2

Remote Rmf Analyst Jobs in Washington, DC (NOW HIRING)

Cybersecurity Program Manager

Reston, VA · Remote

$115K - $156K/yr

Remote Key Responsibilities * Serve as the primary cybersecurity and privacy advisor to System ... Lead RMF activities, including development and maintenance of System Security and Privacy Plans ...

Remote / Alexandria, VA Clearance: Preferred US Gov Secret or above clearance (not a hard ... Integrate static code analysis (SAST), dynamic testing (DAST), container scanning and various ...

OWASP AI Testing Guide, NIST AI Risk Management Framework (AI RMF), NIST Cybersecurity Framework ... Exposure to AI-assisted defect triage or root-cause analysis tools that reduce manual investigation ...

OWASP AI Testing Guide, NIST AI Risk Management Framework (AI RMF), NIST Cybersecurity Framework ... Exposure to AI-assisted defect triage or root-cause analysis tools that reduce manual investigation ...

Cybersecurity Engineer - ISSO

Vienna, VA · On-site +1

$160K - $200K/yr

None Potential for Remote Work: ORA_ON_SITE Description SAIC is seeking a Cyber Security Engineer ... Execute RMF processes for Assessment & Authorization (A&A). * Develop/maintain SSPs, POA&Ms, SARs ...

Dive into innovation in Digital Transformation, Cybersecurity, IT, Data Analytics and Software ... This role supports Authorization and Accreditation (A&A), Risk Management Framework (RMF) ATO ...

Manager, Cyber Security

Reston, VA · Remote

$115K - $156K/yr

... require RMF alignment, assessment documentation, POA&M management, contingency planning ... This position is remote within the United States. Please note that ICF monitors employee work ...

IA Engineer

Chantilly, VA · On-site +1

$99K - $225K/yr

... analysis * Ability to decompose RMF security requirements such as DoD JSIG, DAAG, or ICD-503 into ... Remote : If this position is listed as remote, there may still be occasions when you are required ...

Security Compliance Architect

VA · On-site +1

$65.25 - $84.25/hr

This role leads to RMF activities, develops authorization artifacts, and ensures adherence to ... design, analysis, and development of secure enterprise IT systems and architecture solutions ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...

Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation ... NIST RMF (800-37) and NIST SP 800-53 Rev. 5 * JCAM methodology * Experience reviewing security ...

Showing results 41-60

Remote Rmf Analyst information

See Washington, DC salary details

$44.7K

$121.6K

$159.7K

How much do remote rmf analyst jobs pay per year?

As of Sep 7, 2026, the average yearly pay for remote rmf analyst in Washington, DC is $121,566.00, according to ZipRecruiter salary data. Most workers in this role earn between $103,600.00 and $147,200.00 per year, depending on experience, location, and employer.

What is the difference between Remote Rmf Analyst vs Remote Rmf Reviewer?

AspectRemote Rmf AnalystRemote Rmf Reviewer
CredentialsTypically requires a degree in life sciences, healthcare, or related field; certifications like RAC or RAC-ML are commonSimilar credentials as Rmf Analyst, often with additional experience in review processes
Work EnvironmentPerforms analysis, risk assessments, and compliance evaluations remotely for pharmaceutical or biotech companiesFocuses on reviewing and validating RMF documents and reports remotely within regulatory teams
Employer & IndustryPharmaceutical, biotech, or medical device companiesRegulatory consulting firms, pharmaceutical companies, or biotech firms

The main difference is that Remote Rmf Analysts conduct risk assessments and analysis, while Remote Rmf Reviewers focus on reviewing and validating risk management files. Both roles require similar credentials and work in the same industry, but their responsibilities differ in scope and focus.

What are the most commonly searched types of Rmf Analyst jobs in Washington, DC?

The most popular types of Rmf Analyst jobs in Washington, DC are:

What job categories do people searching Remote Rmf Analyst jobs in Washington, DC look for?

The top searched job categories for Remote Rmf Analyst jobs in Washington, DC are:

Infographic showing various Remote Rmf Analyst job openings in Washington, DC as of August 2026, with employment types broken down into 75% Full Time, and 25% Part Time. Highlights an 100% Remote job distribution, with an average salary of $121,566 per year, or $58.4 per hour.

Cybersecurity Program Manager

asrcfh

Reston, VA • Remote

$115K - $156K/yr

Full-time

This job post has expired today. Applications are no longer accepted.


ASRC Federal rating

7.8

Company rating: 7.8 out of 10

Based on 28 frontline employees who took The Breakroom Quiz

244th of 453 rated engineering


Job description

ASRC Federal Data Networx is seeking a Cybersecurity Program Manager to oversee federal cybersecurity program.

Work Location: Remote

Key Responsibilities

  • Serve as the primary cybersecurity and privacy advisor to System Owners for assigned systems.
  • Lead RMF activities, including development and maintenance of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts.
  • Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements.
  • Assess security risks, validate security controls, and coordinate remediation of vulnerabilities and Plans of Action and Milestones (POA&Ms).
  • Maintain system inventories, security documentation, contingency plans, configuration management plans, and privacy documentation.
  • Collaborate with ISSMs, System Owners, Security Control Assessors, and technical teams to integrate security throughout the system lifecycle.
  • Monitor system security posture, review vulnerability and compliance scan results, and support continuous authorization initiatives.
  • Provide cybersecurity guidance, develop security policies and procedures, and deliver security awareness training.
  • Support security engineering, certification and accreditation activities, and implementation of security controls across systems.
  • Recommend process improvements and automation opportunities to enhance RMF and cybersecurity operations.
  • Perform independent quality assurance reviews of program performance and deliverables to ensure that contractual obligations are being met.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field.
  • Minimum 5–7 years of experience supporting information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience.
  • Experience supporting federal cybersecurity programs and the NIST Risk Management Framework (RMF).
  • Experience developing and maintaining RMF documentation, authorization packages, and Governance, Risk, and Compliance (GRC) tools.
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy requirements.
  • Experience supporting Authorization to Operate (ATO), Continuous ATO (cATO), or Continuous Authorization efforts.
  • Strong analytical, communication, documentation, and stakeholder engagement skills.
  • Expertise in cybersecurity processes and protection of technical architecture.

Required Certifications

  • Certified Information Systems Security Professional (CISSP)
  • Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP)

Preferred Qualifications

  • Experience supporting U.S. federal civilian agencies, preferably the USPTO.
  • Experience with continuous monitoring, vulnerability management, and security automation.
  • Familiarity with cloud security, DevSecOps, and continuous authorization initiatives.
  • Knowledge of privacy compliance activities, including Privacy Threshold Assessments (PTAs), Privacy Impact Assessments (PIAs), and System of Records Notices (SORNs).

What ASRC Federal employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom