2

Remote Rmf Analyst Jobs in Virginia (NOW HIRING)

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

... RMF) activities for enterprise information systems. The ISSO serves as the primary cybersecurity ... Remote Key Responsibilities * Serve as the primary cybersecurity and privacy advisor to System ...

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

... RMF) activities for enterprise information systems. The ISSO serves as the primary cybersecurity ... Remote Key Responsibilities * Serve as the primary cybersecurity and privacy advisor to System ...

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

... RMF) activities for enterprise information systems. The ISSO serves as the primary cybersecurity ... Remote Key Responsibilities * Serve as the primary cybersecurity and privacy advisor to System ...

Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...

This role involves conducting on-site and remote cyber risk assessments, developing mitigation ... Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal ...

Senior Information Security Engineer

Reston, VA · Remote

$110K - $150K/yr

... RMF) activities for enterprise information systems. The ISSO serves as the primary cybersecurity ... Remote Key Responsibilities * Serve as the primary cybersecurity and privacy advisor to System ...

Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...

... RMF Step 4. * Good communication skills and have good interpersonal, organizational, and analytical ... For Remote Opportunities), education and certifications as well as Federal Government Contract ...

OWASP AI Testing Guide, NIST AI Risk Management Framework (AI RMF), NIST Cybersecurity Framework ... Exposure to AI-assisted defect triage or root-cause analysis tools that reduce manual investigation ...

Cybersecurity Engineer - ISSO

Vienna, VA · On-site +1

$160K - $200K/yr

None Potential for Remote Work: ORA_ON_SITE Description SAIC is seeking a Cyber Security Engineer ... Execute RMF processes for Assessment & Authorization (A&A). * Develop/maintain SSPs, POA&Ms, SARs ...

Manager, Cyber Security

Reston, VA · Remote

$115K - $156K/yr

... require RMF alignment, assessment documentation, POA&M management, contingency planning ... This position is remote within the United States. Please note that ICF monitors employee work ...

IA Engineer

Chantilly, VA · On-site +1

$99K - $225K/yr

... analysis * Ability to decompose RMF security requirements such as DoD JSIG, DAAG, or ICD-503 into ... Remote : If this position is listed as remote, there may still be occasions when you are required ...

Showing results 21-40

Remote Rmf Analyst information

What is the difference between Remote Rmf Analyst vs Remote Rmf Reviewer?

AspectRemote Rmf AnalystRemote Rmf Reviewer
CredentialsTypically requires a degree in life sciences, healthcare, or related field; certifications like RAC or RAC-ML are commonSimilar credentials as Rmf Analyst, often with additional experience in review processes
Work EnvironmentPerforms analysis, risk assessments, and compliance evaluations remotely for pharmaceutical or biotech companiesFocuses on reviewing and validating RMF documents and reports remotely within regulatory teams
Employer & IndustryPharmaceutical, biotech, or medical device companiesRegulatory consulting firms, pharmaceutical companies, or biotech firms

The main difference is that Remote Rmf Analysts conduct risk assessments and analysis, while Remote Rmf Reviewers focus on reviewing and validating risk management files. Both roles require similar credentials and work in the same industry, but their responsibilities differ in scope and focus.

What job categories do people searching Remote Rmf Analyst jobs in Virginia look for?

The top searched job categories for Remote Rmf Analyst jobs in Virginia are:

What cities in Virginia are hiring for Remote Rmf Analyst jobs?

Cities in Virginia with the most Remote Rmf Analyst job openings:

Infographic showing various Remote Rmf Analyst job openings in Virginia as of September 2026, with employment types broken down into 1% Internship, 83% Full Time, 10% Part Time, 1% Temporary, 4% Contract, and 1% Nights. Highlights an 79% Physical, 8% Hybrid, and 13% Remote job distribution.

Senior Information Security Engineer

Reston, VA • Remote

$110K - $150K/yr

Full-time

Posted 20 days ago


Key responsibilities

  • Lead RMF activities by developing and maintaining System Security and Privacy Plans, authorization packages, and risk documentation.

  • Assess security risks, validate security controls, and coordinate remediation of vulnerabilities and Plans of Action and Milestones (POA&Ms).

  • Collaborate with stakeholders to ensure security and privacy requirements are integrated throughout the system lifecycle and maintain compliance with federal regulations.


ASRC Federal rating

7.8

Company rating: 7.8 out of 10

Based on 28 frontline employees who took The Breakroom Quiz


Job description

ASRC Federal Data Networx is seeking a Senior Information System Security Officer (ISSO) to support federal cybersecurity and Risk Management Framework (RMF) activities for enterprise information systems. The ISSO serves as the primary cybersecurity and privacy advisor to System Owners (SOs), ensuring security and privacy requirements are integrated throughout the system lifecycle while maintaining compliance with federal regulations and Authorization to Operate (ATO) requirements.

Work Location: Remote

Key Responsibilities

  • Serve as the primary cybersecurity and privacy advisor to System Owners for assigned systems.
  • Lead RMF activities, including development and maintenance of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts.
  • Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements.
  • Assess security risks, validate security controls, and coordinate remediation of vulnerabilities and Plans of Action and Milestones (POA&Ms).
  • Maintain system inventories, security documentation, contingency plans, configuration management plans, and privacy documentation.
  • Collaborate with ISSMs, System Owners, Security Control Assessors, and technical teams to integrate security throughout the system lifecycle.
  • Monitor system security posture, review vulnerability and compliance scan results, and support continuous authorization initiatives.
  • Provide cybersecurity guidance, develop security policies and procedures, and deliver security awareness training.
  • Support security engineering, certification and accreditation activities, and implementation of security controls across systems.
  • Recommend process improvements and automation opportunities to enhance RMF and cybersecurity operations.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field.
  • Minimum 5–7 years of experience supporting information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience.
  • Experience supporting federal cybersecurity programs and the NIST Risk Management Framework (RMF).
  • Experience developing and maintaining RMF documentation, authorization packages, and Governance, Risk, and Compliance (GRC) tools.
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy requirements.
  • Experience supporting Authorization to Operate (ATO), Continuous ATO (cATO), or Continuous Authorization efforts.
  • Strong analytical, communication, documentation, and stakeholder engagement skills.

Required Certifications

  • Certified Information Systems Security Professional (CISSP)
  • Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP)

Preferred Qualifications

  • Experience supporting U.S. federal civilian agencies, preferably the USPTO.
  • Experience with continuous monitoring, vulnerability management, and security automation.
  • Familiarity with cloud security, DevSecOps, and continuous authorization initiatives.
  • Knowledge of privacy compliance activities, including Privacy Threshold Assessments (PTAs), Privacy Impact Assessments (PIAs), and System of Records Notices (SORNs).

What ASRC Federal employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom