and GRC leadership, including... ...are required, with experience using Xacta/RSA Archer/CSAM/eMASS. #J-18808-Ljbffr DSA
- ...IT company serving DoD customers, seeks an Information Assurance Analyst Intern to join the Information Systems Security Engineering team... ...security of Naval software systems. You will assist in RMF A&A services and conduct cybersecurity risk assessments. You will...Internship
- Quadrant, Inc. seeks an Information Assurance (IA) Analyst for a role based at Fort Meade, MD. The position requires an active secret clearance... ...+ years of relevant IA experience, and a solid understanding of RMF, STIGs, ACAS, and ESS. Responsibilities include supporting...
- ...technology solutions provider is seeking an Information Assurance Analyst in Indianapolis, IN. The ideal candidate will have over 5 years... ...and vulnerability assessments, along with familiarity with DoD RMF. An active Secret clearance and U.S. citizenship are required for...
- ...We are seeking Systems Security Analyst to join our team. In this role, you will have the opportunity... ...monitoring processes, including RMF, NIST SP 800-53, NIST CSF, A&A/C&A, POA&M... ...vulnerability and POA&M workflows across CSAM/GRC, WTT/ServiceNow, Jira, and Excel, ensuring...Local areaRemote work3 days per week
- ...assessments and collaborate with program managers to translate complex security concepts into actionable decisions. Ideal candidates have RMF/A&A experience, strong knowledge of Windows and Linux, and TS/SCI or ability to obtain clearance. #J-18808-Ljbffr Phase2 Technology
- Kingfisher Systems, Inc. seeks a Principal Information Assurance Analyst to support the Headquarters Department of the Army ODCS G2. The... ...in certified environments. The successful candidate will manage RMF processes, prepare authorization packages, and ensure compliance...
$105k - $115k
...DSA is hiring a Senior Information Security Analyst. This is a full-time position supporting a... ...regards to the Risk Management Framework (RMF) and all associated information security... ...) tool, Telos Xacta (or an alternate like CSAM or RSA Archer), to track and reconcile findings...Full timeContract workWork at officeRemote workFlexible hours- ...Overview RMF Analyst III Huntsville, AL Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega...Contract workWork at officeNight shiftWeekend work
- CALIBRE Systems, Inc. is seeking a Journeyman Information Security Analyst to support a DoD program with enterprise cybersecurity. The role combines RMF, vulnerability management, incident response, and compliance activities across DoD cloud and information systems. A Secret...
- Falconwood, Inc. is seeking an Information Assurance Analyst to support NAVIFOR N6 RMF processes in a hybrid onsite/remote role in Suffolk, VA. The candidate will develop and review RMF packages, ensure timely artifacts, and advise on information assurance solutions within...Remote work
- ASSYST is seeking a Cybersecurity Risk Advisor to support federal cybersecurity programs. The role focuses on evaluating risk posture, RMF expertise, and guiding stakeholders on actions for risk reduction, with emphasis on PII/PHI handling and regulatory alignment. The...
- Hepburn and Sons LLC seeks a Cybersecurity Acquisition Analyst to support the Cybersecurity program for Hull, Mechanical, and Engineering... ...platforms. The role requires only a generic understanding of RMF and does not involve implementing cyber changes or policy direction...
- Empower AI is hiring an Information Security Analyst I to assist with Risk Management Framework efforts, located in Fort Huachuca, Arizona. The successful candidate will work closely with Project Managers and Cybersecurity Engineers, ensuring compliance and managing cybersecurity...
- CL 1e6d8f31 073f 48cd b324 b581c00084bf is seeking a Compliance Analyst focused on GRC and RMF initiatives. You will support governance and compliance by developing security documentation in accordance with federal standards. The ideal candidate will have experience in...
- ...is seeking a Cleared Senior to Mid-level Information Assurance Analyst to support the Bureau of Overseas Building Operations at the U.S... ...IT portfolio. This is a highly experienced position emphasizing RMF implementation, ATO package development, policy compliance, and...Remote jobWork at officeOverseas
- ...Trust What You Will Do Lead and/or support the development of RMF and A&A documentation including SSPs, control implementation matrices... ...(3) years of relevant experience Experience as an RMF or POAM Analyst (current or past) Excellent verbal and written communication...Temporary workWork at officeFlexible hours
- SkyePoint Decisions is seeking an RMF/Assessment & Authorization (A&A) Analyst to support the implementation and maintenance of the RMF for information systems and applications. You will work with System Owners, ISSOs, cybersecurity teams, and Government stakeholders to...Remote job
- ...Solutions & Strategies seeks a Journeyman Information Security Analyst to support United States Space Force Space Systems Command (SSC)... ...Mexico. The role focuses on cybersecurity, information assurance, RMF, and system authorization for mission systems. The candidate...
- CALIBRE Systems, Inc. is seeking a Journeyman Information Security Analyst to support a DoD client with enterprise cybersecurity for a... ...with required meetings in Alexandria, VA. The analyst will handle RMF, vulnerability management, incident response, and compliance activities...
- ...Inc in Orlando, Florida is seeking a Security Operations Center Analyst II to monitor, detect, and respond to cyber threats 24/7 for the... ...U.S. Army. The role emphasizes adherence to DoD cyber policies, RMF processes, and proactive defense of enterprise systems. The analyst...Remote work
$115k - $135k
...produce meaningful results. This is a contingent position based on contract win. SkyePoint Decisions is seeking a RMF/Assessment & Authorization (A&A) Analyst tosupport the implementation and maintenance of the Risk Management Framework (RMF) for information systems and...Contract workRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to RMF / CSAM Analyst [Remote]. Be the first to apply!
- pay analyst United States
- design analyst United States
- internal audit analyst United States
- open source analyst United States
- production control analyst United States
- legislative analyst United States
- trade analyst United States
- accessibility analyst United States
- soc analyst United States
- hybrid analyst United States

