1

Rmf Analyst Jobs in California (NOW HIRING)

Sr. RMF Security Engineer

San Diego, CA · On-site

$131K - $237K/yr

Leidos has a new and exciting opportunity for a Sr. RMF Security Engineer in our Intelligence Group (IG) Cyber & Analytics Business Area (CABA) . Our talented team is at the forefront in Security ...

Sr. RMF Security Engineer

San Diego, CA · On-site

$131K - $237K/yr

Leidos has a new and exciting opportunity for a Sr. RMF Security Engineer in our Intelligence Group (IG) Cyber & Analytics Business Area (CABA) . Our talented team is at the forefront in Security ...

Description RMF Engineer - Intermediate Xcelerate Solutions is seeking a RMF Engineer to support ... analysis, POA&M remediation, and compliance troubleshooting. Minimum Qualifications * Bachelor ...

Leidos is seeking a Sr. RMF Security Engineer to support a project at a Navy base in San Diego ... Responsibilities include performing risk assessments, analyzing security test results, recommending ...

Senior Cybersecurity Analyst

San Diego, CA · On-site

$106K - $137K/yr

You will be instrumental in identifying and mitigating traditional Navy Cybersecurity (RMF) process inefficiencies, analysis and execution of the changing broader formulation of Navy Cybersecurity ...

Security Analyst

China Lake, CA · On-site

$85K - $110K/yr

Security Analyst Location: China Lake, CA Clearance Level: Must Have Ability to Obtain a Secret ... Execute and oversee RMF Documentation and Compliance: Review the accuracy and traceability of all A ...

next page

Showing results 1-20

Rmf Analyst information

See California salary details

$39K

$105.9K

$139.2K

How much do rmf analyst jobs pay per year?

As of Aug 23, 2026, the average yearly pay for rmf analyst in California is $105,928.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,300.00 and $128,300.00 per year, depending on experience, location, and employer.

What is an RMF analyst?

An RMF (Risk Management Framework) Analyst is responsible for ensuring IT systems comply with security regulations and frameworks, such as NIST 800-53. They assess risks, implement security controls, and help organizations maintain authorization to operate (ATO) for their systems. RMF Analysts work closely with security teams, auditors, and system owners to document risks and remediation efforts. Their role is crucial in maintaining cybersecurity compliance for government and private-sector organizations handling sensitive data.

What are the typical daily responsibilities of an RMF analyst?

As an RMF Analyst, your daily responsibilities often include conducting security assessments, preparing documentation to support system accreditation, reviewing compliance with information security policies, and coordinating with system owners to address security risks. You may also be responsible for monitoring ongoing system changes, updating risk assessment reports, and supporting remediation activities based on audit findings. Most RMF Analysts work as part of a cybersecurity or compliance team, collaborating closely with IT personnel, auditors, and management to maintain a secure organizational environment. The work requires a mix of independent analysis and team-oriented problem-solving, making communication and attention to detail key to your success.

What are the key skills and qualifications needed to thrive in the RMF analyst position, and why are they important?

To thrive as an RMF Analyst, you need a thorough understanding of the Risk Management Framework (RMF), information security policies, and federal compliance standards such as NIST SP 800-53. Familiarity with security assessment tools, vulnerability scanning software, and certifications like CompTIA Security+ or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication are important soft skills in this position. These abilities are crucial for accurately evaluating security risks, maintaining regulatory compliance, and effectively collaborating with both technical and non-technical stakeholders.

What does an RMF analyst do?

An RMF analyst is responsible for implementing and managing the Risk Management Framework (RMF) to ensure the security of information systems. They assess security controls, conduct risk assessments, and prepare documentation to meet compliance standards, often using tools like NIST guidelines. This role requires knowledge of cybersecurity principles and attention to detail to protect organizational assets.

What are the most commonly searched types of Rmf Analyst jobs in California?

The most popular types of Rmf Analyst jobs in California are:

Infographic showing various Rmf Analyst job openings in California as of August 2026, with employment types broken down into 91% Full Time, 4% Part Time, and 5% Contract. Highlights an 80% Physical, 9% Hybrid, and 11% Remote job distribution, with an average salary of $105,928 per year, or $50.9 per hour.

Sr. RMF Security Engineer

Leidos

San Diego, CA • On-site

$131K - $237K/yr

Full-time

Retirement, PTO

Re-posted 25 days ago


Leidos rating

8.3

Company rating: 8.3 out of 10

Based on 152 frontline employees who took The Breakroom Quiz

79th of 496 rated business services


Job description

Leidos has a new and exciting opportunity for a Sr. RMF Security Engineer in our Intelligence Group (IG) Cyber & Analytics Business Area (CABA). Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO), Mission Software, Analytical Methods and Modeling, Signals Intelligence (SIGINT), and Cryptographic Key Management. At Leidos, we offer competitive benefits, including Paid Time Off, 11 paid Holidays, 401K with a 6% company match and immediate vesting, Flexible Schedules, Discounted Stock Purchase Plans, Technical Upskilling, Education and Training Support, Parental Paid Leave, and much more. Join us and make a difference in National Security!

Leidos is seeking a Sr. Risk Management Framework (RMF) Security Engineer to support a project at a Navy base in San Diego. This position will play a critical role in ensuring that information systems comply with federal cybersecurity standards, particularly within the U.S. Department of Defense (DoD) cyber community. The RMF Security Engineer will guide the project through the RMF lifecycle, which includes categorizing information systems based on risk, selecting and implementing appropriate security controls (per NIST SP 800-53 or DoD-specific requirements), and assessing those controls for effectiveness. The RMF Security Engineer will conduct continuous monitoring, identify vulnerabilities, address compliance gaps, recommend useful vulnerability mitigations, and ensure systems remain secure against evolving threats.

The RMF Security Engineer will act as a technical advisor and problem solver, bridging the gap between cybersecurity policy and system implementation. Will perform risk assessments, analyze security test results, and recommend mitigation strategies to address findings, whether through configuration changes, tool updates, or process improvements.

This position is 100% on site at the Navy base.

Required Qualifications:

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science or related field. BS with 12+ years' experience or MS with 10+ years' experience. Will consider work experience in lieu of a degree.

  • DoD 8570 approved security certification (i.e., Security +) (Will berequired90 days after hire).

  • Position requires US citizenship and an active Secret DoD security clearance.

  • RMF Compliance Expertise: Deep knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-171, FedRAMP, and DoD Instruction 8510.01 (DIARMF).

  • Security Assessment & Authorization (SA&A):

  • Experience preparing System Security Plans (SSP), Security Assessment Reports (SAR), and Plan of Action & Milestones (POA&M).

  • Conducting risk assessments, vulnerability scans, and penetration testing.

  • eMASS (Enterprise Mission Assurance Support Service)

  • SCAP tools (e.g., Nessus, Tenable.sc, OpenSCAP).

  • STIG compliance (DISA STIGs, SCAP benchmarks)

  • Find and address vulnerabilities in code base using:

    • SAST tools - identify and verify structural flaws

    • DAST tools - identify and verify runtime and environment misconfigurations with running code

Preferred Qualifications:

  • At least one for automation: Python, Javascript, Typescript, Bash, Rust, PowerShell

  • Experience leveraging AI agentic workflows that incorporate with the NIST RMF to analyze one or more code bases to provide security compliance coverage and mitigate vulnerabilities per the applicable 800-53 STIG and SRG requirements.

  • Zero Trust Integration: Understanding NIST SP 800-207 (Zero Trust Architecture) and how it intersects with RMF.

  • CMMC 2.0.

  • COMSEC Understanding

  • CISSP Certification

  • Experience with log/SIEM and health monitoring tools (e.g., Splunk, ArcSight). Experience with High Assurance / Type 1 security evaluation processes

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting:July 17, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:Pay Range $131,300.00 - $237,350.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.


What Leidos employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Leidos logo

About Leidos

Sourced by ZipRecruiter

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Reston, VA, US

Social media