1

Rmf Analyst Jobs in Ohio (NOW HIRING)

Reviews program office artifacts and make recommendations to support cybersecurity RMF analysis. * Assist in performing vulnerability, threat, and risk assessments, and security impact assessments on ...

Cybersecurity Policy Analyst

Columbus, OH · On-site

  • Medical

  • Dental

  • Retirement

  • PTO

Ensure cybersecurity policies and documentation comply with DoD, DLA, NIST, RMF, and applicable ... Strong technical writing, documentation, analytical, and presentation skills. * Ability to ...

Be Seen First

Cybersecurity Policy Analyst

Columbus, OH · On-site

$90K - $130K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Ensure cybersecurity policies and documentation comply with DoD, DLA, NIST, RMF, and applicable ... Strong technical writing, documentation, analytical, and presentation skills. * Ability to ...

New

Be Seen First

Cybersecurity Policy Analyst

Columbus, OH · On-site

$90K - $130K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Ensure cybersecurity policies and documentation comply with DoD, DLA, NIST, RMF, and applicable ... Strong technical writing, documentation, analytical, and presentation skills. * Ability to ...

New

... RMF analysis. * Assist in evaluating the technical implementation of the security design to ascertain that security software, hardware and firmware features affecting confidentiality, integrity ...

Information Security Analyst

Miamisburg, OH

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Information Security Analyst (Classified Systems) The Information Security Analyst (Classified ... Manage and maintain RMF documentation in eMASS or manually (based on customer requirements ...

Information Security Analyst

Miamisburg, OH · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Information Security Analyst (Classified Systems) The Information Security Analyst (Classified ... Manage and maintain RMF documentation in eMASS or manually (based on customer requirements ...

Cybersecurity SME

Dayton, OH · On-site

$90K - $125K/yr

... RMF analysis. * Assist in evaluating the technical implementation of the security design to ascertain that security software, hardware and firmware features affecting confidentiality, integrity ...

... RMF processes for weapon systems that will generate both unclassified and classified information. * The Contractor will develop and analyze cyber security engineering artifacts used to support the ...

Cybersecurity (ISSM)

Dayton, OH · On-site

$125K - $155K/yr

... RMF processes for weapon systems that will generate both unclassified and classified information. * The Contractor will develop and analyze cyber security engineering artifacts used to support the ...

next page

Showing results 1-20

Rmf Analyst information

See Ohio salary details

$37.6K

$102K

$134K

How much do rmf analyst jobs pay per year?

As of Aug 15, 2026, the average yearly pay for rmf analyst in Ohio is $102,042.00, according to ZipRecruiter salary data. Most workers in this role earn between $87,000.00 and $123,600.00 per year, depending on experience, location, and employer.

What are the typical daily responsibilities of an RMF analyst?

As an RMF Analyst, your daily responsibilities often include conducting security assessments, preparing documentation to support system accreditation, reviewing compliance with information security policies, and coordinating with system owners to address security risks. You may also be responsible for monitoring ongoing system changes, updating risk assessment reports, and supporting remediation activities based on audit findings. Most RMF Analysts work as part of a cybersecurity or compliance team, collaborating closely with IT personnel, auditors, and management to maintain a secure organizational environment. The work requires a mix of independent analysis and team-oriented problem-solving, making communication and attention to detail key to your success.

What is an RMF analyst?

An RMF (Risk Management Framework) Analyst is responsible for ensuring IT systems comply with security regulations and frameworks, such as NIST 800-53. They assess risks, implement security controls, and help organizations maintain authorization to operate (ATO) for their systems. RMF Analysts work closely with security teams, auditors, and system owners to document risks and remediation efforts. Their role is crucial in maintaining cybersecurity compliance for government and private-sector organizations handling sensitive data.

What are the key skills and qualifications needed to thrive in the RMF analyst position, and why are they important?

To thrive as an RMF Analyst, you need a thorough understanding of the Risk Management Framework (RMF), information security policies, and federal compliance standards such as NIST SP 800-53. Familiarity with security assessment tools, vulnerability scanning software, and certifications like CompTIA Security+ or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication are important soft skills in this position. These abilities are crucial for accurately evaluating security risks, maintaining regulatory compliance, and effectively collaborating with both technical and non-technical stakeholders.

What are the most commonly searched types of Rmf Analyst jobs in Ohio?

The most popular types of Rmf Analyst jobs in Ohio are:

Infographic showing various Rmf Analyst job openings in Ohio as of August 2026, with employment types broken down into 82% Full Time, and 18% Contract. Highlights an 91% In-person, and 9% Remote job distribution, with an average salary of $102,042 per year, or $49.1 per hour.

Full-time

Re-posted 6 days ago


Job description

COLSA Corporation is seeking candidates for Cybersecurity positions in support of a USAF contract.

NOTE: This posting does not represent a current job opening but may be used to identify candidates with skills and experience for recurring positions within COLSA. Candidates who express interest may be considered for future opportunities.

  • Responsible for the maintenance and support of DoD and Air Force computing systems and networks (both unclassified and classified).

  • Requires the individual to obtain/maintain classified systems administrative privileges for SIPRNet and other systems. 

  • Perform system trusted downloads, burning classified Compact Discs (CDs), maintain and update host system patches, implement mandated system vulnerability mitigations and set up user accesses and accounts. 

  • Demonstrate proficiency in currently utilized Windows Operating Systems (OS), Windows group policy objects, DoD Cybersecurity, National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), Security Technical Implementation Guides (STIGs), Endpoint Security System (SS)/Host-based Security System (HBS) and DoD Public Key Infrastructure (PKI). 

  • Assist the Information Systems Security Manager (ISSM) and provide multi-discipline expertise covering project management, system security engineering, system administration, and network administration. 

  • Provide cybersecurity support to assigned systems and shall assist in developing, modifying, reviewing or coordinating items that include, but are not limited to:  PIT determination package, cybersecurity strategy (formerly IAS), System Security Plan (SSP), system controls traceability matrix, risk assessment report, plan of action and milestones, security assessment plan, artifacts for program review and RFP. 

  • Assist in executing the cybersecurity RMF to support Assessment and Authorization (A&A) of assigned systems. 

  • Reviews program office artifacts and make recommendations to support cybersecurity RMF analysis. 

  • Assist in performing vulnerability, threat, and risk assessments, and security impact assessments on assigned systems, modifications, and interconnections. 

  • Assist in developing an A&A report and an A&A presentation for each required system to support approval decisions.   

  • Assist in managing, planning, documenting and conducting Independent Verification and Validation (IV&V) of security requirements for weapon system

  • Assist in performing cybersecurity site audits to verify architecture analysis, cybersecurity requirements and controls, verify mitigation actions, witness cybersecurity testing and evaluation, and to support final approval for Interim Authority to Test (IATT), Interim Authority To Operate (IATO), Authority To Operate (ATO), and/or Authority To Connect (ATC).  Assists in documenting and reporting cybersecurity site audit findings and recommendations to the program office and/or Security Certification Authority (CA). 

  • Assist in identifying the Software Assurance (SWA) pedigree (including platform software) and QA issues and documenting the results.  The C

At COLSA, people are our most valuable resource and centered at our core value. We invite you to unite your talents with opportunity and be a part of our "Family of Professionals!" Learn about our employee-centric culture and benefits here.