1

Nist Rmf Jobs (NOW HIRING)

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements. * Assess security ...

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements. * Assess security ...

Security Engineer

Mclean, VA · On-site

$150K - $200K/yr

Lead and support FedRAMP Moderate/High and IC ATO authorization efforts, ensuring compliance with NIST RMF, NIST 800-53, NIST 800-37, FedRAMP, and ICD 503 requirements. * Conduct risk assessments ...

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements. * Assess security ...

Semper Valens Solutions is seeking a detail-oriented RMF Analyst to support the assessment, authorization, and continuous monitoring of information systems in accordance with the NIST Risk Management ...

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements. * Assess security ...

$89K - $110K/yr

Cyber Command, MC&FP, NIST RMF, Zero Trust, STIG/SRG, ACAS, and eMASS requirements while supporting the attainment and sustainment of Government-issued Authorizations to Operate (ATOs). An active TOP ...

Cyber Command, MC&FP, NIST RMF, Zero Trust, STIG/SRG, ACAS, and eMASS requirements while supporting the attainment and sustainment of Government-issued Authorizations to Operate (ATOs). An active TOP ...

$189K - $231K/yr

System Security Engineer 2 - (Security, RMF, NIST 800-53) * Annapolis Junction, Maryland System Security Engineer 2 - (Security, RMF, NIST 800-53) Clearance: TS/SCI - Polygraph required Position ID ...

RMF Engineer, Journeyman Job Category: Security Time Type: Full time Minimum Clearance Required to ... Implement and validate NIST SP 800-53 security controls supporting system authorization and ...

Showing results 41-60

Nist Rmf information

See salary details

$43K

$99.4K

$150K

How much do nist rmf jobs pay per year?

As of Sep 13, 2026, the average yearly pay for nist rmf in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What is NIST RMF?

NIST RMF stands for the National Institute of Standards and Technology Risk Management Framework. It is a structured process used by federal agencies and organizations to identify, assess, and manage cybersecurity risks to information systems. The RMF provides a set of steps that guide organizations through the selection, implementation, assessment, and monitoring of security controls to ensure systems meet required security standards. This framework is essential for achieving compliance with federal cybersecurity requirements and improving overall information security.

What are the key skills and qualifications needed to thrive as a NIST RMF specialist?

To thrive as a NIST RMF specialist, you need a solid understanding of information security principles, risk assessment, compliance standards, and often a background in cybersecurity or IT, supported by certifications like CISSP, CAP, or Security+. Familiarity with NIST SP 800-37, eMASS, and other GRC (Governance, Risk, and Compliance) tools is typically required. Attention to detail, analytical thinking, and strong communication skills help professionals navigate complex regulatory requirements and effectively collaborate with stakeholders. These skills are essential for ensuring organizational compliance, safeguarding sensitive data, and managing security risks efficiently.

What are some typical challenges faced by professionals implementing the NIST RMF in an organization?

Professionals working with the NIST Risk Management Framework (RMF) often encounter challenges such as aligning organizational processes with RMF requirements, ensuring stakeholder buy-in, and maintaining comprehensive documentation. Adapting legacy systems to meet modern security controls can be complex, and coordinating efforts across multiple teams—such as IT, compliance, and management—requires strong communication skills. Staying current with evolving NIST guidelines and integrating continuous monitoring into daily operations are also important aspects to manage for success in this role.

What is the difference between Nist Rmf vs Cybersecurity Analyst?

AspectNist RmfCybersecurity Analyst
CertificationsRisk Management Framework (RMF) certifications, NIST guidelinesCompTIA Security+, CISSP, CEH
Work EnvironmentGovernment agencies, federal projects, compliance-focusedPrivate sector, IT departments, security teams
Industry UsagePrimarily in federal and defense sectorsAcross various industries including finance, healthcare, tech
Primary FocusImplementing and managing risk management frameworksMonitoring, analyzing, and responding to security threats

While Nist Rmf specialists focus on establishing and maintaining risk management processes based on NIST standards, Cybersecurity Analysts are more involved in threat detection and incident response. Both roles require security knowledge but serve different functions within cybersecurity frameworks.

More about Nist Rmf jobs

What states have the most Nist Rmf jobs?

States with the most job openings for Nist Rmf jobs include:

Infographic showing various Nist Rmf job openings in the United States as of September 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $99,400 per year, or $47.8 per hour.

Senior Information Security Engineer

Reston, VA • Remote

$110K - $150K/yr

Full-time

Posted 20 days ago


ASRC Federal rating

7.8

Company rating: 7.8 out of 10

Based on 28 frontline employees who took The Breakroom Quiz


Job description

ASRC Federal Data Networx is seeking a Senior Information System Security Officer (ISSO) to support federal cybersecurity and Risk Management Framework (RMF) activities for enterprise information systems. The ISSO serves as the primary cybersecurity and privacy advisor to System Owners (SOs), ensuring security and privacy requirements are integrated throughout the system lifecycle while maintaining compliance with federal regulations and Authorization to Operate (ATO) requirements.

Work Location: Remote

Key Responsibilities

  • Serve as the primary cybersecurity and privacy advisor to System Owners for assigned systems.
  • Lead RMF activities, including development and maintenance of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts.
  • Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements.
  • Assess security risks, validate security controls, and coordinate remediation of vulnerabilities and Plans of Action and Milestones (POA&Ms).
  • Maintain system inventories, security documentation, contingency plans, configuration management plans, and privacy documentation.
  • Collaborate with ISSMs, System Owners, Security Control Assessors, and technical teams to integrate security throughout the system lifecycle.
  • Monitor system security posture, review vulnerability and compliance scan results, and support continuous authorization initiatives.
  • Provide cybersecurity guidance, develop security policies and procedures, and deliver security awareness training.
  • Support security engineering, certification and accreditation activities, and implementation of security controls across systems.
  • Recommend process improvements and automation opportunities to enhance RMF and cybersecurity operations.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field.
  • Minimum 5–7 years of experience supporting information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience.
  • Experience supporting federal cybersecurity programs and the NIST Risk Management Framework (RMF).
  • Experience developing and maintaining RMF documentation, authorization packages, and Governance, Risk, and Compliance (GRC) tools.
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy requirements.
  • Experience supporting Authorization to Operate (ATO), Continuous ATO (cATO), or Continuous Authorization efforts.
  • Strong analytical, communication, documentation, and stakeholder engagement skills.

Required Certifications

  • Certified Information Systems Security Professional (CISSP)
  • Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP)

Preferred Qualifications

  • Experience supporting U.S. federal civilian agencies, preferably the USPTO.
  • Experience with continuous monitoring, vulnerability management, and security automation.
  • Familiarity with cloud security, DevSecOps, and continuous authorization initiatives.
  • Knowledge of privacy compliance activities, including Privacy Threshold Assessments (PTAs), Privacy Impact Assessments (PIAs), and System of Records Notices (SORNs).

What ASRC Federal employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom