1

Nist Rmf Jobs (NOW HIRING)

Lead and support FedRAMP Moderate/High and IC ATO authorization efforts, ensuring compliance with NIST RMF, NIST 800-53, NIST 800-37, FedRAMP, and ICD 503 requirements. * Conduct risk assessments ...

Security Engineer

Mclean, VA · On-site

$150K - $200K/yr

Lead and support FedRAMP Moderate/High and IC ATO authorization efforts, ensuring compliance with NIST RMF, NIST 800-53, NIST 800-37, FedRAMP, and ICD 503 requirements. * Conduct risk assessments ...

IT Security SME

Los Angeles, CA · On-site

$48 - $53/hr

Support the Risk Management Framework (RMF) processes and system authorization lifecycle. * Create systems baseline using NIST 800-53 security controls. * Develop, review, and maintain security ...

Cyber Command, MC&FP, NIST RMF, Zero Trust, STIG/SRG, ACAS, and eMASS requirements while supporting the attainment and sustainment of Government-issued Authorizations to Operate (ATOs). An active ...

New

Showing results 41-60

Nist Rmf information

See salary details

$43K

$99.4K

$150K

How much do nist rmf jobs pay per year?

As of Aug 22, 2026, the average yearly pay for nist rmf in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What is NIST RMF?

NIST RMF stands for the National Institute of Standards and Technology Risk Management Framework. It is a structured process used by federal agencies and organizations to identify, assess, and manage cybersecurity risks to information systems. The RMF provides a set of steps that guide organizations through the selection, implementation, assessment, and monitoring of security controls to ensure systems meet required security standards. This framework is essential for achieving compliance with federal cybersecurity requirements and improving overall information security.

What are the key skills and qualifications needed to thrive as a NIST RMF specialist?

To thrive as a NIST RMF specialist, you need a solid understanding of information security principles, risk assessment, compliance standards, and often a background in cybersecurity or IT, supported by certifications like CISSP, CAP, or Security+. Familiarity with NIST SP 800-37, eMASS, and other GRC (Governance, Risk, and Compliance) tools is typically required. Attention to detail, analytical thinking, and strong communication skills help professionals navigate complex regulatory requirements and effectively collaborate with stakeholders. These skills are essential for ensuring organizational compliance, safeguarding sensitive data, and managing security risks efficiently.

What are some typical challenges faced by professionals implementing the NIST RMF in an organization?

Professionals working with the NIST Risk Management Framework (RMF) often encounter challenges such as aligning organizational processes with RMF requirements, ensuring stakeholder buy-in, and maintaining comprehensive documentation. Adapting legacy systems to meet modern security controls can be complex, and coordinating efforts across multiple teams—such as IT, compliance, and management—requires strong communication skills. Staying current with evolving NIST guidelines and integrating continuous monitoring into daily operations are also important aspects to manage for success in this role.

What is the difference between Nist Rmf vs Cybersecurity Analyst?

AspectNist RmfCybersecurity Analyst
CertificationsRisk Management Framework (RMF) certifications, NIST guidelinesCompTIA Security+, CISSP, CEH
Work EnvironmentGovernment agencies, federal projects, compliance-focusedPrivate sector, IT departments, security teams
Industry UsagePrimarily in federal and defense sectorsAcross various industries including finance, healthcare, tech
Primary FocusImplementing and managing risk management frameworksMonitoring, analyzing, and responding to security threats

While Nist Rmf specialists focus on establishing and maintaining risk management processes based on NIST standards, Cybersecurity Analysts are more involved in threat detection and incident response. Both roles require security knowledge but serve different functions within cybersecurity frameworks.

More about Nist Rmf jobs

What states have the most Nist Rmf jobs?

States with the most job openings for Nist Rmf jobs include:

What job categories do people searching Nist Rmf jobs look for?

The top searched job categories for Nist Rmf jobs are:

Infographic showing various Nist Rmf job openings in the United States as of August 2026, with employment types broken down into 75% Full Time, and 25% Contract. Highlights an 100% In-person job distribution, with an average salary of $99,400 per year, or $47.8 per hour.

$130K - $159K/yr

Full-time

Posted 11 days ago


Job description

RMF Engineer
Innovatus Technology Consulting
Location: San Diego, CA or Norfolk/Suffolk, VA area (Hybrid - mostly remote)
Clearance: Active DoD Secret clearance (minimum) required
About Innovatus Technology Consulting
Innovatus Technology Consulting is a Service-Disabled Veteran-Owned Small Business (SDVOSB) headquartered in San Diego, California. Founded in 2012, we deliver mission-critical IT, cybersecurity, cloud engineering, and engineering solutions to Department of Defense and federal customers. Guided by ethics, experience, and expertise, we help defense organizations achieve operational readiness through secure, compliant, and innovative technology solutions.
Position Overview
Innovatus is seeking an experienced Risk Management Framework (RMF) Engineer to support Assessment & Authorization (A&A) activities for DoD systems in accordance with NIST and DoD RMF requirements. The role focuses on developing, maintaining, and managing RMF documentation and artifacts throughout the system lifecycle. This is a hybrid position that is mostly remote, with candidates based in the San Diego, CA or Norfolk/Suffolk, VA areas preferred to support occasional on-site collaboration, meetings, or program needs.
Key Responsibilities
  • Support system categorization by identifying information types, system boundaries, and information flows.
  • Develop, update, and maintain RMF artifacts, including System Security Plans (SSPs), Contingency Plans (CPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Continuous Monitoring Strategies, and supporting diagrams.
  • Assess and evaluate implemented security controls; identify gaps and work with engineering and cybersecurity teams on remediation.
  • Manage and validate RMF packages in eMASS (or equivalent DoD tools), including uploading artifacts and tracking authorization status.
  • Support continuous monitoring, ATO package preparation, and authorization/renewal processes.
  • Collaborate with system engineers, ISSOs/ISSMs, Security Control Assessors, Authorizing Officials, and government stakeholders.
  • Provide guidance on NIST SP 800-53 controls, DoD cybersecurity policies, STIGs, and RMF best practices.
  • Contribute to risk assessments, vulnerability management coordination, and compliance documentation as needed.
Required Qualifications
  • Active DoD Secret security clearance (minimum).
  • U.S. citizenship.
  • 3+ years of hands-on experience supporting DoD RMF processes and A&A activities.
  • Proven experience developing RMF artifacts (SSPs, CPs, control evidence, test plans, POA&Ms, etc.).
  • Strong familiarity with NIST SP 800-53, RMF steps (per NIST SP 800-37 / DoDI 8510.01), and authorization workflows.
  • Experience with eMASS (or similar authorization management systems) for package management and artifact validation.
  • Ability to work independently in a mostly remote environment while collaborating effectively with distributed teams.
  • Strong written and verbal communication skills for technical documentation and stakeholder interaction.
Preferred Qualifications
  • Experience supporting Navy, NAVWAR, or other DoD component systems.
  • Familiarity with additional tools such as ACAS, Nessus, or STIG Viewer.
  • Relevant certifications (e.g., CAP, Security+, CISSP, CISM, or DoD 8570/8140 IAM Level I/II).
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
What We Offer
  • Competitive salary and benefits package.
  • Mostly remote hybrid flexibility with work-life balance.
  • Opportunity to support high-impact DoD missions.
  • Professional growth in a mission-driven, veteran-friendly SDVOSB environment.
  • Collaborative culture focused on ethics, expertise, and results.