This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF and Cybersecurity Assessment Expertise: Provides subject matter expertise on implementation and ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF and Cybersecurity Assessment Expertise: Provides subject matter expertise on implementation and ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... Coordinates with CS analysts, policy specialists, and RMF practitioners to ensure consistent ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... Coordinates with CS analysts, policy specialists, and RMF practitioners to ensure consistent ...
Cyber Security Specialist
Herndon, VA · Remote
Remote Clearance Required: Top Secret with SCI eligibility Position type: Full-time About VivSoft ... Support RMF activities, including system authorization (ATO), control validation, and continuous ...
New
Quick apply
Cyber Security Specialist
Herndon, VA · Remote
Remote Clearance Required: Top Secret with SCI eligibility Position type: Full-time About VivSoft ... Support RMF activities, including system authorization (ATO), control validation, and continuous ...
New
Manager, Cyber Security
Reston, VA · Remote
$115.50K - $156.10K/yr
... require RMF alignment, assessment documentation, POA&M management, contingency planning ... This position is remote within the United States. Please note that ICF monitors employee work ...
Manager, Cyber Security
Reston, VA · Remote
$115.50K - $156.10K/yr
... require RMF alignment, assessment documentation, POA&M management, contingency planning ... This position is remote within the United States. Please note that ICF monitors employee work ...
Splunk Dashboard Engineer #1749928
Mclean, VA · Remote
$57.75 - $71/hr
... RMF frameworks, providing Executives with top-level information needed for decision-making, and ... This position is remote with occasional travel to DC, MD, VA, WV, NJ, and OK. Qualifications and ...
Splunk Dashboard Engineer #1749928
Mclean, VA · Remote
$57.75 - $71/hr
... RMF frameworks, providing Executives with top-level information needed for decision-making, and ... This position is remote with occasional travel to DC, MD, VA, WV, NJ, and OK. Qualifications and ...
System Security Administrator - Remote
Ashburn, VA · On-site +1
Providing security analysis and remediation of security vulnerabilities for application using IBM ... RMF), and security compliance processes * Experience with Federal Information Security Management ...
System Security Administrator - Remote
Ashburn, VA · On-site +1
Providing security analysis and remediation of security vulnerabilities for application using IBM ... RMF), and security compliance processes * Experience with Federal Information Security Management ...
Task Order Project Manager (59843)
Fort Myer, VA · On-site +1
... Analyst (CS AAA) Support Services program. This is a fully remote position and contingent on ... RMF Program Management: Oversees contractor support activities associated with the Risk Management ...
Task Order Project Manager (59843)
Fort Myer, VA · On-site +1
... Analyst (CS AAA) Support Services program. This is a fully remote position and contingent on ... RMF Program Management: Oversees contractor support activities associated with the Risk Management ...
Cyber Action Officer
Arlington, VA · On-site +1
None Potential for Remote Work: ORA_ON_SITE Description SAIC is seeking qualified applicants to ... Apply DoW Risk Management Framework (RMF) and Zero Trust Architecture principles across the ...
Cyber Action Officer
Arlington, VA · On-site +1
None Potential for Remote Work: ORA_ON_SITE Description SAIC is seeking qualified applicants to ... Apply DoW Risk Management Framework (RMF) and Zero Trust Architecture principles across the ...
FCC - Lead Cybersecurity Engineer
Washington, DC · On-site +1
This position is remote. This position requires the ability a Public Trust clearance ... Strong understanding of NIST frameworks, RMF, and federal cybersecurity standards * Expertise in ...
FCC - Lead Cybersecurity Engineer
Washington, DC · On-site +1
This position is remote. This position requires the ability a Public Trust clearance ... Strong understanding of NIST frameworks, RMF, and federal cybersecurity standards * Expertise in ...
This position is remote. This position requires the ability a Public Trust clearance ... Strong understanding of NIST frameworks, RMF, and federal cybersecurity standards * Expertise in ...
Quick apply
This position is remote. This position requires the ability a Public Trust clearance ... Strong understanding of NIST frameworks, RMF, and federal cybersecurity standards * Expertise in ...
Implement graph traversal queries for gap analysis (risk dimension unaddressed controls), tier ... NIST AI RMF, ISO 42001, NIST CSF, OWASP LLM Top 10, OWASP Agentic Top 10, MITRE ATLAS, OSCAL.
New
Implement graph traversal queries for gap analysis (risk dimension unaddressed controls), tier ... NIST AI RMF, ISO 42001, NIST CSF, OWASP LLM Top 10, OWASP Agentic Top 10, MITRE ATLAS, OSCAL.
New
Senior CMMC SME Engineer with Security Clearance
Washington, DC · Remote
$129.20K - $177.20K/yr
Remote-first with occasional onsite customer engagements Location: Washington, DC Clearance ... GCC High engineering Microsoft 365 security CMMC readiness NIST SP 800-171 RMF operationalization ...
New
Senior CMMC SME Engineer with Security Clearance
Washington, DC · Remote
$129.20K - $177.20K/yr
Remote-first with occasional onsite customer engagements Location: Washington, DC Clearance ... GCC High engineering Microsoft 365 security CMMC readiness NIST SP 800-171 RMF operationalization ...
New
DLP Cybersecurity Engineer Remote Secret or Top Secret
Washington, DC · Remote
$140K - $180K/yr
... File Content Analysis (FCA) program. This role will support the continued enhancement and ... RMF / ATO documentation experience for DLP solutions, particularly cloud-based with DoD reciprocity ...
Quick apply
DLP Cybersecurity Engineer Remote Secret or Top Secret
Washington, DC · Remote
$140K - $180K/yr
... File Content Analysis (FCA) program. This role will support the continued enhancement and ... RMF / ATO documentation experience for DLP solutions, particularly cloud-based with DoD reciprocity ...
DLP Cybersecurity Engineer Remote Secret or Top Secret
Washington, DC · Remote
$140K - $180K/yr
... File Content Analysis (FCA) program. This role will support the continued enhancement and ... RMF / ATO documentation experience for DLP solutions, particularly cloud-based with DoD reciprocity ...
DLP Cybersecurity Engineer Remote Secret or Top Secret
Washington, DC · Remote
$140K - $180K/yr
... File Content Analysis (FCA) program. This role will support the continued enhancement and ... RMF / ATO documentation experience for DLP solutions, particularly cloud-based with DoD reciprocity ...
FCC - Vulnerability Management Lead
Washington, DC · On-site +1
This position is remote. This position requires the ability a Public Trust clearance ... Strong analytical, problem-solving, and communication skills. * Required Certifications * Relevant ...
FCC - Vulnerability Management Lead
Washington, DC · On-site +1
This position is remote. This position requires the ability a Public Trust clearance ... Strong analytical, problem-solving, and communication skills. * Required Certifications * Relevant ...
This position is remote. This position requires the ability a Public Trust clearance ... Strong analytical, problem-solving, and communication skills. * Required Certifications * Relevant ...
Quick apply
This position is remote. This position requires the ability a Public Trust clearance ... Strong analytical, problem-solving, and communication skills. * Required Certifications * Relevant ...
Sr. Cybersecurity OT SME
Washington, DC · On-site +1
Support forensic analysis and recovery planning for cyber-physical systems. * Stakeholder ... Strong knowledge of NIST SP 800-82, ISA/IEC 62443, and RMF. * U.S. Citizenship; Public Trust ...
Sr. Cybersecurity OT SME
Washington, DC · On-site +1
Support forensic analysis and recovery planning for cyber-physical systems. * Stakeholder ... Strong knowledge of NIST SP 800-82, ISA/IEC 62443, and RMF. * U.S. Citizenship; Public Trust ...
Remote Cloud Data Engineer (Must have experience with Pyspark) with Security Clearance
Fort George G Meade, MD · Remote
$127K - $152.50K/yr
... analytics within secure DoD environments. The ideal candidate will have strong experience ... RMF, STIG, FedRAMP, and DoD security standards Utilize Oracle databases and cloud-native tools to ...
Remote Cloud Data Engineer (Must have experience with Pyspark) with Security Clearance
Fort George G Meade, MD · Remote
$127K - $152.50K/yr
... analytics within secure DoD environments. The ideal candidate will have strong experience ... RMF, STIG, FedRAMP, and DoD security standards Utilize Oracle databases and cloud-native tools to ...
DevSecOps Engineer
Arlington, VA · Remote
This is a fully remote position. Here, your work is more than a job - it's a journey in innovation ... Familiarity with Zero Trust, RMF, and DISA STIG compliance * Hands-on experience with monitoring ...
Quick apply
DevSecOps Engineer
Arlington, VA · Remote
This is a fully remote position. Here, your work is more than a job - it's a journey in innovation ... Familiarity with Zero Trust, RMF, and DISA STIG compliance * Hands-on experience with monitoring ...
DevSecOps Engineer
Arlington, VA · On-site +1
This is a fully remote position. Here, your work is more than a job - it's a journey in innovation ... Familiarity with Zero Trust, RMF, and DISA STIG compliance * Hands-on experience with monitoring ...
DevSecOps Engineer
Arlington, VA · On-site +1
This is a fully remote position. Here, your work is more than a job - it's a journey in innovation ... Familiarity with Zero Trust, RMF, and DISA STIG compliance * Hands-on experience with monitoring ...
Remote Rmf Analyst information
See Silver Spring, MD salary details
$40.8K - $50.4K
1% of jobs
$50.4K - $59.9K
3% of jobs
$59.9K - $69.5K
4% of jobs
$69.5K - $79K
5% of jobs
$79K - $88.5K
6% of jobs
$96.1K is the 25th percentile. Wages below this are outliers.
$88.5K - $98.1K
6% of jobs
$98.1K - $107.6K
5% of jobs
The median wage is $113.2K / yr.
$107.6K - $117.1K
32% of jobs
$117.1K - $126.7K
3% of jobs
$129.3K is the 75th percentile. Wages above this are outliers.
$126.7K - $136.2K
32% of jobs
$136.2K - $145.8K
2% of jobs
$40.8K
$111K
$145.8K
How much do remote rmf analyst jobs pay per year?
What is the difference between Remote Rmf Analyst vs Remote Rmf Reviewer?
| Aspect | Remote Rmf Analyst | Remote Rmf Reviewer |
|---|---|---|
| Credentials | Typically requires a degree in life sciences, healthcare, or related field; certifications like RAC or RAC-ML are common | Similar credentials as Rmf Analyst, often with additional experience in review processes |
| Work Environment | Performs analysis, risk assessments, and compliance evaluations remotely for pharmaceutical or biotech companies | Focuses on reviewing and validating RMF documents and reports remotely within regulatory teams |
| Employer & Industry | Pharmaceutical, biotech, or medical device companies | Regulatory consulting firms, pharmaceutical companies, or biotech firms |
The main difference is that Remote Rmf Analysts conduct risk assessments and analysis, while Remote Rmf Reviewers focus on reviewing and validating risk management files. Both roles require similar credentials and work in the same industry, but their responsibilities differ in scope and focus.
Cybersecurity Subject Matter Expert Lead (59834)
Beshenich & Muir AssociatesFort Myer, VA • On-site, Remote
Full-time
Medical, Dental, Vision, Retirement
Posted 24 days ago
Job description
Job Summary
BMA is seeking a Cybersecurity Subject Matter Expert (CS SME) - Lead to support our DLA Cybersecurity Policy and Oversight Support Services (CPOSS) contract. The CS SME - Lead provides senior-level technical leadership and advisory support to the CPOSS program supporting DLA's J6/J611 Cybersecurity Directorate. The SME serves as the principal cybersecurity authority for complex technical and governance challenges related to the enterprise Risk Management Framework (RMF) program, cybersecurity policy development, continuous monitoring, and control validation activities across the DLA enterprise. Working under consultative direction, the SME independently evaluates exceptionally complex cybersecurity issues, develops innovative solutions, and provides authoritative technical guidance to government leadership, Security Control Assessors (SCAs), Authorizing Officials (AOs), and enterprise cybersecurity stakeholders. The role also contributes to the development of enterprise cybersecurity methodologies, advanced assessment techniques, and improved cybersecurity governance practices aligned with DoD cybersecurity policy and DLA strategic initiatives.
Key Responsibilities
- Enterprise Cybersecurity Technical Leadership: Serves as the senior technical advisor to the DLA cybersecurity assessment and oversight program, providing expert interpretation of cybersecurity policies, standards, and technical requirements. Provides authoritative guidance on complex cybersecurity issues involving enterprise systems, networks, applications, enclaves, and emerging technologies. Analyzes highly complex cybersecurity challenges and recommends innovative solutions that balance mission requirements, operational risks, and regulatory compliance.
- RMF and Cybersecurity Assessment Expertise: Provides subject matter expertise on implementation and governance of the DoDI 8510.01 Risk Management Framework for DoD IT across DLA information systems. Advises government stakeholders on security control validation, risk assessments, and authorization readiness determinations. Provides technical review of security control assessments, continuous monitoring activities, and RMF authorization packages submitted through eMASS. Supports development of enterprise-level recommendations regarding residual risk acceptance and cybersecurity posture improvements.
- Cybersecurity Tools, Standards, and Architecture Support: Evaluates cybersecurity tools and technologies to support enterprise security assessment, monitoring, and compliance activities. Recommends cybersecurity software solutions and assists in defining functional and technical requirements for tool selection. Supports development of product-specific Security Technical Implementation Guides (STIGs) based on Defense Information Systems Agency Security Requirements Guides (SRGs). Provides technical leadership in evaluating network security architectures, vulnerability assessment methodologies, and cybersecurity implementation strategies.
- Enterprise Cybersecurity Policy and Methodology Development: Contributes to the development of new cybersecurity principles, methodologies, and governance practices that improve the DLA enterprise cybersecurity program. Provides expert guidance in the development and refinement of enterprise cybersecurity policies, directives, and standard operating procedures supporting the CPOSS program. Supports the development of advanced cybersecurity concepts and technical approaches that strengthen enterprise security posture and compliance with DoD cybersecurity regulations.
- Strategic Analysis and Innovation: Conducts research and analysis of emerging cybersecurity threats, technologies, and best practices relevant to the DLA mission environment. Develops innovative approaches for improving cybersecurity assessment processes, continuous monitoring practices, and enterprise risk management strategies. Identifies opportunities to enhance cybersecurity oversight capabilities through improved tools, automation, analytics, and governance frameworks.
- Senior-Level Advisory and Communication Support: Provides expert written and oral briefings to senior government leadership regarding cybersecurity risks, program status, and recommended solutions. Prepares technical reports, white papers, and presentations addressing enterprise cybersecurity challenges.
Clearance Requirements
There is a Secret Security clearance requirement for this position.
Required Skills & Certifications
- Current DoD 8670.01/8140 IAM Level III certification that includes one or more of the following: ISACA CISM, ISC2 Certified Information Systems Security Professional (CISSP), GIAC/SANS GIAS Security Leadership Certification (GSLC), or EC-Council Certified Chief Information Security Officer (CCISO).
- 7+ years of Information Technology experience.
- 5+ years of Information Assurance / Cybersecurity experience.
- Demonstrated expertise in cybersecurity assessment methodologies, risk analysis, and enterprise cybersecurity governance.
- Strong analytical and problem-solving skills with the ability to resolve complex cybersecurity challenges.
- In-depth knowledge of DoD cybersecurity regulations and guidance, including RMF implementation.
- Strong familiarity with Defense Information Systems Agency STIGs and Security Requirements Guides (SRGs).
- Demonstrated ability to develop and evaluate cybersecurity technologies, architectures, and security solutions.
- Exceptional technical leadership and independent decision-making ability.
- Ability to translate complex cybersecurity issues into clear, actionable guidance for senior leadership.
- Strong written and oral communication skills capable of supporting executive-level briefings.
- Proven ability to innovate and develop new cybersecurity concepts, processes, and technical solutions.
- Demonstrated ability to work independently toward long-range cybersecurity program objectives.
Desired Skills & Certifications
- Experience supporting DoD or DLA program offices.
- Experience supporting DoD DLA environments.
- Experience leading enterprise-level cyber modernization initiatives.
- Familiarity with DLA-specific cybersecurity governance frameworks.
- Current Project Management Professional (PMP) certification.
- Current Risk Management Professional certification such as one or more of the following: PMP-RMP, ISACA Certified in Risk and Information Systems Control (CRISC), ISACA Certified Information Systems Auditor (CISA), ISACA Certified Information Security Manager (CISM), ISC2 Certified in Governance, Risk and Compliance (CGRC), or Risk and Insurance Management Society (RIMS) Certified Risk Management Professional (RIMS-CRMP).
Other Duties
- Able to travel within a week's notice.
- This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job.
- Duties, responsibilities, and activities may change at any time with or without notice.
Overview
BMA is an employee-owned small business headquartered in Huntsville, AL that provides superior customer service by empowering all levels of our staff to make timely decisions to produce high-quality results. BMA fosters an environment of passion, precision, and dedication in order to fulfill our commitments to our partners, government, and country.
Benefits
We believe that our employees well-being is paramount to our success so our benefits package has been crafted with that in mind. We offer multiple healthcare coverage options to include low deductible, high deductible, and plans eligible for our Health Savings Account (HSA) option. Along with medical coverage, employees have dental, vision, accident & illness, short- and long-term disability all available to them. BMA proudly maintains a 401(k) plan with an industry leading 6% match that can include profit sharing based on company performance. Lastly, being an employee-owned company means that BMA offers a 100% Employee Stock Ownership Plan (ESOP), providing eligible employees the opportunity to earn stock in BMA, subject to plan eligibility and vesting requirements.
AAP & EEO Statement
Beshenich Muir & Associates, LLC (BMA) is an Equal opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, religious creed, gender, sexual orientation, gender identity, gender expression, transgender, pregnancy, marital status, national origin, ancestry, citizenship status, age, disability, protected Veteran Status, genetics or any other characteristics protected by applicable Federal, State, or Local Law.