2

Remote Rmf Jobs in Washington, DC (NOW HIRING)

Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF IT Security Analyst serves as a mid-level cybersecurity ...

New

DevSecOps Engineer - REMOTE

Bethesda, MD ยท Remote

$65K - $136K/yr

Knowledge of DoD RMF, IL4/IL5, and FedRAMP requirements for cybersecurity and compliance * Strong ... The starting pay range for this remote role is $65,592 - $136,650. This range reflects the minimum ...

next page

Showing results 1-20

Remote Rmf information

See Washington, DC salary details

$33.4K

$107.5K

$193.1K

How much do remote rmf jobs pay per year?

As of Jul 26, 2026, the average yearly pay for remote rmf in Washington, DC is $107,513.00, according to ZipRecruiter salary data. Most workers in this role earn between $56,100.00 and $144,400.00 per year, depending on experience, location, and employer.

What is a Remote RMF job?

A Remote RMF (Risk Management Framework) job involves managing cybersecurity risk and compliance for an organization while working remotely. Professionals in this role ensure that IT systems align with federal security standards, such as those outlined by NIST. Responsibilities may include conducting risk assessments, implementing security controls, and maintaining compliance documentation. Remote RMF specialists often work with government agencies, contractors, or private companies handling sensitive data. This position requires expertise in cybersecurity policies, risk management, and regulatory compliance.

What are the typical daily responsibilities of a Remote RMF Specialist?

As a Remote RMF Specialist, your daily responsibilities often include conducting security assessments, preparing and reviewing authorization packages, and ensuring ongoing compliance with federal information security standards. You'll collaborate with cross-functional teams to identify risks, develop mitigation strategies, and document security control implementations. Regular communication with stakeholders, participation in virtual meetings, and continual monitoring of systems and processes to ensure compliance are also core aspects of the job. This role leverages remote work tools to collaborate effectively with cybersecurity, IT, and compliance professionals across multiple locations.

What are the key skills and qualifications needed to thrive in the Remote Rmf position, and why are they important?

To thrive as a Remote RMF (Risk Management Framework) Specialist, you need a strong understanding of information security principles, federal risk management frameworks (such as NIST SP 800-37), and relevant cybersecurity policies, typically backed by a degree in information security or related field. Familiarity with security assessment tools, governance, risk, and compliance (GRC) software, as well as certifications like CISSP, CAP, or CISM, is highly valued. Excellent organizational skills, attention to detail, and the ability to communicate complex security concepts clearly are important soft skills. These capabilities are critical to ensure regulatory compliance and robust information system security in a remote work context.

What are popular job titles related to Remote Rmf jobs in Washington, DC? For Remote Rmf jobs in Washington, DC, the most frequently searched job titles are:
What job categories do people searching Remote Rmf jobs in Washington, DC look for? The top searched job categories for Remote Rmf jobs in Washington, DC are:
Infographic showing various Remote Rmf job openings in Washington, DC as of July 2026, with employment types broken down into 86% Full Time, 10% Part Time, and 4% Contract. Highlights an 59% Physical, 4% Hybrid, and 37% Remote job distribution, with an average salary of $107,513 per year, or $51.7 per hour.
RMF IT Security Analyst

RMF IT Security Analyst

System One

Bethesda, MD โ€ข Remote

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 2 days ago


Job description

Job Title: RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF IT Security Analyst serves as a mid-level cybersecurity professional. Working under Lead and Senior RMF personnel, the analyst independently supports RMF lifecycle activities, security assessments, continuous monitoring, and compliance initiatives while mentoring junior staff. Work is primarily remote with occasional on-site meetings. Key Responsibilities

  • Support the implementation and maintenance of the NIST RMF program.
  • Develop, review, and maintain RMF documentation including SSPs, SARs, POA&Ms, and authorization packages.
  • Support system categorization, security control selection, assessments, authorization, and continuous monitoring.
  • Maintain the Risk Management Register and track remediation activities.
  • Support cybersecurity audits and assessments conducted by NIH, HHS, OIG, GAO, and other oversight organizations.
  • Support Cybersecurity Supply Chain Risk Management (C-SCRM) activities, including vendor documentation and SBOM reviews.
  • Manage or assist with Risk Mitigation Waivers, documentation, approvals, annual reviews, and tracking.
  • Coordinate contingency plan testing and document results and corrective actions.
  • Communicate risk posture and compliance status while collaborating with system owners, ISSOs, and technical teams.
  • Provide technical guidance and mentoring to junior analysts.
Required Qualifications Bachelor's degree in a related technical field (or equivalent experience) and 3โ€“5 years supporting RMF, cybersecurity compliance, or information security programs. Preferred Qualifications
  • Experience supporting federal civilian agencies, including NIH, HHS, or other Federal agencies.
  • Familiarity with NIST RMF, NIST SP 800-37, NIST SP 800-53 Rev. 5, and the Joint Cybersecurity Assessment Methodology (JCAM).
  • Experience using eMASS or similar Governance, Risk, and Compliance (GRC) platforms.
  • Experience supporting cybersecurity audits, POA&M management, continuous monitoring, and contingency planning.
  • Knowledge of Cybersecurity Supply Chain Risk Management (C-SCRM).
  • Experience developing or reviewing SSPs, SARs, SAPs, POA&Ms, and Authorization Packages.
Desired Certifications
  • ISC2 Certified in Cybersecurity (CC)
  • CompTIA Security+
  • CompTIA CySA+
  • CompTIA SecurityX (formerly CASP+)
  • CompTIA PenTest+
  • CAP/CGRC
  • CISSP
  • CISM
  • Knowledge, Skills, and Abilities Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity compliance. Ability to collaborate with system owners, ISSOs, and technical teams. Work Environment This position is primarily remote with occasional on-site meetings or support activities as required.

System One, and its subsidiaries including Joulรฉ and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

#M-2 #LI-CB5 Ref: #856-Baltimore-S1