2

Remote Rmf Analyst Jobs in Silver Spring, MD (NOW HIRING)

Your work will align with FISMA, NIST RMF for Federal Civilian Agencies, RMF for DoD IT, FedRAMP ... Work independently or as part of a client delivery team in a fast-paced, deadline-driven, remote ...

... Remote Country United States Working time Full-time Description & Requirements We are seeking a ... RMF, FedRAMP, and DoD requirements. The successful candidate will collaborate closely with ...

FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...

FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...

next page

Showing results 1-20

Remote Rmf Analyst information

See Silver Spring, MD salary details

$40.8K

$111K

$145.8K

How much do remote rmf analyst jobs pay per year?

As of May 30, 2026, the average yearly pay for remote rmf analyst in Silver Spring, MD is $110,960.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,600.00 and $134,400.00 per year, depending on experience, location, and employer.

What is the difference between Remote Rmf Analyst vs Remote Rmf Reviewer?

AspectRemote Rmf AnalystRemote Rmf Reviewer
CredentialsTypically requires a degree in life sciences, healthcare, or related field; certifications like RAC or RAC-ML are commonSimilar credentials as Rmf Analyst, often with additional experience in review processes
Work EnvironmentPerforms analysis, risk assessments, and compliance evaluations remotely for pharmaceutical or biotech companiesFocuses on reviewing and validating RMF documents and reports remotely within regulatory teams
Employer & IndustryPharmaceutical, biotech, or medical device companiesRegulatory consulting firms, pharmaceutical companies, or biotech firms

The main difference is that Remote Rmf Analysts conduct risk assessments and analysis, while Remote Rmf Reviewers focus on reviewing and validating risk management files. Both roles require similar credentials and work in the same industry, but their responsibilities differ in scope and focus.

What are popular job titles related to Remote Rmf Analyst jobs in Silver Spring, MD? For Remote Rmf Analyst jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Remote Rmf Analyst jobs in Silver Spring, MD look for? The top searched job categories for Remote Rmf Analyst jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Remote Rmf Analyst jobs? Cities near Silver Spring, MD with the most Remote Rmf Analyst job openings:
FCC - Security Compliance / RMF Analyst

FCC - Security Compliance / RMF Analyst

cFocus Software Incorporated

Washington, DC • On-site, Remote

Full-time

Posted 25 days ago


Job description

cFocus Software seeks a Security Compliance / RMF Analyst to join our program supporting the Federal Communications Commission (FCC). This position is remote. This position requires the ability a Public Trust clearance.
Qualifications:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
  • Experience in cybersecurity compliance, RMF, risk management, or related environments.
  • Demonstrated experience supporting enterprise-level cybersecurity or compliance programs.
  • Experience working in complex IT environments with federal or regulated systems.
  • Strong knowledge of NIST RMF (SP 800-37) and NIST SP 800-53 controls.
  • Experience with A&A, ATO processes, and continuous monitoring.
  • Familiarity with GRC tools (e.g., Archer, Xacta, CSAM).
  • Experience with vulnerability management and risk prioritization.
  • Strong documentation and technical writing skills.
  • Analytical and problem-solving capabilities.
  • Ability to communicate effectively with technical and non-technical stakeholders
  • Required Certifications
    • Role-appropriate cybersecurity certification demonstrating competency in compliance, RMF, or risk management.
    • Examples include: Security+, CISA, CISSP (or equivalent certifications aligned with role responsibilities).
Duties:
  • Support RMF lifecycle activities including system authorization, reauthorization, and continuous monitoring.
  • Develop, maintain, and update security documentation (SSPs, SARs, POA&Ms, contingency plans).
  • Perform security control assessments (SCA) and control validation activities.
  • Track and manage POA&Ms, vulnerabilities, and remediation activities.
  • Conduct risk assessments, gap analyses, and compliance reviews.
  • Support FISMA, NIST SP 800-53, and other federal compliance requirements.
  • Coordinate with system owners, ISSOs, engineers, and auditors.
  • Support audit readiness and respond to internal/external audit requests.
  • Maintain RMF artifacts in GRC tools (e.g., Xacta, Archer, ServiceNow).
  • Assist with continuous monitoring, reporting, and compliance metrics development.