Salary:
RMF / Compliance Analyst
Position Overview
The RMF / Compliance Analyst provides hands-on support for federal cybersecurity compliance, RMF documentation, FISMA reporting, POA&M maintenance, risk assessments, policy analysis, gap assessments, training materials, and recurring operational security support. This role works under the direction of the Senior ISSO / RMF Lead and supports timely completion of contract deliverables.
Key Responsibilities
- Support RMF implementation and execution activities across assigned NCHS systems.
- Develop, update, and maintain SSPs, POA&Ms, RARs, contingency plan inputs, authorization artifacts, and compliance documentation.
- Conduct or support risk assessments for systems, business processes, policies, and security requirements.
- Perform policy analysis and gap assessments against federal, HHS, CDC, and NCHS security/privacy requirements.
- Support FISMA reporting, OMB/DHS data calls, and recurring compliance submissions.
- Track vulnerabilities, security weaknesses, remediation timelines, POA&M status, and evidence of closure.
- Assist with development of SOPs, templates, dashboards, process documentation, training materials, and stakeholder briefing materials.
- Support weekly status reporting and monthly RMF reporting with accurate status, risk, issue, and remediation updates.
- Assist with EPLC reviews, IT acquisition security reviews, software assurance support, and other ad hoc RMF-related taskings.
Qualifications and Experience
- Experience supporting RMF, FISMA, SA&A/ATO, POA&M, and federal compliance documentation.
- Familiarity with NIST SP 800-37, 800-30, 800-53/53A, 800-18, 800-60, FIPS 199/200, OMB A-130, and federal privacy/security requirements.
- Experience preparing or maintaining SSPs, RARs, POA&Ms, policy gap reports, vulnerability reports, and process documentation.
- Experience using Archer or comparable GRC/security documentation platforms.
- Strong technical writing, documentation management, meeting support, and stakeholder coordination skills.
Required Skills
RMF documentation, FISMA compliance, SA&A support, ATO artifacts, POA&M tracking, SSP updates, risk assessments, vulnerability and compliance reporting, NIST controls, policy analysis, gap analysis, SOP development, dashboard/report preparation, Archer/GRC tools, technical writing, and stakeholder coordination.
Certification Requirement
Preferred: CAP, Security+, CISSP Associate, CISM, or equivalent cybersecurity/compliance certification.
Clearance / Security Requirement
No classified clearance required. Personnel must complete applicable CDC/HHS security, privacy, records management, role-based training, NDA requirements, and any required Public Trust/HSPD-12/PIV processing.
Salary
TBD.