This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF authorization packages, supporting documentation, and system security artifacts. Analyze ...
This is a fully remote position and contingent on contract award. Job Summary BMA is seeking a ... RMF authorization packages, supporting documentation, and system security artifacts. Analyze ...
Remote: Cobol Developer with Hogan
Dallas, TX · Remote
$49.75 - $67.25/hr
Exciting Remote Cobol Developer with Hogan contract opportunity. Requirements Design, code, test ... RMF) Comfortable in Agile/Scrum development environment Excellent analytical, problem-solving and ...
Remote: Cobol Developer with Hogan
Dallas, TX · Remote
$49.75 - $67.25/hr
Exciting Remote Cobol Developer with Hogan contract opportunity. Requirements Design, code, test ... RMF) Comfortable in Agile/Scrum development environment Excellent analytical, problem-solving and ...
FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Cybersecurity Systems Analyst
Herndon, VA · On-site +1
FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Cybersecurity Systems Analyst
Herndon, VA · On-site +1
FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Remote: Cobol Developer with Hogan
Dallas, TX · Remote
$51.50 - $69.50/hr
Exciting Remote Cobol Developer with Hogan contract opportunity. Requirements • Design, code ... RMF) • Comfortable in Agile/Scrum development environment • Excellent analytical, problem ...
Quick apply
Remote: Cobol Developer with Hogan
Dallas, TX · Remote
$51.50 - $69.50/hr
Exciting Remote Cobol Developer with Hogan contract opportunity. Requirements • Design, code ... RMF) • Comfortable in Agile/Scrum development environment • Excellent analytical, problem ...
Senior Cybersecurity Compliance Analyst
OR · On-site +1
$93K - $121K/yr
This is a full-time remote position with occasional on-site support (Beltsville, MD or Reston, VA ... Support enterprise-level compliance with NIST 800-53 security and privacy controls. * Assist in RMF ...
Senior Cybersecurity Compliance Analyst
OR · On-site +1
$93K - $121K/yr
This is a full-time remote position with occasional on-site support (Beltsville, MD or Reston, VA ... Support enterprise-level compliance with NIST 800-53 security and privacy controls. * Assist in RMF ...
Senior Cybersecurity Compliance Analyst
Myrtle Point, OR · Remote
$93K - $121K/yr
This is a full-time remote position with occasional on-site support (Beltsville, MD or Reston, VA ... Support enterprise-level compliance with NIST 800-53 security and privacy controls. * Assist in RMF ...
Senior Cybersecurity Compliance Analyst
Myrtle Point, OR · Remote
$93K - $121K/yr
This is a full-time remote position with occasional on-site support (Beltsville, MD or Reston, VA ... Support enterprise-level compliance with NIST 800-53 security and privacy controls. * Assist in RMF ...
We are currently seeking a Business Analyst - Product Owner to join our team in Bethesda (REMOTE ... Knowledge of DoD cybersecurity, privacy, and RMF requirements for IL4/IL5 systems. * Experience ...
We are currently seeking a Business Analyst - Product Owner to join our team in Bethesda (REMOTE ... Knowledge of DoD cybersecurity, privacy, and RMF requirements for IL4/IL5 systems. * Experience ...
Remote: Cobol Developer with Hogan
Dallas, TX · On-site +1
$49.75 - $67.25/hr
Exciting Remote Cobol Developer with Hogan contract opportunity. Requirements • Design, code ... RMF) • Comfortable in Agile/Scrum development environment • Excellent analytical, problem ...
Remote: Cobol Developer with Hogan
Dallas, TX · On-site +1
$49.75 - $67.25/hr
Exciting Remote Cobol Developer with Hogan contract opportunity. Requirements • Design, code ... RMF) • Comfortable in Agile/Scrum development environment • Excellent analytical, problem ...
Cybersecurity Systems Analyst
Herndon, VA · On-site +1
FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Cybersecurity Systems Analyst
Herndon, VA · On-site +1
FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Gartner analysts are industry thought leaders who create must-have insight and provide advice to a ... NIST AI RMF * Understanding of geopolitical and sovereign workloads requirements in different ...
Gartner analysts are industry thought leaders who create must-have insight and provide advice to a ... NIST AI RMF * Understanding of geopolitical and sovereign workloads requirements in different ...
Gartner analysts are industry thought leaders who create must-have insight and provide advice to a ... NIST AI RMF * Understanding of geopolitical and sovereign workloads requirements in different ...
Gartner analysts are industry thought leaders who create must-have insight and provide advice to a ... NIST AI RMF * Understanding of geopolitical and sovereign workloads requirements in different ...
Cyber Risk Analyst SME
Arlington, VA · On-site +1
This role involves conducting on-site and remote cyber risk assessments, developing mitigation ... Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal ...
Cyber Risk Analyst SME
Arlington, VA · On-site +1
This role involves conducting on-site and remote cyber risk assessments, developing mitigation ... Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal ...
System Technical Security Analyst
Herndon, VA · On-site +1
Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
System Technical Security Analyst
Herndon, VA · On-site +1
Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
RMF subject matter expertise * A&A authorization experience * IV&V cybersecurity validation ... Provide expert analysis of residual risk and authorization recommendations * Provide oversight of ...
RMF subject matter expertise * A&A authorization experience * IV&V cybersecurity validation ... Provide expert analysis of residual risk and authorization recommendations * Provide oversight of ...
Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... Identify and assess Cloud System state, including vulnerabilities, RMF package status/accreditation ...
If you are a roll-up-your-sleeves security leader who can speak RMF, NIST 800-53, Cloud SRG ... We have several ISSM job opportunities offering either a remote or hybrid commute around the ...
If you are a roll-up-your-sleeves security leader who can speak RMF, NIST 800-53, Cloud SRG ... We have several ISSM job opportunities offering either a remote or hybrid commute around the ...
RMF subject matter expertise * A&A authorization experience * IV&V cybersecurity validation ... Provide expert analysis of residual risk and authorization recommendations * Provide oversight of ...
RMF subject matter expertise * A&A authorization experience * IV&V cybersecurity validation ... Provide expert analysis of residual risk and authorization recommendations * Provide oversight of ...
Subject Matter Expert (SME) - Computer Systems Analyst
Lakewood, CO · On-site +1
$128K - $149K/yr
Support RMF security documentation and ATO packages. * Evaluate system performance and recommend ... Remote (Virtual) - US - US Education Bachelor's Degree
Subject Matter Expert (SME) - Computer Systems Analyst
Lakewood, CO · On-site +1
$128K - $149K/yr
Support RMF security documentation and ATO packages. * Evaluate system performance and recommend ... Remote (Virtual) - US - US Education Bachelor's Degree
Remote Rmf Analyst information
See salary details
$39.5K - $48.7K
1% of jobs
$48.7K - $58K
3% of jobs
$58K - $67.2K
4% of jobs
$67.2K - $76.4K
5% of jobs
$76.4K - $85.6K
6% of jobs
$92.9K is the 25th percentile. Wages below this are outliers.
$85.6K - $94.9K
6% of jobs
$94.9K - $104.1K
5% of jobs
The median wage is $109.5K / yr.
$104.1K - $113.3K
32% of jobs
$113.3K - $122.5K
3% of jobs
$125.1K is the 75th percentile. Wages above this are outliers.
$122.5K - $131.8K
32% of jobs
$131.8K - $141K
2% of jobs
$39.5K
$107.3K
$141K
How much do remote rmf analyst jobs pay per year?
What is the difference between Remote Rmf Analyst vs Remote Rmf Reviewer?
| Aspect | Remote Rmf Analyst | Remote Rmf Reviewer |
|---|---|---|
| Credentials | Typically requires a degree in life sciences, healthcare, or related field; certifications like RAC or RAC-ML are common | Similar credentials as Rmf Analyst, often with additional experience in review processes |
| Work Environment | Performs analysis, risk assessments, and compliance evaluations remotely for pharmaceutical or biotech companies | Focuses on reviewing and validating RMF documents and reports remotely within regulatory teams |
| Employer & Industry | Pharmaceutical, biotech, or medical device companies | Regulatory consulting firms, pharmaceutical companies, or biotech firms |
The main difference is that Remote Rmf Analysts conduct risk assessments and analysis, while Remote Rmf Reviewers focus on reviewing and validating risk management files. Both roles require similar credentials and work in the same industry, but their responsibilities differ in scope and focus.

Control Validation Security Specialist Senior (59833)
Beshenich & Muir AssociatesFort Myer, VA • On-site, Remote
Full-time
Medical, Dental, Vision, Retirement
Posted 9 days ago
Job description
Job Summary
BMA is seeking a Control Validation Security Specialist - Senior to support our DLA Cybersecurity Policy and Oversight Support Services (CPOSS) contract. The position provides advanced cybersecurity assessment and validation support to the CPOSS program supporting DLA's J6/J611 Cybersecurity Directorate. The specialist independently conducts information system security control validation, RMF authorization package reviews, and enterprise cybersecurity assessments across DLA systems, networks, applications, and enclaves. This role ensures cybersecurity controls are properly implemented, operating effectively, and compliant with Federal, DoD, and DLA cybersecurity policies. The specialist performs technical evaluations of cybersecurity posture, analyzes system risks, validates mitigation strategies, and provides recommendations to strengthen enterprise security while balancing operational mission requirements. Working in support of the Security Control Assessor (SCA) Representative Team, the position contributes to enterprise RMF authorization oversight, continuous monitoring verification, and cybersecurity policy compliance activities across classified and unclassified environments.
Key Responsibilities
- Cybersecurity Control Validation and IT Audit Support: Independently perform information system security control validation and IT audit activities across complex information systems, applications, networks, and enclaves. Verify that cybersecurity controls are properly implemented, configured correctly, and operating in accordance with federal and DoD cybersecurity requirements. Conduct cybersecurity assessments to determine whether implemented controls effectively protect systems from unauthorized access, misuse, or destruction. Validate compliance with cybersecurity policies and standards applicable to DLA enterprise systems.
- RMF Authorization and Security Assessment Support: Support the enterprise RMF authorization process in accordance with DoDI 8510.01 RMF for DoD IT. Perform technical reviews of RMF authorization packages, supporting documentation, and system security artifacts. Analyze residual risk and determine whether implemented security controls satisfy security requirements and authorization standards. Assist in preparing security assessment reports and authorization recommendations for review by the Security Control Assessor and Authorizing Official.
- Continuous Monitoring and Vulnerability Analysis: Conduct cybersecurity control validation exercises on classified and unclassified systems to verify the effectiveness of implemented security measures. Perform vulnerability assessments and analyze security weaknesses to identify potential threats to enterprise systems. Evaluate remediation activities and mitigation strategies to determine whether corrective actions adequately address security findings. Support enterprise continuous monitoring initiatives and cybersecurity risk analysis.
- Security Analysis and Technical Evaluation: Perform technical evaluations of customer systems to identify security weaknesses and recommend improvements to strengthen cybersecurity posture. Analyze network security configurations and system architectures to verify secure implementation of cybersecurity controls. Provide recommendations for improving cybersecurity controls, risk mitigation strategies, and security implementation practices. Balance mission requirements with cybersecurity controls by evaluating operational needs against risk considerations.
- Documentation, Reporting, and Coordination: Document findings from security control assessments, audits, and validation activities in formal reports and assessment summaries. Prepare technical documentation and supporting evidence to support RMF reviews and cybersecurity compliance activities. Coordinate with program managers, system managers, and Information System Security Managers to resolve cybersecurity issues and improve security compliance. Participate in cybersecurity working groups, technical reviews, and enterprise cybersecurity coordination meetings.
Clearance Requirements
There is a Secret Security clearance requirement for this position.
Required Skills & Certifications
- Current DoD 8670.01/8140 IAM Level III certification that includes one or more of the following: ISACA CISM, ISC2 Certified Information Systems Security Professional (CISSP), GIAC/SANS GIAS Security Leadership Certification (GSLC), or EC-Council Certified Chief Information Security Officer (CCISO).
- 3+ years of experience working with DoD cybersecurity policy such as DoD 8500-series or NIST SP 800-53, with strong understanding of Risk Management Framework (RMF) principles and processes.
- 2+ years of experience using Enterprise Mission Assurance Support Service (eMASS) to support RMF authorization activities and security documentation tracking.
- Demonstrated ability to perform independent IT audits and security control validation across complex enterprise environments.
- Strong analytical and problem-solving skills with the ability to identify cybersecurity vulnerabilities and recommend appropriate mitigations.
- Proficiency with Microsoft Office tools, including Excel, Access, Word, and PowerPoint, for cybersecurity analysis and reporting.
- Strong knowledge of network architecture and network security implementation.
- Strong written and oral communication skills capable of supporting executive-level briefings.
- Ability to balance mission objectives with cybersecurity risk management.
- Must be eligible for IT-II designation upon assignment.
Desired Skills & Certifications
- Experience supporting DoD or DLA program offices.
- Experience supporting DoD DLA environments.
- Experience leading enterprise-level cyber modernization initiatives.
- Familiarity with DLA-specific cybersecurity governance frameworks.
- Current Project Management Professional (PMP) certification.
- Current Risk Management Professional certification such as one or more of the following: PMP-RMP, ISACA Certified in Risk and Information Systems Control (CRISC), ISACA Certified Information Systems Auditor (CISA), ISACA Certified Information Security Manager (CISM), ISC2 Certified in Governance, Risk and Compliance (CGRC), or Risk and Insurance Management Society (RIMS) Certified Risk Management Professional (RIMS-CRMP).
Other Duties
- Able to travel within a week's notice.
- This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job.
- Duties, responsibilities, and activities may change at any time with or without notice.
Overview
BMA is an employee-owned small business headquartered in Huntsville, AL that provides superior customer service by empowering all levels of our staff to make timely decisions to produce high-quality results. BMA fosters an environment of passion, precision, and dedication in order to fulfill our commitments to our partners, government, and country.
Benefits
We believe that our employees well-being is paramount to our success so our benefits package has been crafted with that in mind. We offer multiple healthcare coverage options to include low deductible, high deductible, and plans eligible for our Health Savings Account (HSA) option. Along with medical coverage, employees have dental, vision, accident & illness, short- and long-term disability all available to them. BMA proudly maintains a 401(k) plan with an industry leading 6% match that can include profit sharing based on company performance. Lastly, being an employee-owned company means that BMA offers a 100% Employee Stock Ownership Plan (ESOP), providing eligible employees the opportunity to earn stock in BMA, subject to plan eligibility and vesting requirements.
AAP & EEO Statement
Beshenich Muir & Associates, LLC (BMA) is an Equal opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, religious creed, gender, sexual orientation, gender identity, gender expression, transgender, pregnancy, marital status, national origin, ancestry, citizenship status, age, disability, protected Veteran Status, genetics or any other characteristics protected by applicable Federal, State, or Local Law.