This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF Execution: Supports execution of all phases of the RMF authorization process, including system ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF Execution: Supports execution of all phases of the RMF authorization process, including system ...
This is a fully remote position. Come join our great team in the ongoing effort to strengthen and ... This is your opportunity to act as an information security and RMF subject matter expert while ...
This is a fully remote position. Come join our great team in the ongoing effort to strengthen and ... This is your opportunity to act as an information security and RMF subject matter expert while ...
Senior ATO Security Analyst
Manassas, VA · Remote
$90K - $117K/yr
This is a fully remote position. Come join our great team in the ongoing effort to strengthen and ... This is your opportunity to act as an information security and RMF subject matter expert while ...
Senior ATO Security Analyst
Manassas, VA · Remote
$90K - $117K/yr
This is a fully remote position. Come join our great team in the ongoing effort to strengthen and ... This is your opportunity to act as an information security and RMF subject matter expert while ...
Business Analyst (Senior)
Herndon, VA · Remote
$80K - $128K/yr
This position is remote and requires an active Secret clearance. Provide senior business analysis ... Familiarity with NIST RMF, ATO processes, and DoD security compliance frameworks. * CompTIA ...
Business Analyst (Senior)
Herndon, VA · Remote
$80K - $128K/yr
This position is remote and requires an active Secret clearance. Provide senior business analysis ... Familiarity with NIST RMF, ATO processes, and DoD security compliance frameworks. * CompTIA ...
Lead Consultant, Cybersecurity (Remote)
Washington, DC · On-site +1
$80/hr
RMF implementation and sustainment. * A&A package development and maintenance. * Security control ... Conduct analysis of vulnerability data, scan results, remediation status, and compliance findings.
Lead Consultant, Cybersecurity (Remote)
Washington, DC · On-site +1
$80/hr
RMF implementation and sustainment. * A&A package development and maintenance. * Security control ... Conduct analysis of vulnerability data, scan results, remediation status, and compliance findings.
Lead Consultant, Cybersecurity (Remote)
Washington, DC · Remote
$80/hr
RMF implementation and sustainment. * A&A package development and maintenance. * Security control ... Conduct analysis of vulnerability data, scan results, remediation status, and compliance findings.
Lead Consultant, Cybersecurity (Remote)
Washington, DC · Remote
$80/hr
RMF implementation and sustainment. * A&A package development and maintenance. * Security control ... Conduct analysis of vulnerability data, scan results, remediation status, and compliance findings.
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF authorization packages, supporting documentation, and system security artifacts. Analyze ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF authorization packages, supporting documentation, and system security artifacts. Analyze ...
FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Cybersecurity Systems Analyst
Herndon, VA · On-site +1
FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Cybersecurity Systems Analyst
Herndon, VA · On-site +1
FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
We are currently seeking a Business Analyst - Product Owner to join our team in Bethesda (REMOTE ... Knowledge of DoD cybersecurity, privacy, and RMF requirements for IL4/IL5 systems. * Experience ...
We are currently seeking a Business Analyst - Product Owner to join our team in Bethesda (REMOTE ... Knowledge of DoD cybersecurity, privacy, and RMF requirements for IL4/IL5 systems. * Experience ...
Cybersecurity Systems Analyst
Herndon, VA · On-site +1
FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Cybersecurity Systems Analyst
Herndon, VA · On-site +1
FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Cyber Risk Analyst SME
Arlington, VA · On-site +1
This role involves conducting on-site and remote cyber risk assessments, developing mitigation ... Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal ...
Cyber Risk Analyst SME
Arlington, VA · On-site +1
This role involves conducting on-site and remote cyber risk assessments, developing mitigation ... Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal ...
System Technical Security Analyst
Herndon, VA · On-site +1
Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
System Technical Security Analyst
Herndon, VA · On-site +1
Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
If you are a roll-up-your-sleeves security leader who can speak RMF, NIST 800-53, Cloud SRG ... We have several ISSM job opportunities offering either a remote or hybrid commute around the ...
If you are a roll-up-your-sleeves security leader who can speak RMF, NIST 800-53, Cloud SRG ... We have several ISSM job opportunities offering either a remote or hybrid commute around the ...
Security risk assessment and analysis ... NIST frameworks (RMF, CSF, 800-53) implementation * Vulnerability assessment and penetration ...
Quick apply
Security risk assessment and analysis ... NIST frameworks (RMF, CSF, 800-53) implementation * Vulnerability assessment and penetration ...
Software Engineer (Senior)
Herndon, VA · Remote
$104K - $166K/yr
... RMF/ATO alignment. This position is remote and requires an active Secret clearance. Responsible for ... Provides technical leadership to cross functional teams (UX, analytics, security), defines ...
Software Engineer (Senior)
Herndon, VA · Remote
$104K - $166K/yr
... RMF/ATO alignment. This position is remote and requires an active Secret clearance. Responsible for ... Provides technical leadership to cross functional teams (UX, analytics, security), defines ...
Software Engineer Senior
Herndon, VA · Remote
$104K - $166K/yr
... RMF/ATO alignment. This position is remote and requires an active Secret clearance ... Provides technical leadership to cross functional teams (UX, analytics, security), defines ...
Software Engineer Senior
Herndon, VA · Remote
$104K - $166K/yr
... RMF/ATO alignment. This position is remote and requires an active Secret clearance ... Provides technical leadership to cross functional teams (UX, analytics, security), defines ...
Software Engineer (Senior)
Reston, VA · Remote
$104K - $166K/yr
... RMF/ATO alignment. This position is remote and requires an active Secret clearance. Responsible for ... Provides technical leadership to cross functional teams (UX, analytics, security), defines ...
Software Engineer (Senior)
Reston, VA · Remote
$104K - $166K/yr
... RMF/ATO alignment. This position is remote and requires an active Secret clearance. Responsible for ... Provides technical leadership to cross functional teams (UX, analytics, security), defines ...
Remote Rmf Analyst information
See Washington, DC salary details
$44.7K - $55.2K
1% of jobs
$55.2K - $65.6K
3% of jobs
$65.6K - $76.1K
4% of jobs
$76.1K - $86.5K
5% of jobs
$86.5K - $97K
6% of jobs
$105.3K is the 25th percentile. Wages below this are outliers.
$97K - $107.4K
6% of jobs
$107.4K - $117.9K
5% of jobs
The median wage is $124K / yr.
$117.9K - $128.3K
32% of jobs
$128.3K - $138.8K
3% of jobs
$141.7K is the 75th percentile. Wages above this are outliers.
$138.8K - $149.2K
32% of jobs
$149.2K - $159.7K
2% of jobs
$44.7K
$121.6K
$159.7K
How much do remote rmf analyst jobs pay per year?
What is the difference between Remote Rmf Analyst vs Remote Rmf Reviewer?
| Aspect | Remote Rmf Analyst | Remote Rmf Reviewer |
|---|---|---|
| Credentials | Typically requires a degree in life sciences, healthcare, or related field; certifications like RAC or RAC-ML are common | Similar credentials as Rmf Analyst, often with additional experience in review processes |
| Work Environment | Performs analysis, risk assessments, and compliance evaluations remotely for pharmaceutical or biotech companies | Focuses on reviewing and validating RMF documents and reports remotely within regulatory teams |
| Employer & Industry | Pharmaceutical, biotech, or medical device companies | Regulatory consulting firms, pharmaceutical companies, or biotech firms |
The main difference is that Remote Rmf Analysts conduct risk assessments and analysis, while Remote Rmf Reviewers focus on reviewing and validating risk management files. Both roles require similar credentials and work in the same industry, but their responsibilities differ in scope and focus.

Cybersecurity Certification & Accreditation Analyst Lead (59788)
Beshenich & Muir AssociatesFort Myer, VA • On-site, Remote
Full-time
Medical, Dental, Vision, Retirement
Posted 15 days ago
Job description
Job Summary
BMA is seeking a Cybersecurity Certification and Accreditation (C&A) Analyst to support our DLA Cybersecurity Assessment and Authorization Analyst (CS AAA) Support Services contract. The analyst serves as a cybersecurity Subject Matter Expert (SME) supporting the DLA J6 Cybersecurity Program, providing technical expertise in the authorization of information systems and cybersecurity compliance activities across DLA's enterprise IT and Operational Technology (OT) environments. This role supports the assessment, authorization, and continuous monitoring of information systems under the Risk Management Framework (RMF) and ensures compliance with DoD cybersecurity policies, federal information security regulations, and DLA cybersecurity implementation guidance. The analyst performs cybersecurity validation activities throughout the DoD System Development Life Cycle (SDLC) and assists program offices, Information System Security Managers (ISSMs), and Authorizing Officials (AOs) in maintaining the security posture of DLA systems. The position supports complex enterprise environments including large and small enclaves, applications, and outsourced IT services, ensuring security controls are implemented, assessed, and monitored in accordance with NIST SP 800-53, DoD cybersecurity policy, and the DLA RMF Implementation Process Guide.
Key Responsibilities include but are not limited to:
- Cybersecurity Assessment and Authorization Support: Provides cybersecurity subject matter expertise supporting authorization and accreditation activities for DLA information systems. Assists ISSMs and AOs with implementation of the DoD Risk Management Framework throughout the system development lifecycle, conducts security control reviews and authorization package analysis, and supports cybersecurity activities across IT, Platform IT (PIT), and Operational Technology / Facility Related Control Systems environments.
- RMF Execution: Supports execution of all phases of the RMF authorization process, including system categorization, security control selection, implementation validation, security control assessment, authorization, and continuous monitoring. Assists in the development and maintenance of RMF documentation and supports system registration and cybersecurity documentation management within the Enterprise Mission Assurance Support Service environment.
- Security Control Assessment and Compliance Validation: Evaluates the implementation and effectiveness of security controls defined in NIST SP 800-53 and DoD cybersecurity guidance. Conducts security control validation reviews, identifies non-compliant controls and vulnerabilities, determines severity levels, assesses impacts to system authorization status, and provides mitigation strategies and remediation recommendations.
- Cybersecurity Risk Analysis and Vulnerability Management: Analyzes security findings and vulnerabilities identified through cybersecurity assessments and scanning tools. Determines the operational and security impact of vulnerabilities on system authorization and risk posture, supports remediation activities, tracks vulnerabilities through Plans of Action and Milestones (POA&M), and assists with monitoring vulnerabilities identified through ACAS scans and IAVA alerts.
- Documentation, Reporting, and Briefings: Develops cybersecurity assessment documentation supporting system authorization packages, maintains documentation repositories for system and organizational artifacts, prepares and delivers briefings to government stakeholders and senior leadership, and provides cybersecurity status reports and recommendations to Program Managers, ISSMs, and Authorizing Officials.
- Cybersecurity Program Coordination: Coordinates cybersecurity activities with program offices, system managers, and security personnel across the DLA enterprise to support effective execution of authorization and compliance efforts.
Clearance Requirements
There is a Secret Security clearance requirement for this position.
Required Skills & Certifications
- Current DoD 8570.01/8140 IAM Level III certification that includes one or more of the following: CISM, CISSP, GSLC, or CCISO.
- Five or more years of relevant Certification and Accreditation (C&A) and/or RMF cybersecurity experience.
- Demonstrated experience supporting DoD cybersecurity programs and system authorization processes.
- Strong understanding of Risk Management Framework (RMF) implementation and NIST cybersecurity standards.
- Experience assessing security controls and conducting authorization reviews within large, complex enterprise environments.
- Ability to evaluate vulnerabilities, assess risk, and determine impacts to system authorization status.
- Strong analytical, technical documentation, and communication skills.
Desired Skills & Certifications
- Experience supporting DoD or DLA program offices.
- Experience supporting DoD or DLA environments.
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, Business Administration, or a related field.
- Five or more years of leadership experience with progressively increasing responsibility managing technical teams, programs, or contracts.
- At least one year of program or project management experience.
- Current Project Management Professional (PMP) certification or an equivalent recognized project management certification.
- Current Risk Management Professional certification such as PMP-RMP, CRISC, CISA, CISM, CGRC, or RIMS-CRMP.
Other Duties
- Able to travel within a week's notice.
- This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job.
- Duties, responsibilities, and activities may change at any time with or without notice.
Overview
BMA is an employee-owned small business headquartered in Huntsville, AL that provides superior customer service by empowering all levels of our staff to make timely decisions to produce high-quality results. BMA fosters an environment of passion, precision, and dedication in order to fulfill our commitments to our partners, government, and country.
Benefits
We believe that our employees well-being is paramount to our success so our benefits package has been crafted with that in mind. We offer multiple healthcare coverage options to include low deductible, high deductible, and plans eligible for our Health Savings Account (HSA) option. Along with medical coverage, employees have dental, vision, accident & illness, short- and long-term disability all available to them. BMA proudly maintains a 401(k) plan with an industry leading 6% match that can include profit sharing based on company performance. Lastly, being an employee-owned company means that BMA offers a 100% Employee Stock Ownership Plan (ESOP), providing eligible employees the opportunity to earn stock in BMA, subject to plan eligibility and vesting requirements.
AAP & EEO Statement
Beshenich Muir & Associates, LLC (BMA) is an Equal opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, religious creed, gender, sexual orientation, gender identity, gender expression, transgender, pregnancy, marital status, national origin, ancestry, citizenship status, age, disability, protected Veteran Status, genetics or any other characteristics protected by applicable Federal, State, or Local Law.