Maintain working knowledge of DoD, DCSA, and NIST RMF guidance and policies * Perform SSP reviews in accordance with the plan * Use critical thinking to aid decision-making and highlight paths that ...
Maintain working knowledge of DoD, DCSA, and NIST RMF guidance and policies * Perform SSP reviews in accordance with the plan * Use critical thinking to aid decision-making and highlight paths that ...
Lead Information System Security Officer (ISSO)
Washington, DC · On-site +1
$120K - $160K/yr
Ensure assigned systems remain aligned with NIST RMF, NIST SP 800-53, FISMA, and agency cybersecurity requirements. * Support and maintain reporting dashboards, status tracking, and collaboration ...
Lead Information System Security Officer (ISSO)
Washington, DC · On-site +1
$120K - $160K/yr
Ensure assigned systems remain aligned with NIST RMF, NIST SP 800-53, FISMA, and agency cybersecurity requirements. * Support and maintain reporting dashboards, status tracking, and collaboration ...
IA frameworks (NIST RMF, FISMA, NIST SP 800 series) into clear, actionable outputs for UK Government stakeholders • Provide analytical assurance support to ensure outputs are coherent, complete ...
IA frameworks (NIST RMF, FISMA, NIST SP 800 series) into clear, actionable outputs for UK Government stakeholders • Provide analytical assurance support to ensure outputs are coherent, complete ...
Sr. Solutions Architect II (6543)
$175K - $220K/yr
Design and govern enterprise Zero Trust architectures aligned with ICD 503, IC CIO guidance, and NIST RMF. * Assess current and target states to identify and manage systemic, inherited, and residual ...
Sr. Solutions Architect II (6543)
$175K - $220K/yr
Design and govern enterprise Zero Trust architectures aligned with ICD 503, IC CIO guidance, and NIST RMF. * Assess current and target states to identify and manage systemic, inherited, and residual ...
Maintain working knowledge of DoD, DCSA, and NIST RMF guidance and policies * Perform SSP reviews in accordance with the plan * Use critical thinking to aid decision-making and highlight paths that ...
Maintain working knowledge of DoD, DCSA, and NIST RMF guidance and policies * Perform SSP reviews in accordance with the plan * Use critical thinking to aid decision-making and highlight paths that ...
Maintain working knowledge of DoD, DCSA, and NIST RMF guidance and policies * Perform SSP reviews in accordance with the plan * Use critical thinking to aid decision-making and highlight paths that ...
Maintain working knowledge of DoD, DCSA, and NIST RMF guidance and policies * Perform SSP reviews in accordance with the plan * Use critical thinking to aid decision-making and highlight paths that ...
Maintain working knowledge of DoD, DCSA, and NIST RMF guidance and policies * Perform SSP reviews in accordance with the plan * Use critical thinking to aid decision-making and highlight paths that ...
Maintain working knowledge of DoD, DCSA, and NIST RMF guidance and policies * Perform SSP reviews in accordance with the plan * Use critical thinking to aid decision-making and highlight paths that ...
Cloud Architect / Engineer / Integrator (C&A)
Washington, DC · On-site
$74.25 - $98.50/hr
Ensures compliance with federal security standards, including FISMA, NIST, RMF, and Zero Trust.
Cloud Architect / Engineer / Integrator (C&A)
Washington, DC · On-site
$74.25 - $98.50/hr
Ensures compliance with federal security standards, including FISMA, NIST, RMF, and Zero Trust.
Ensure systems comply with NIST, RMF, and organizational security policies * Collaborate with ISSOs, system administrators, and developers to remediate vulnerabilities * Support continuous monitoring ...
Ensure systems comply with NIST, RMF, and organizational security policies * Collaborate with ISSOs, system administrators, and developers to remediate vulnerabilities * Support continuous monitoring ...
Develop, implement, review, and maintain IT security controls in accordance with NIST SP 800-53, RMF, and agency security policies. * Support the preparation, review, and submission of Security ...
Develop, implement, review, and maintain IT security controls in accordance with NIST SP 800-53, RMF, and agency security policies. * Support the preparation, review, and submission of Security ...
IA frameworks (NIST RMF, FISMA, NIST SP 800 series) into clear, actionable outputs for UK Government stakeholders Provide analytical assurance support to ensure outputs are coherent, complete, and ...
IA frameworks (NIST RMF, FISMA, NIST SP 800 series) into clear, actionable outputs for UK Government stakeholders Provide analytical assurance support to ensure outputs are coherent, complete, and ...
STIGs NIST RMF Monitoring endpoint health and activity to identify potential risks Investigating endpoint security findings and coordinating remediation efforts Agile Collaboration & Workflow ...
STIGs NIST RMF Monitoring endpoint health and activity to identify potential risks Investigating endpoint security findings and coordinating remediation efforts Agile Collaboration & Workflow ...
Maintain working knowledge of DoD, DCSA, and NIST RMF guidance and policies * Perform SSP reviews in accordance with the plan * Use critical thinking to aid decision-making and highlight paths that ...
Maintain working knowledge of DoD, DCSA, and NIST RMF guidance and policies * Perform SSP reviews in accordance with the plan * Use critical thinking to aid decision-making and highlight paths that ...
Develop, implement, review, and maintain IT security controls in accordance with NIST SP 800-53, RMF, and agency security policies. * Support the preparation, review, and submission of Security ...
Develop, implement, review, and maintain IT security controls in accordance with NIST SP 800-53, RMF, and agency security policies. * Support the preparation, review, and submission of Security ...
Knowledge of DoD cybersecurity frameworks (NIST, RMF). DoD 8570/8140 certification (e.g., Security+, CISSP). Preferred Qualifications: Experience supporting DoD cybersecurity programs. Familiarity ...
Knowledge of DoD cybersecurity frameworks (NIST, RMF). DoD 8570/8140 certification (e.g., Security+, CISSP). Preferred Qualifications: Experience supporting DoD cybersecurity programs. Familiarity ...
Lead and support assessment teams conducting FedRAMP, DoD SRG, and NIST RMF security assessments . * Review Security Packages (SSP, SAP, SAR, POA&M, Deviation Requests, Significant Change Requests ...
New
Lead and support assessment teams conducting FedRAMP, DoD SRG, and NIST RMF security assessments . * Review Security Packages (SSP, SAP, SAR, POA&M, Deviation Requests, Significant Change Requests ...
New
Develop, implement, review, and maintain IT security controls in accordance with NIST SP 800-53, RMF, and agency security policies. * Support the preparation, review, and submission of Security ...
Develop, implement, review, and maintain IT security controls in accordance with NIST SP 800-53, RMF, and agency security policies. * Support the preparation, review, and submission of Security ...
Cloud Cybersecurity Manager (CCM)
$118K - $160K/yr
Eight or more years of experience with NIST RMF, NIST SP 800-53, STIGs, SCAP, IAVAs, and FISMA. * One or more of the following certifications: CISM, CISSO, FITSP-M, GCIA, GCSA, GCIH, GSLC, GICSP ...
Cloud Cybersecurity Manager (CCM)
$118K - $160K/yr
Eight or more years of experience with NIST RMF, NIST SP 800-53, STIGs, SCAP, IAVAs, and FISMA. * One or more of the following certifications: CISM, CISSO, FITSP-M, GCIA, GCSA, GCIH, GSLC, GICSP ...
Ensure assigned systems remain aligned with NIST RMF, NIST SP 800-53, FISMA, and agency cybersecurity requirements. * Support and maintain reporting dashboards, status tracking, and collaboration ...
Ensure assigned systems remain aligned with NIST RMF, NIST SP 800-53, FISMA, and agency cybersecurity requirements. * Support and maintain reporting dashboards, status tracking, and collaboration ...
Ensure assigned systems remain aligned with NIST RMF, NIST SP 800-53, FISMA, and agency cybersecurity requirements. * Support and maintain reporting dashboards, status tracking, and collaboration ...
Ensure assigned systems remain aligned with NIST RMF, NIST SP 800-53, FISMA, and agency cybersecurity requirements. * Support and maintain reporting dashboards, status tracking, and collaboration ...
Nist Rmf information
See salary details
$43K - $52.7K
1% of jobs
$52.7K - $62.5K
6% of jobs
$62.5K - $72.2K
10% of jobs
$78.8K is the 25th percentile. Wages below this are outliers.
$72.2K - $81.9K
12% of jobs
$81.9K - $91.6K
15% of jobs
The median wage is $95.8K / yr.
$91.6K - $101.4K
15% of jobs
$101.4K - $111.1K
10% of jobs
$115.3K is the 75th percentile. Wages above this are outliers.
$111.1K - $120.8K
16% of jobs
$120.8K - $130.5K
7% of jobs
$130.5K - $140.3K
5% of jobs
$140.3K - $150K
3% of jobs
$43K
$99.4K
$150K
How much do nist rmf jobs pay per year?
What is NIST RMF?
What is the difference between Nist Rmf vs Cybersecurity Analyst?
| Aspect | Nist Rmf | Cybersecurity Analyst |
|---|---|---|
| Certifications | Risk Management Framework (RMF) certifications, NIST guidelines | CompTIA Security+, CISSP, CEH |
| Work Environment | Government agencies, federal projects, compliance-focused | Private sector, IT departments, security teams |
| Industry Usage | Primarily in federal and defense sectors | Across various industries including finance, healthcare, tech |
| Primary Focus | Implementing and managing risk management frameworks | Monitoring, analyzing, and responding to security threats |
While Nist Rmf specialists focus on establishing and maintaining risk management processes based on NIST standards, Cybersecurity Analysts are more involved in threat detection and incident response. Both roles require security knowledge but serve different functions within cybersecurity frameworks.
What are some typical challenges faced by professionals implementing the NIST RMF in an organization?
What are the key skills and qualifications needed to thrive as a NIST RMF (Risk Management Framework) specialist, and why are they important?

Full-time
Medical, Dental, Vision, Retirement, PTO
This job post has expired today. Applications are no longer accepted.
Job description
Goldbelt Nighthawk offers sound solutions in software development and both defensive and proactive cybersecurity. Nighthawk offers an integrated, holistic cybersecurity workforce that is enthusiastic, continuously learning, and progressive. The team is fully committed to implementing dynamic cybersecurity solutions that effectively address the needs of customers. Nighthawk's flexibility and expertise across the cybersecurity field provides customized solutions to our customer's unique needs.
Summary:
The Security Control Assessor - Representative will perform a risk-based review and evaluation A&A process for classified systems to evaluate system security plans (SSPs) leading to an authorization decision. There is a requirement to be onsite at customer facility in Hanover, MD three days per week and could be increased to five days per week, depending on the government requirements.
Responsibilities
Essential Job Functions:
- Maintain expert-level knowledge of all NIST 800-53 Security Controls
- Maintain working knowledge of DoD, DCSA, and NIST RMF guidance and policies
- Perform SSP reviews in accordance with the plan
- Use critical thinking to aid decision-making and highlight paths that will help achieve desired outcomes during risk-based analysis
- Assess SSPs, document the findings, and make recommendations
- Review and evaluate A&A artifacts in submission documentation
- Provide information security services such as system security documentation evaluation and other support activities connected with the implementation of the Risk Management Framework (RMF)
- Evaluate system security package submissions for authorization of classified systems against defined DCSA and Government technical standards.
- Acquire and maintain NISP eMASS account for daily use
- Attend and participate in training on the NISP eMASS tool
- Be familiar with the NIST RMF and be able to process and track packages through the NISP Enterprise Mission Assurance Support Service (eMASS).
- Use NISP eMASS as an approved repository for artifacts and Plans of Action and Milestones (POA&M)
- Provide written documentation for each SSP review that includes:
Qualifications
Necessary Skills and Knowledge:
- Cybersecurity experience
- Proficiency in Microsoft Office Suite
- Working knowledge and skills in eMASS
Minimum Qualifications:
- Certified at IAT II (CCNA Security, CSA+, GICSP, GSEC, Security+ CE, SSCP)
- 3-5 yrs. experience in information protection, threat protection, architecture, or system security operations
- Approved personnel with Secret clearance
- Pass an employer background check
- Experience in vulnerability and risk assessment, architecture, and network configuration
Preferred Qualifications:
- Computer Science, information technology or cyber security degree or 5-7 year work experience in IAT I and II environment
- eMASS skills
- Process engineering
Pay and Benefits
At Goldbelt, we value and reward our team's dedication and hard work. We provide a competitive base salary commensurate with your qualifications and experience. As an employee, you'll enjoy a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.