1

Rmf Analyst Jobs in Virginia (NOW HIRING)

RMF Cyber Security Analyst Senior

Quantico, VA ยท On-site

$120K - $160K/yr

The RMF Cyber Security Analyst Senior will provide support for a program, an organization, system, or an enclave; provides support for proposing, coordinating, implementing, and enforcing information ...

The RMF Cyber Security Analyst Senior will provide support for a program, an organization, system, or an enclave; provides support for proposing, coordinating, implementing, and enforcing information ...

RMF Cyber Security Analyst Senior

Quantico, VA ยท On-site

$120K - $160K/yr

The RMF Cyber Security Analyst Senior will provide support for a program, an organization, system, or an enclave; provides support for proposing, coordinating, implementing, and enforcing information ...

next page

Showing results 1-20

Rmf Analyst information

See Virginia salary details

$39.2K

$106.4K

$139.8K

How much do rmf analyst jobs pay per year?

As of Aug 25, 2026, the average yearly pay for rmf analyst in Virginia is $106,413.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,700.00 and $128,900.00 per year, depending on experience, location, and employer.

What is an RMF analyst?

An RMF (Risk Management Framework) Analyst is responsible for ensuring IT systems comply with security regulations and frameworks, such as NIST 800-53. They assess risks, implement security controls, and help organizations maintain authorization to operate (ATO) for their systems. RMF Analysts work closely with security teams, auditors, and system owners to document risks and remediation efforts. Their role is crucial in maintaining cybersecurity compliance for government and private-sector organizations handling sensitive data.

What are the typical daily responsibilities of an RMF analyst?

As an RMF Analyst, your daily responsibilities often include conducting security assessments, preparing documentation to support system accreditation, reviewing compliance with information security policies, and coordinating with system owners to address security risks. You may also be responsible for monitoring ongoing system changes, updating risk assessment reports, and supporting remediation activities based on audit findings. Most RMF Analysts work as part of a cybersecurity or compliance team, collaborating closely with IT personnel, auditors, and management to maintain a secure organizational environment. The work requires a mix of independent analysis and team-oriented problem-solving, making communication and attention to detail key to your success.

What are the key skills and qualifications needed to thrive in the RMF analyst position, and why are they important?

To thrive as an RMF Analyst, you need a thorough understanding of the Risk Management Framework (RMF), information security policies, and federal compliance standards such as NIST SP 800-53. Familiarity with security assessment tools, vulnerability scanning software, and certifications like CompTIA Security+ or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication are important soft skills in this position. These abilities are crucial for accurately evaluating security risks, maintaining regulatory compliance, and effectively collaborating with both technical and non-technical stakeholders.

What does an RMF analyst do?

An RMF analyst is responsible for implementing and managing the Risk Management Framework (RMF) to ensure the security of information systems. They assess security controls, conduct risk assessments, and prepare documentation to meet compliance standards, often using tools like NIST guidelines. This role requires knowledge of cybersecurity principles and attention to detail to protect organizational assets.

What are the most commonly searched types of Rmf Analyst jobs in Virginia?

The most popular types of Rmf Analyst jobs in Virginia are:

Infographic showing various Rmf Analyst job openings in Virginia as of August 2026, with employment types broken down into 88% Full Time, 7% Part Time, and 5% Contract. Highlights an 82% Physical, 7% Hybrid, and 11% Remote job distribution, with an average salary of $106,413 per year, or $51.2 per hour.

Risk Management Framework (RMF) Analyst

Stafford, VA โ€ข On-site

DeVillier's Technology Solutions
Computer and Computer Peripheral Equipment and Software Wholesalersย โ€ขย 11 - 50 employees

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 3 days ago


Job description

Position SummaryThe candidate shall be responsible for analyzing Software applications and encryption technology product(s) being assessed or developed for the purpose of specifying and developing Risk Management Framework (RMF) documentation. These documents are required in order to submit products for an Authority To Operate (ATO) or for certifications, such as the National Information Assurance Partnership (NIAP) and the Classified Solutions for Classified (CSfC). Essential Duties and ResponsibilitiesThe essential functions include, but are not limited to the following:Apply the NIST Special Publication 800-37 Rev 2 Risk Management Framework (RMF) process to information systems and applications currently being assessed or developed by our company for use in the U.S. Federal government, especially the Department of Defense (DoD).Formulate plans and schedules to conduct either portions or all of the RMF process on selected products.Conduct and guide the analysis needed to gather information needed to produce RMF artifacts.Provide recommendation on how RMF products can be used to prepare for other processes or certifications, such as NIAP and CSfC.Develop RMF documentation as required to prepare products and systems for submission to an ATO authority or a NIAP/CSfC laboratory.Minimum Qualifications (Knowledge, Skills, and Abilities)Experience conducting RMF process, per NIST SP 800-37 for in-development or existing programs or systems.Experience personally drafting RMF products.Detailed knowledge ofNIST SP 800-53. Experience using Cyber-Security analysis tools.Desired Qualifications (Knowledge, Skills, and Abilities)Experience undergoing the NIAP certification process to successful completion, or work experience conducting NIAP certification within a third party NIAP laboratory.Experience working within the CSfC program.Certifications in Information Systems security, such as CISSP.CompensationSalary is $80,000 - $125,000, based on experience and qualificationsBenefits include health, dental, and vision insurance, short and long term disability, life insurance, 401K, Health Reimbursement Agreement (HRA), and 10 days paid leave, 7 sick days, and 11 Federal holidays.

DeVilliers Technology Solutions logo

About DeVilliers Technology Solutions

Sourced by ZipRecruiter

DeVilliers Technology Solutions LLC dba DeVil-Tech is a systems engineering and software development company established in 2012. Based in Stafford, Virginia, we provide engineering services, consulting and product development to our customers. We are a registered vendor to Federal agencies, such as the Department of Defense , the National Security Agency , and the National Aeronautics and Space Administration , as well as State and commercial firms, such as Baltimore Gas and Electric. Our personal and corporate experience is in complex DoD command and control systems that have been globally fielded. Yet, our skills and knowledge go beyond DoD, and are just as applicable to the commercial world.

Industry

Computer and computer peripheral equipment and software wholesalers

Company size

11 - 50 Employees

Headquarters location

Stafford, VA, US