1

Rmf Analyst Jobs in Colorado (NOW HIRING)

Cybersecurity Analyst

Colorado Springs, CO ยท On-site

$80K - $90K/yr

Cybersecurity Analyst LOCATION: Colorado Springs, CO, Peterson SFB REQUIRED SECURITY CLEARANCE ... Creates and maintains RMF documentation to include Enterprise Mission Assurance Support Service ...

Job Title MID LEVEL CYBERSECURITY ANALYST Location Colorado Springs, CO US (Primary) Huntsville, AL ... This position performs cybersecurity assessments, RMF activities, and continuous monitoring to ...

Cybersecurity Analyst LOCATION: Colorado Springs, CO, Peterson SFB REQUIRED SECURITY CLEARANCE ... Creates and maintains RMF documentation to include Enterprise Mission Assurance Support Service ...

Provide senior cybersecurity engineering and analysis support to Space Force ISSMs and SSCAs for missile warning and space sensing programs Support Risk Management Framework (RMF) activities ...

Sr Info Security Analyst

Boulder, CO ยท On-site

$185K - $210K/yr

Taxable Entity MCCALLIE ASSOCIATES INC Job Title Sr Info Security Analyst Location CO Boulder BGIF ... Support Risk Management Framework (RMF) activities including system categorization, security ...

This role is ideal for a mid-career risk professional who is fluent in frameworks such as NIST RMF ... prioritization analyses for leadership. * Maintain and update the enterprise risk register ...

next page

Showing results 1-20

Rmf Analyst information

See Colorado salary details

$41.5K

$112.9K

$148.3K

How much do rmf analyst jobs pay per year?

As of Aug 10, 2026, the average yearly pay for rmf analyst in Colorado is $112,864.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,200.00 and $136,700.00 per year, depending on experience, location, and employer.

What are the typical daily responsibilities of an RMF analyst?

As an RMF Analyst, your daily responsibilities often include conducting security assessments, preparing documentation to support system accreditation, reviewing compliance with information security policies, and coordinating with system owners to address security risks. You may also be responsible for monitoring ongoing system changes, updating risk assessment reports, and supporting remediation activities based on audit findings. Most RMF Analysts work as part of a cybersecurity or compliance team, collaborating closely with IT personnel, auditors, and management to maintain a secure organizational environment. The work requires a mix of independent analysis and team-oriented problem-solving, making communication and attention to detail key to your success.

What is an RMF analyst?

An RMF (Risk Management Framework) Analyst is responsible for ensuring IT systems comply with security regulations and frameworks, such as NIST 800-53. They assess risks, implement security controls, and help organizations maintain authorization to operate (ATO) for their systems. RMF Analysts work closely with security teams, auditors, and system owners to document risks and remediation efforts. Their role is crucial in maintaining cybersecurity compliance for government and private-sector organizations handling sensitive data.

What are the key skills and qualifications needed to thrive in the RMF analyst position, and why are they important?

To thrive as an RMF Analyst, you need a thorough understanding of the Risk Management Framework (RMF), information security policies, and federal compliance standards such as NIST SP 800-53. Familiarity with security assessment tools, vulnerability scanning software, and certifications like CompTIA Security+ or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication are important soft skills in this position. These abilities are crucial for accurately evaluating security risks, maintaining regulatory compliance, and effectively collaborating with both technical and non-technical stakeholders.

What are the most commonly searched types of Rmf Analyst jobs in Colorado? The most popular types of Rmf Analyst jobs in Colorado are:
What job categories do people searching Rmf Analyst jobs in Colorado look for? The top searched job categories for Rmf Analyst jobs in Colorado are:
Infographic showing various Rmf Analyst job openings in Colorado as of August 2026, with employment types broken down into 1% Internship, 85% Full Time, 8% Part Time, and 6% Contract. Highlights an 81% Physical, 9% Hybrid, and 10% Remote job distribution, with an average salary of $112,864 per year, or $54.3 per hour.

Information Security Analyst

Akhiok-Kaguyak, Inc.

Colorado Springs, CO โ€ข On-site

$105K - $120K/yr

Full-time

Posted 19 days ago


Job description

Information Security Analyst


Company: Sugpiat Defense

Program: Missile Defense Agency (MDA)

Employment Type: Full-Time


Position Overview

Sugpiat Defense is seeking an experienced Information Security Analyst to support the Missile Defense Agency (MDA) in Colorado Springs, Colorado. The selected candidate will assist in protecting mission-critical information systems by implementing cybersecurity policies, supporting Risk Management Framework (RMF) activities, monitoring system security posture, and ensuring compliance with Department of Defense (DoD) cybersecurity requirements.

The ideal candidate is detail-oriented, possesses strong analytical and problem-solving skills, and has experience supporting cybersecurity operations within a DoD environment. This role works closely with Information System Security Managers (ISSMs), engineers, system administrators, and government personnel to maintain the security and compliance of MDA information systems.


Essential Duties and Responsibilities

  • Support the implementation and maintenance of cybersecurity requirements for classified and unclassified information systems.
  • Assist with Risk Management Framework (RMF) activities throughout the system lifecycle.
  • Maintain and update RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and supporting artifacts.
  • Perform continuous monitoring activities to ensure compliance with DoD cybersecurity requirements.
  • Review vulnerability scan results, document findings, and coordinate remediation efforts with technical teams.
  • Support implementation and validation of DISA Security Technical Implementation Guides (STIGs).
  • Assist with Assessment and Authorization (A&A) activities to maintain system Authority to Operate (ATO).
  • Monitor system security posture and report cybersecurity risks and compliance issues.
  • Support security audits, inspections, and cybersecurity assessments.
  • Assist with investigating and documenting cybersecurity incidents in accordance with established procedures.
  • Review proposed system changes to identify potential security impacts.
  • Collaborate with engineers, system administrators, and government stakeholders to ensure cybersecurity requirements are incorporated into system operations.
  • Prepare reports, metrics, and status updates related to cybersecurity compliance and continuous monitoring.
  • Stay current on DoD cybersecurity policies, emerging threats, and industry best practices.


Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or a related field.
  • Minimum of 3–5 years of experience supporting information assurance or cybersecurity programs, preferably within the Department of Defense.
  • Experience supporting the DoD Risk Management Framework (RMF).
  • Working knowledge of:
    • NIST SP 800-53
    • NIST SP 800-37
    • DoD RMF
    • DISA STIGs
    • Vulnerability management
    • Security compliance and continuous monitoring
  • Experience with Enterprise Mission Assurance Support Service (eMASS) or similar RMF tools.
  • Familiarity with Windows and Linux operating systems, Active Directory, and basic networking concepts.
  • Strong analytical, organizational, written, and verbal communication skills.
  • Ability to work independently while contributing effectively within a collaborative team environment.


Preferred Qualifications

  • Experience supporting the Missile Defense Agency (MDA) or another DoD organization.
  • Experience using ACAS, SCAP Compliance Checker, or other DoD cybersecurity assessment tools.
  • Familiarity with cybersecurity engineering principles and secure system development practices.
  • Experience supporting classified information systems.
  • Knowledge of Zero Trust concepts and current DoD cybersecurity initiatives.


Certifications

One or more of the following certifications is preferred:

  • Security+
  • CySA+
  • CASP+
  • CISSP (Associate or full certification)
  • CAP

Certification must meet applicable DoD 8570/8140 requirements for the assigned position.


Security Clearance

  • Active Top Secret with SCI eligibility security clearance required.


Why Join Sugpiat Defense?

  • Sugpiat Defense offers the opportunity to support the Missile Defense Agency's critical national security mission while working with a talented team of cybersecurity professionals. We provide competitive compensation, comprehensive benefits, opportunities for professional growth, and a collaborative environment where employees can make a meaningful impact.
  • Sugpiat Defense is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, or any other status protected by applicable law.
  • Position Contingent on Contract Award.