2

Remote Rmf Jobs in Georgia (NOW HIRING)

This is a fully remote position open to Contract or Full-Time candidates. Key Responsibilities * Conduct control assessments and gap analyses against frameworks including NIST CSF, NIST 800-53, ISO ...

New

Information Security Analyst

Atlanta, GA · On-site +1

$75K - $120K/yr

This role has a preference to be located in the Greater Atlanta Metro, but a fully remote candidate will be considered with the right skillset. How you'll make an impact: * Create and maintain ...

Due to an increase in fraudulent candidates, remote candidates will be considered on a case-by-case basis and only after passing an identity verification assessment. Candidates must live in and be ...

next page

Showing results 1-20

Remote Rmf information

What is a Remote RMF job?

A Remote RMF (Risk Management Framework) job involves managing cybersecurity risk and compliance for an organization while working remotely. Professionals in this role ensure that IT systems align with federal security standards, such as those outlined by NIST. Responsibilities may include conducting risk assessments, implementing security controls, and maintaining compliance documentation. Remote RMF specialists often work with government agencies, contractors, or private companies handling sensitive data. This position requires expertise in cybersecurity policies, risk management, and regulatory compliance.

What are the typical daily responsibilities of a Remote RMF Specialist?

As a Remote RMF Specialist, your daily responsibilities often include conducting security assessments, preparing and reviewing authorization packages, and ensuring ongoing compliance with federal information security standards. You'll collaborate with cross-functional teams to identify risks, develop mitigation strategies, and document security control implementations. Regular communication with stakeholders, participation in virtual meetings, and continual monitoring of systems and processes to ensure compliance are also core aspects of the job. This role leverages remote work tools to collaborate effectively with cybersecurity, IT, and compliance professionals across multiple locations.

What are the key skills and qualifications needed to thrive in the Remote Rmf position, and why are they important?

To thrive as a Remote RMF (Risk Management Framework) Specialist, you need a strong understanding of information security principles, federal risk management frameworks (such as NIST SP 800-37), and relevant cybersecurity policies, typically backed by a degree in information security or related field. Familiarity with security assessment tools, governance, risk, and compliance (GRC) software, as well as certifications like CISSP, CAP, or CISM, is highly valued. Excellent organizational skills, attention to detail, and the ability to communicate complex security concepts clearly are important soft skills. These capabilities are critical to ensure regulatory compliance and robust information system security in a remote work context.

What are popular job titles related to Remote Rmf jobs in Georgia? For Remote Rmf jobs in Georgia, the most frequently searched job titles are:
What cities in Georgia are hiring for Remote Rmf jobs? Cities in Georgia with the most Remote Rmf job openings:

GRC Analyst

Merci Technologies - Talent

Atlanta, GA • Remote

Full-time

Posted 2 days ago


Job description

About the Role
Merci Technologies is seeking a GRC Analyst to support the governance, risk, and compliance program for one of our enterprise clients. This role sits at the intersection of security, audit, and business operations, translating complex regulatory and framework requirements into practical controls that teams can actually implement and sustain. You will be the person who knows where the control gaps are, what the auditors are going to ask for, and how to keep the organization audit-ready year round rather than scrambling at assessment time.

The work is varied and visible. In a given month you might run a control assessment against NIST CSF, prepare evidence for a SOC 2 examination, complete a vendor risk review for a new SaaS purchase, and brief stakeholders on the status of open findings. You will maintain the policy library, track risk to closure, and act as a trusted advisor to engineering and business teams who need to understand what compliance requires of them. This is a strong fit for someone who is organized, detail-driven, and comfortable holding teams accountable to commitments. This is a fully remote position open to Contract or Full-Time candidates.

Key Responsibilities

  • Conduct control assessments and gap analyses against frameworks including NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CMMC
  • Plan and support internal and third-party audits, including scoping, evidence collection, and walkthroughs
  • Track audit and assessment findings to remediation and closure, escalating risks where needed
  • Develop, maintain, and version-control security policies, standards, and procedures
  • Perform vendor and third-party risk assessments and document risk acceptance decisions
  • Build and maintain the risk register and report risk posture to leadership and stakeholders
  • Support regulatory, customer, and compliance reporting requests
  • Help operationalize new framework or regulatory requirements as they emerge

Required Qualifications

  • 3 to 5 years of experience in governance, risk, and compliance, IT audit, or information security
  • Working knowledge of one or more frameworks: NIST CSF, NIST 800-53, ISO 27001, SOC 2, or CMMC
  • Demonstrated experience supporting audit cycles and risk assessments end to end
  • Ability to read a control requirement and translate it into clear, actionable guidance
  • Strong documentation, organization, and stakeholder communication skills

Preferred Qualifications

  • CISA, CRISC, ISO 27001 Lead Auditor, or CISSP certification
  • Hands-on experience with GRC platforms such as Archer, ServiceNow GRC, or OneTrust
  • Familiarity with defense, healthcare, or financial-services compliance requirements
  • Experience with CMMC readiness and assessment preparation

What You Will Bring
You are the kind of person who reads the fine print and keeps the spreadsheet honest. You can push a remediation owner for an update without burning the relationship, and you can explain to a busy engineer why a control matters in language they care about. You treat compliance as a way to make the organization genuinely more secure, not just to pass an audit.