1

Rmf Analyst Jobs (NOW HIRING)

About the role Concept Plus is seeking a Cybersecurity Policy and RMF Analyst to provide Risk Management Support to identify shortfalls in the assessment and authorization process, track and manage ...

Jr. RMF Analyst

Washington, DC ยท On-site

$64K - $124.20K/yr

Overall 2 years of experience in Cybersecurity (RMF and Compliance) * Experience in identifying and documenting security/privacy weaknesses, and recommending improvement actions Bonus: * Governance ...

Jr. RMF Analyst

Washington, DC ยท On-site

$64K - $124.20K/yr

Overall 2 years of experience in Cybersecurity (RMF and Compliance) * Experience in identifying and documenting security/privacy weaknesses, and recommending improvement actions Bonus: * Governance ...

Reviews program office artifacts and make recommendations to support cybersecurity RMF analysis. * Assist in performing vulnerability, threat, and risk assessments, and security impact assessments on ...

RMF Cybersecurity Analyst

Lexington, MA ยท On-site

$61.90K - $141K/yr

R0237852 RMF Cybersecurity Analyst The Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government ...

next page

Showing results 1-20

People also search for

Rmf Analyst information

See salary details

$39.5K

$107.3K

$141K

How much do rmf analyst jobs pay per year?

As of May 28, 2026, the average yearly pay for rmf analyst in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is an RMF Analyst job?

An RMF (Risk Management Framework) Analyst is responsible for ensuring IT systems comply with security regulations and frameworks, such as NIST 800-53. They assess risks, implement security controls, and help organizations maintain authorization to operate (ATO) for their systems. RMF Analysts work closely with security teams, auditors, and system owners to document risks and remediation efforts. Their role is crucial in maintaining cybersecurity compliance for government and private-sector organizations handling sensitive data.

What are the key skills and qualifications needed to thrive in the Rmf Analyst position, and why are they important?

To thrive as an RMF Analyst, you need a thorough understanding of the Risk Management Framework (RMF), information security policies, and federal compliance standards such as NIST SP 800-53. Familiarity with security assessment tools, vulnerability scanning software, and certifications like CompTIA Security+ or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication are important soft skills in this position. These abilities are crucial for accurately evaluating security risks, maintaining regulatory compliance, and effectively collaborating with both technical and non-technical stakeholders.

What are the typical daily responsibilities of an RMF Analyst?

As an RMF Analyst, your daily responsibilities often include conducting security assessments, preparing documentation to support system accreditation, reviewing compliance with information security policies, and coordinating with system owners to address security risks. You may also be responsible for monitoring ongoing system changes, updating risk assessment reports, and supporting remediation activities based on audit findings. Most RMF Analysts work as part of a cybersecurity or compliance team, collaborating closely with IT personnel, auditors, and management to maintain a secure organizational environment. The work requires a mix of independent analysis and team-oriented problem-solving, making communication and attention to detail key to your success.
What cities are hiring for Rmf Analyst jobs? Cities with the most Rmf Analyst job openings:
What are the most commonly searched types of Rmf Analyst jobs? The most popular types of Rmf Analyst jobs are:
What states have the most Rmf Analyst jobs? States with the most job openings for Rmf Analyst jobs include:
Infographic showing various Rmf Analyst job openings in the United States as of May 2026, with employment types broken down into 2% Internship, 2% As Needed, 37% Full Time, and 59% Contract. Highlights an 80% Physical, and 20% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.
FCC - Security Compliance / RMF Analyst

FCC - Security Compliance / RMF Analyst

cFocus Software Incorporated

Washington, DC โ€ข On-site, Remote

Full-time

Posted 23 days ago


Job description

cFocus Software seeks a Security Compliance / RMF Analyst to join our program supporting the Federal Communications Commission (FCC). This position is remote. This position requires the ability a Public Trust clearance.
Qualifications:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
  • Experience in cybersecurity compliance, RMF, risk management, or related environments.
  • Demonstrated experience supporting enterprise-level cybersecurity or compliance programs.
  • Experience working in complex IT environments with federal or regulated systems.
  • Strong knowledge of NIST RMF (SP 800-37) and NIST SP 800-53 controls.
  • Experience with A&A, ATO processes, and continuous monitoring.
  • Familiarity with GRC tools (e.g., Archer, Xacta, CSAM).
  • Experience with vulnerability management and risk prioritization.
  • Strong documentation and technical writing skills.
  • Analytical and problem-solving capabilities.
  • Ability to communicate effectively with technical and non-technical stakeholders
  • Required Certifications
    • Role-appropriate cybersecurity certification demonstrating competency in compliance, RMF, or risk management.
    • Examples include: Security+, CISA, CISSP (or equivalent certifications aligned with role responsibilities).
Duties:
  • Support RMF lifecycle activities including system authorization, reauthorization, and continuous monitoring.
  • Develop, maintain, and update security documentation (SSPs, SARs, POA&Ms, contingency plans).
  • Perform security control assessments (SCA) and control validation activities.
  • Track and manage POA&Ms, vulnerabilities, and remediation activities.
  • Conduct risk assessments, gap analyses, and compliance reviews.
  • Support FISMA, NIST SP 800-53, and other federal compliance requirements.
  • Coordinate with system owners, ISSOs, engineers, and auditors.
  • Support audit readiness and respond to internal/external audit requests.
  • Maintain RMF artifacts in GRC tools (e.g., Xacta, Archer, ServiceNow).
  • Assist with continuous monitoring, reporting, and compliance metrics development.