1

Rmf Analyst Jobs in Colorado (NOW HIRING)

We are seeking a highly skilled Cyber Analyst - RMF Specialist in Colorado Springs, CO to support the critical North American Aerospace Defense Command and United States Northern Command (N&NC ...

New

We are seeking a highly skilled Cyber Analyst - RMF Specialist in Colorado Springs, CO to support the critical North American Aerospace Defense Command and United States Northern Command (N&NC ...

New

Cybersecurity Analyst LOCATION: Colorado Springs, CO, Peterson SFB REQUIRED SECURITY CLEARANCE ... Creates and maintains RMF documentation to include Enterprise Mission Assurance Support Service ...

Cybersecurity Analyst LOCATION: Colorado Springs, CO, Peterson SFB REQUIRED SECURITY CLEARANCE ... Creates and maintains RMF documentation to include Enterprise Mission Assurance Support Service ...

Sr Info Security Analyst

Boulder, CO · On-site

$185K - $210K/yr

Provide senior cybersecurity engineering and analysis support to Space Force ISSMs and SSCAs for missile warning and space sensing programs Support Risk Management Framework (RMF) activities ...

Sr Info Security Analyst

Boulder, CO · On-site

$185K - $210K/yr

Taxable Entity MCCALLIE ASSOCIATES INC Job Title Sr Info Security Analyst Location CO Boulder BGIF ... Support Risk Management Framework (RMF) activities including system categorization, security ...

This role is ideal for a mid-career risk professional who is fluent in frameworks such as NIST RMF ... prioritization analyses for leadership. * Maintain and update the enterprise risk register ...

next page

Showing results 1-20

Rmf Analyst information

See Colorado salary details

$41.5K

$112.9K

$148.3K

How much do rmf analyst jobs pay per year?

As of Aug 21, 2026, the average yearly pay for rmf analyst in Colorado is $112,864.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,200.00 and $136,700.00 per year, depending on experience, location, and employer.

What is an RMF analyst?

An RMF (Risk Management Framework) Analyst is responsible for ensuring IT systems comply with security regulations and frameworks, such as NIST 800-53. They assess risks, implement security controls, and help organizations maintain authorization to operate (ATO) for their systems. RMF Analysts work closely with security teams, auditors, and system owners to document risks and remediation efforts. Their role is crucial in maintaining cybersecurity compliance for government and private-sector organizations handling sensitive data.

What are the typical daily responsibilities of an RMF analyst?

As an RMF Analyst, your daily responsibilities often include conducting security assessments, preparing documentation to support system accreditation, reviewing compliance with information security policies, and coordinating with system owners to address security risks. You may also be responsible for monitoring ongoing system changes, updating risk assessment reports, and supporting remediation activities based on audit findings. Most RMF Analysts work as part of a cybersecurity or compliance team, collaborating closely with IT personnel, auditors, and management to maintain a secure organizational environment. The work requires a mix of independent analysis and team-oriented problem-solving, making communication and attention to detail key to your success.

What are the key skills and qualifications needed to thrive in the RMF analyst position, and why are they important?

To thrive as an RMF Analyst, you need a thorough understanding of the Risk Management Framework (RMF), information security policies, and federal compliance standards such as NIST SP 800-53. Familiarity with security assessment tools, vulnerability scanning software, and certifications like CompTIA Security+ or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication are important soft skills in this position. These abilities are crucial for accurately evaluating security risks, maintaining regulatory compliance, and effectively collaborating with both technical and non-technical stakeholders.

What does an RMF analyst do?

An RMF analyst is responsible for implementing and managing the Risk Management Framework (RMF) to ensure the security of information systems. They assess security controls, conduct risk assessments, and prepare documentation to meet compliance standards, often using tools like NIST guidelines. This role requires knowledge of cybersecurity principles and attention to detail to protect organizational assets.

What are the most commonly searched types of Rmf Analyst jobs in Colorado?

The most popular types of Rmf Analyst jobs in Colorado are:

Infographic showing various Rmf Analyst job openings in Colorado as of August 2026, with employment types broken down into 87% Full Time, 7% Part Time, 1% Temporary, and 5% Contract. Highlights an 80% Physical, 9% Hybrid, and 11% Remote job distribution, with an average salary of $112,864 per year, or $54.3 per hour.

Cyber Analyst-RMF Specialist

SAIC

Colorado Springs, CO

$120K - $160K/yr

Full-time

Posted 3 days ago

New


SAIC rating

7.9

Company rating: 7.9 out of 10

Based on 79 frontline employees who took The Breakroom Quiz

79th of 224 rated it services


Job description

Job ID: 2615743

Location: Colorado Springs, CO, US

Date Posted: 2026-08-17

Category: Cyber

Subcategory: Cyber Engineer

Schedule: Full-Time

Shift: Day Job

Travel: No

Minimum Clearance Required: TS.SCI

Clearance Level Must Be Able to Obtain: None

Potential for Remote Work: ORA_ON_SITE


Description

Join our team and play a pivotal role in defending North America. We are seeking a highly skilled Cyber Analyst - RMF Specialist in Colorado Springs, CO to support the critical North American Aerospace Defense Command and United States Northern Command (N&NC) Information Technology Enterprise Services (NITES) contract in Colorado Springs, CO.

In this role, you will act as a key technical compliance specialist. You will hold administrator-level access to information systems to perform advanced vulnerability and compliance scanning and manage Security Technical Implementation Guide (STIG) compliance. Crucially, you will bridge the gap between technical operations and cyber governance by directly supporting the Risk Management Framework (RMF) team, maintaining up-to-date system records in Enterprise Mission Assurance Support Service (eMASS), and executing rapid response protocols to downward-directed Cyber Tasking Orders (CTASKORDs).

Responsibilities: 

The selected candidate will be responsible for the following technical and compliance activities:

  • Directly support the Risk Management Framework (RMF) team by registering, updating, and maintaining continuous monitoring records within the eMASS.
  • Maintain administrator-level access to enterprise information systems to configure, manage, and perform regular Assured Compliance Assessment Solution (ACAS) and Security Content Automation Protocol (SCAP) compliance scans.
  • Analyze scan results to ensure continuous patching and STIG compliance. 
  • Implement, track, and validate system hardening measures across Windows, Linux, and network enclaves.
  • Lead the execution, tracking, and operational response to Cyber Tasking Orders (CTASKORDs) and other downward-directed orders when STIG compliance gaps must be urgently addressed.
  • Translate technical scan findings and non-compliant STIG items into actionable Plan of Action and Milestones (POA&Ms), maintaining accurate tracking of remediation milestones.
  • Maintain continuous cyber security posture and system hygiene to ensure systems remain in a Cyber Operational Readiness Assessment (CORA) ready state.
  • Provide clear vulnerability status updates, technical mitigations, and compliance roadmaps to System Owners, technical administration teams, and leadership.

Qualifications

Required Qualifications:

  • Active TS/SCI security clearance.
  • Certification required per DoDD 8140.03, Intermediate Level (e.g., CompTIA CySA+, Security+ CE, GSEC, or equivalent).
  • BS or equivalent work experience in the Information Assurance, Cybersecurity, or Systems Administration field.
  • 5+ years of overall IT and cybersecurity experience.
  • Demonstrated experience with defending identity services, domain environments, Active Directory, and Windows/Linux server systems.
  • 2+ years of experience as an ISSO for DoD systems.
  • Experience using STIG Viewer and SCAP tools, such as EvaluateSTIG.

Desired Qualifications:

  • Familiarity with enterprise vulnerability scanners and continuous network monitoring tools.
  • Previous experience operating in a highly complex, metrics-driven DoD cybersecurity environment.
  • Familiarity with the use of eMASS as a central repository for RMF artifacts.

Target salary range: $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

What SAIC employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom