Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Analyst, RMF & ATO

JBS International

Job Description

Job Description

The Cybersecurity Analyst provides cybersecurity, information assurance, risk management, and compliance support across Digital Services initiatives. The role supports Authorization to Operate (ATO) activities, continuous monitoring, security assessments, vulnerability management, and implementation of federal cybersecurity requirements while collaborating with engineering, architecture, product, infrastructure, and program teams throughout the solution lifecycle. The Cybersecurity Analyst will serve as the Information System Security Officer (ISSO) for assigned federal systems and environments.

This position contributes to cybersecurity governance, develops and maintains security documentation, supports security assessments and audits, and helps ensure digital products, cloud environments, and enterprise technology solutions meet applicable federal security and privacy requirements.

Essential Job Functions

Cybersecurity Advisory & Secure Solution Delivery

  • Provide cybersecurity and privacy subject matter expertise across digital products, cloud services, enterprise applications, AI initiatives, and technology modernization efforts.

  • Advise project teams on identity and access management, security controls, data protection, authorization boundaries, and cybersecurity best practices throughout the system development lifecycle.

  • Review technical solutions, architectures, and proposed system changes to identify security risks and recommend appropriate mitigations.

  • Collaborate with software engineering, infrastructure, architecture, product, and data teams to integrate security requirements into solution planning, development, testing, deployment, and operational support.

  • Support alignment of technology initiatives with applicable federal cybersecurity, privacy, and risk management requirements.

Risk Management & Compliance

  • Support identification, analysis, documentation, and tracking of cybersecurity and compliance risks across systems, applications, cloud environments, and operational activities.

  • Conduct or support security assessments, compliance reviews, technical evaluations, and security control validation activities.

  • Contribute to governance reviews, technical assessments, risk recommendations, and cybersecurity decision support.

  • Assist in developing and maintaining cybersecurity policies, procedures, standards, and implementation guidance.

  • Support continuous improvement of security posture, compliance maturity, and enterprise risk visibility.

Authorization to Operate (ATO) & Security Authorization

  • Support Authorization to Operate (ATO) and Security Assessment and Authorization (SA&A) activities throughout the system lifecycle.

  • Develop, coordinate, maintain, and update authorization documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and related security artifacts.

  • Coordinate security assessments, evidence collection, remediation activities, and documentation required to obtain and maintain system authorization.

  • Support authorization decisions by collaborating with governance bodies, Authorizing Officials, Information System Security Managers (ISSMs), system owners, and technical teams.

  • Advise project teams on authorization boundaries, security categorization, inheritance, and applicable federal security requirements.

  • Support continuous monitoring activities necessary to maintain ongoing authorization.

Security Operations & Continuous Monitoring

  • Coordinate vulnerability identification, remediation tracking, and verification activities in collaboration with engineering, infrastructure, and operations teams.

  • Review vulnerability scan results, assess security findings, monitor corrective actions, and track remediation through completion.

  • Support security incident response activities through documentation, coordination, evidence collection, corrective action tracking, and lessons learned.

  • Monitor changes to systems and cloud environments to help ensure continued compliance with approved security baselines.

  • Support internal and external audits through evidence collection, documentation, corrective action management, and audit response activities.

Governance, Collaboration & Delivery Integration

  • Coordinate with project managers, architects, developers, Corporate IT, Data & AI, and governance stakeholders to ensure cybersecurity considerations are integrated throughout project planning and delivery.

  • Participate in development of governance materials, executive briefings, technical documentation, reports, and other artifacts requiring cybersecurity or compliance input.

  • Promote secure development practices and provide guidance on applicable cybersecurity requirements across Digital Services initiatives.

  • Contribute to the continuous improvement of cybersecurity templates, operational procedures, documentation standards, and governance processes.

Minimum Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.

  • 3 years of experience supporting cybersecurity, information assurance, security compliance, enterprise security, or risk management programs.

  • 3 years of experience applying federal cybersecurity frameworks and standards, including FISMA, NIST Risk Management Framework (RMF), NIST SP 800-53, FICAM, or comparable federal requirements.

  • 3+ years of experience supporting Authorization to Operate (ATO), Security Assessment and Authorization (SA&A), continuous monitoring, or related authorization activities.

  • Experience supporting the security lifecycle of one or more FIPS 199 Moderate-impact federal information systems, including security documentation, security control implementation, assessment support, Authorization to Operate (ATO), and continuous monitoring activities.

  • Experience developing and maintaining security authorization documentation, including SSPs, SAPs, SARs, POA&Ms, and related security artifacts.

  • Experience supporting security assessments, compliance reviews, vulnerability management, audit support, or enterprise risk management activities.

  • Experience collaborating with software engineering, cloud, infrastructure, architecture, product, and project teams to integrate cybersecurity requirements into technology solutions.

  • Working knowledge of cloud platforms (AWS and/or Azure), identity and access management, secure system development lifecycle (SDLC), and cybersecurity best practices.

  • One or more professional cybersecurity certifications such as CompTIA Security+, CompTIA CySA+, ISC2’s Certified in Cybersecurity (CC), Certified in Governance, Risk and Compliance (CGRC), Systems Security Certified Practitioner (SSCP), or an equivalent cybersecurity certification is required.

  • Strong analytical, organizational, written, and verbal communication skills with the ability to communicate effectively with both technical and non-technical stakeholders.

Security Clearance:

• Ability to pass background investigations as required for access to federal facilities and systems.

  • This position requires the ability to obtain a Public Trust.

Location:

  • Remote with the consideration that if a candidate lives within a 50-mile radius of JBS's North Bethesda, MD or San Mateo, CA offices, the position will be considered hybrid.

Physical Requirements:

  • Ability to sit for prolonged periods at a desk or computer workstation.

  • Regularly uses a computer, keyboard, and mouse.

  • Normal or corrected vision to read documents, view computer screens, and perform tasks that require visual accuracy.

  • Ability to hear and understand spoken information in person and over the phone.

  • Minimal lifting and carrying may be required, typically light office supplies or documents.

  • Ability to move within the office environment to access equipment, files, and interact with colleagues.

  • Ability to handle occasional stress related to deadlines, workloads, or challenging tasks.

Preferred Qualifications

  • Advanced cybersecurity certifications such as ISC2 CISSP, ISACA CISM, or equivalent.

  • Experience supporting FedRAMP-authorized cloud environments.

  • Experience with vulnerability management and security assessment tools such as Tenable, Nessus, AWS Inspector, Microsoft Defender, or comparable technologies.

  • Familiarity with DevSecOps, secure software development lifecycle (Secure SDLC), or cloud-native application security practices.

  • Experience supporting web applications, cloud-native solutions, AI-enabled technologies, APIs, or enterprise business systems.

  • Experience supporting privacy, data protection, or governance initiatives within federal environments.

Other Duties Assigned: This position description should not be construed to imply that these requirements are the exclusive standards of the position, nor will it be the sole basis for any subsequent employee evaluations. Incumbents will follow any other instructions and perform any other related duties as may be required by their supervisor.

This position is subject to availability of funds and to any and all restrictions contained in the contract or contracts that provide funding for this position.

APPLICATION INFORMATION:

If you meet the minimum requirements for this position, please click on the "Apply" link posted below and complete the application. Please include cover letter, resume, and at least (3) professional references.

Our company is an equal opportunity/affirmative action employer. Applicants can learn more about the company's status as an equal opportunity employer by viewing the federal "EEO" poster at EEOPost.pdf. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, disability, or protected Veteran status.

If you need a reasonable accommodation for any part of the employment process, please contact us by email at View email address on us.fitly.work and let us know the nature of your request and your contact information.

Vacancy posted 16 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity Analyst, RMF & ATO in Rockville, MD vacancy
  • DLH Corporation seeks a Security Assessment & Authorization Analyst to develop and maintain Authority to Operate (ATO) security packages and RMF artifacts for assigned systems. You will collaborate across teams to assess controls, document security posture, manage POA&... 
    Suggested

    Socket.dev

    Bethesda, MD
    2 days ago
  • Phase2 Technology is seeking a Senior Security Analyst to partner with VA ISO/ISSO, site managers, and stakeholders to drive RMF steps 0-6 and ATO activities. You will identify and mitigate risks, elevate issues to leadership, apply VA policies, and produce security documentation... 
    Suggested

    Phase2 Technology

    Mc Lean, VA
    5 days ago
  •  ...experienced Security Assessment & Authorization Analyst to develop and maintain Authority to Operate (ATO) packages and RMF-based documentation. You will work with...  ...coordinate with cross-functional teams to solve cybersecurity challenges in a federal #J-18808-Ljbffr Socket
    Suggested

    Socket

    Bethesda, MD
    2 days ago
  • DLH Corp in Bethesda, Maryland is seeking a Security Assessment & Authorization Analyst to develop and maintain ATO packages and support RMF lifecycle across assigned systems. You will work with customers to understand technologies, document security controls, and manage... 
    Suggested

    DLH Corporation

    Bethesda, MD
    2 days ago
  • Amentum is seeking a Cybersecurity Analyst to support a McLean, VA based federal civilian agency as a contractor. The role focuses on RMF/A&A activities, developing SSPs, POA&Ms, SARs, and related RMF artifacts, with emphasis on risk analysis and security documentation... 
    Suggested
    Civilian Contractor

    Amentum

    Mc Lean, VA
    5 days ago
  •  ...benefits package. Position Title: Senior Cyber-Security Analyst / Navy Validator Location: Onsite in Arlington, VA...  ...systems and networks. Implements Navy Risk Management Framework (RMF) Implementation Plan IAW DODI 8510.01. Develops, coordinates,... 
    Work at office
    Immediate start

    Saliense Consulting LLC

    McLean, VA
    19 days ago
  •  ...National Security Solutions in Northern Virginia is seeking a Senior Cybersecurity Advisor to support a government customer. You will advise on...  ...policy to align with mission requirements. Key duties include RMF/ATO activities, zero-trust planning, incident response guidance,... 

    KBR Careers

    Mc Lean, VA
    4 days ago
  • DLH Corp in Bethesda, MD is seeking a Security Assessment & Authorization Analyst to develop and maintain ATO packages and support RMF across systems. The ideal candidate has 5+ years in ATO, experience with NIST 800-53, cloud security, and FedRAMP considerations, and... 

    DLH Corp

    Bethesda, MD
    2 days ago
  • $90k - $130k

     ...Job Summary  JCS Solutions is seeking a Cybersecurity Analyst and help protect critical federal...  ...environments.   Familiarity with NIST, FISMA, RMF, and other federal cybersecurity...  ...compliance activities, or Authority to Operate (ATO) processes.  How will you wow us:... 
    Contract work
    Temporary work
    Local area

    JCS Solutions LLC

    Bethesda, MD
    12 days ago
  •  ...Germantown, MD to lead cyber strategy across radar programs. You will own vulnerability management, STIG implementation, and the end-to-end ATO process, guiding audits and mentoring engineers while ensuring DoD security alignment. The role demands DoD-focused expertise,... 

    Jobleads-US

    Germantown, MD
    1 day ago
  •  ...Clearance: TS/SCI w/Polygraph VMR Strategic Solutions is seeking an RMF/Security Assessment. Are you interested in joining a dynamic...  ...-wide cyberspace operations systems? We’re seeking a skilled cybersecurity professional to play a pivotal role within this team. Your... 
    Full time
    Shift work

    VMR Strategic Solutions

    Derwood, MD
    24 days ago
  • $100k - $150k

     ...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location: 50 miles of McLean, Virginia Position...  ...federal national security customer. Experience with RMF, ATO, NIST SP 800-53, continuous monitoring, vulnerability management... 
    Full time
    Contract work

    Ops Tech Alliance

    McLean, VA
    more than 2 months ago
  • DLH Corporation is seeking a Security Assessment & Authorization Analyst to develop and maintain ATO security packages and documentation, guiding systems through the RMF lifecycle. You will collaborate across teams to assess controls, track POA&Ms, and ensure compliance... 

    Socket

    Bethesda, MD
    2 days ago
  • $130k - $170k

     ...Description Tier 3 Cybersecurity Analyst Location: Rockville, MD Position Overview The Tier 3 Cybersecurity Analyst serves as a senior technical leader within the SOC, responsible for advanced threat detection, incident response, threat hunting, and forensic... 
    Full time
    Flexible hours

    ActioNet, Inc.

    Rockville, MD
    a month ago
  • $158.95k - $215.05k

     ...Description: CYBER TECHNICAL ANALYST SR PRINCIPAL Advance your career...  ...operations. Support the full RMF and Assessment & Authorization...  ...in information assurance and cybersecurity roles Minimum of 5 years of...  ...of achieving and maintaining ATO for classified systems Expert... 
    Temporary work
    Immediate start
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Mc Lean, VA
    6 days ago
  • $62k - $141k

    Cybersecurity AnalystThe Opportunity: As an Information Security Risk Specialist on our team, you will leverage your expertise...  ...supporting federal government or DoD ATO packages, performing A&A and RMF, and conducting risk assessments for federal government... 
    Full time
    Contract work
    Part time
    For contractors
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    2 days ago
  • $130k - $160k

    Amentum is seeking a Cybersecurity Analyst to join our team and support our McLean, VA customer. We are looking for team members who are passionate...  ...(A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor. The... 
    Hourly pay
    Civilian Contractor
    Contract work
    For contractors
    Work at office
    Local area

    Amentum

    Mc Lean, VA
    5 days ago
  •  ...hybrid systems in accordance with the NIST Risk Management Framework (RMF), NWS policy, NOAA, and DOC directives Validate information...  ...Assessment Reports (VARs), and Authorization to Operate (ATO) briefing deck. Skills: Cyber Security, Information Security... 
    Temporary work
    Remote work

    ATTAINX INC

    Silver Spring, MD
    18 days ago
  •  ...MANTECH seeks a motivated, career and customer-oriented Cybersecurity Analyst - Evenings to join our team in Tysons, VA   The Cybersecurity Analyst will monitor Air Gapped Security Fabrics through managed SECOPs Tools.   Responsibilities include but... 
    Work at office
    Local area
    Shift work
    Afternoon shift

    MANTECH

    Tysons, VA
    48 minutes ago
  •  ...MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x7x365 cybersecurity support to one of the most coveted targets in the world.  The Cyber Incident Response Analyst... 
    Shift work
    Night shift
    Day shift
    Afternoon shift

    MANTECH

    McLean, VA
    48 minutes ago
  • ActioNet, Inc. seeks a senior Tier 3 Cybersecurity Analyst to lead advanced threat detection, incident response, and forensics within a high-sophistication SOC. You will mentor junior staff, craft detection analytics, and coordinate with federal partners on complex investigations... 

    ActioNet, Inc.

    Rockville, MD
    5 days ago
  • ActioNet is seeking a Tier 3 Cybersecurity Analyst in Rockville, MD to lead advanced incident detection, response, and forensic investigations. The role requires extensive expertise in malware analysis, threat hunting, and multi-source data fusion to mitigate sophisticated... 

    ActioNet

    Rockville, MD
    5 days ago
  • $91.6k - $153.8k

     ...groundbreaking tech. Explore thrilling projects in Digital Transformation, Cybersecurity, IT, Data Analytics and Software Development. Elevate your...  ..., career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x7x... 
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Local area
    Remote work
    Shift work
    Night shift
    Day shift
    Afternoon shift

    ManTech International Corporation

    McLean, VA
    1 day ago
  • A cybersecurity consulting firm based in McLean, Virginia is seeking an IT Security Control Assessor. The role involves conducting FISMA security...  ...and supporting system authorizations throughout the RMF lifecycle. Candidates should have at least three years of experience... 
    Flexible hours

    Dovel Technologies, Inc

    Mc Lean, VA
    2 days ago
  • Senior Cybersecurity Advisor (Expert/Master) Location Bethesda, MD Job Code 2632 of Openings 1 Apply Now ( DCCA is a veteran-owned IT...  ...leadership, guiding cybersecurity policy, Zero Trust implementation, RMF/ATO activities, DevSecOps integration, and enterprise security... 
    Flexible hours

    DCCA

    Bethesda, MD
    6 days ago
  •  ...approaches in federal environments. Supports cybersecurity risk reduction patterns such as...  ...environments with NIST control baselines and formal ATO constraints. Demonstrated ability to...  ...3A assessment evidence expectations, and RMF lifecycle. Systems security engineering... 
    Contract work
    Temporary work
    For contractors
    Flexible hours

    PRECISE SOFTWARE SOLUTIONS INCORPORATED

    Rockville, MD
    26 days ago
  • $70k - $98k

     ...year Requirements: High School Diploma Experience in a cybersecurity-related position Capability to acquire DoD 8570 IAT-II...  ...strategies Provide guidance and technical mentorship to junior analysts during intensive investigative processes Technologies:... 
    Full time
    Shift work
    Day shift

    MANTECH

    McLean, VA
    17 days ago
  • $131.3k - $237.35k

     ...capabilities. You will serve as a senior cybersecurity architect responsible for defining the security...  ...environmentsLead Authority to Operate (ATO) planning and execution activitiesConduct...  ...controls and Risk Management Framework (RMF)Experience leading ATO efforts for... 
    Full time
    Remote work

    Leidos

    Gaithersburg, MD
    18 days ago
  •  ...Job Description Job Description Job Title: Mid-Level Cybersecurity Incident Response Analyst Location: Bethesda, Maryland Type: Direct Hire Compensation: 120k Work Model: Hybrid Hours: 40.0 Security Clearance: Public Trust Responsibilities Monitor... 
    Local area

    System One

    Bethesda, MD
    26 days ago
  • Overview Cybersecurity Analyst - McLean, VA. TS/SCI clearance with polygraph required. Bridge Core is seeking a skilled analyst to support government agencies in cyberspace. Responsibilities We are seeking a skilled and motivated Cybersecurity Analyst to join our team.... 
    Shift work
    Night shift
    Afternoon shift

    Bridge Core (BCore)

    Mc Lean, VA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Analyst, RMF & ATO. Be the first to apply!