1

Rmf Analyst Jobs in Silver Spring, MD (NOW HIRING)

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

Description RMF Engineer Xcelerate Solutions is seeking a RMF Engineer to support CyberPRIMES ... analysis, POA&M remediation, and compliance troubleshooting. Minimum Qualifications * Bachelor ...

New

Description RMF Engineer Xcelerate Solutions is seeking a RMF Engineer to support CyberPRIMES ... analysis, POA&M remediation, and compliance troubleshooting. Minimum Qualifications * Bachelor ...

New

next page

Showing results 1-20

Rmf Analyst information

See Silver Spring, MD salary details

$40.8K

$111K

$145.8K

How much do rmf analyst jobs pay per year?

As of Aug 8, 2026, the average yearly pay for rmf analyst in Silver Spring, MD is $110,960.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,600.00 and $134,400.00 per year, depending on experience, location, and employer.

What are the typical daily responsibilities of an RMF analyst?

As an RMF Analyst, your daily responsibilities often include conducting security assessments, preparing documentation to support system accreditation, reviewing compliance with information security policies, and coordinating with system owners to address security risks. You may also be responsible for monitoring ongoing system changes, updating risk assessment reports, and supporting remediation activities based on audit findings. Most RMF Analysts work as part of a cybersecurity or compliance team, collaborating closely with IT personnel, auditors, and management to maintain a secure organizational environment. The work requires a mix of independent analysis and team-oriented problem-solving, making communication and attention to detail key to your success.

What is an RMF analyst?

An RMF (Risk Management Framework) Analyst is responsible for ensuring IT systems comply with security regulations and frameworks, such as NIST 800-53. They assess risks, implement security controls, and help organizations maintain authorization to operate (ATO) for their systems. RMF Analysts work closely with security teams, auditors, and system owners to document risks and remediation efforts. Their role is crucial in maintaining cybersecurity compliance for government and private-sector organizations handling sensitive data.

What are the key skills and qualifications needed to thrive in the RMF analyst position, and why are they important?

To thrive as an RMF Analyst, you need a thorough understanding of the Risk Management Framework (RMF), information security policies, and federal compliance standards such as NIST SP 800-53. Familiarity with security assessment tools, vulnerability scanning software, and certifications like CompTIA Security+ or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication are important soft skills in this position. These abilities are crucial for accurately evaluating security risks, maintaining regulatory compliance, and effectively collaborating with both technical and non-technical stakeholders.

What are popular job titles related to Rmf Analyst jobs in Silver Spring, MD? For Rmf Analyst jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Rmf Analyst jobs in Silver Spring, MD look for? The top searched job categories for Rmf Analyst jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Rmf Analyst jobs? Cities near Silver Spring, MD with the most Rmf Analyst job openings:
Infographic showing various Rmf Analyst job openings in Silver Spring, MD as of August 2026, with employment types broken down into 85% Full Time, 7% Part Time, 1% Temporary, and 7% Contract. Highlights an 81% Physical, 7% Hybrid, and 12% Remote job distribution, with an average salary of $110,960 per year, or $53.3 per hour.

Junior ISSO/ RMF Analyst - Defense

Tetrad Digital Integrity LLC

Arlington, VA โ€ข On-site

$125K - $140K/yr

Full-time

This job post hasย expired 1 day ago.ย Applications are no longer accepted.


Job description

Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments where mission, complexity, and trust intersect. Our single focus has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years!
TDI is seeking a Junior Cloud RMF Analyst to support RMF and security execution for a mission-critical cloud-hosted defense system. This is a growth role for an early-career cybersecurity professional who is organized, coachable, mission-focused, and ready to build real-world experience in DoW (USMC) cloud security and RMF operations. The role is designed for candidates with a solid foundation in cybersecurity, an active clearance, and the discipline to operate in a high-visibility environment where accuracy, follow-through, and customer trust matter.
You will work alongside experienced ISSOs, ISSMs, and engineering teams to support the RMF engine room: maintaining artifact quality, tracking POA&Ms, collecting and organizing evidence, supporting Continuous Monitoring, and helping ensure that documentation stays aligned to system reality as the environment evolves. If you are the kind of person who learns quickly, writes clearly, stays organized under pressure, and wants to grow into a cloud-savvy ISSO role supporting consequential national security systems, we want to meet you.
This position will require hybrid commute to the DC area.
RESPONSIBILITIES:
  • Support day-to-day RMF execution across the system lifecycle under the guidance of senior cybersecurity staff.
  • Assist with development and maintenance of RMF artifacts including SSPs, SAR support materials, POA&Ms, control implementation details, evidence mappings, and supporting documentation.
  • Collect, organize, and maintain evidence needed to support assessments, audits, Continuous Monitoring, and authorization activities.
  • Support POA&M management with discipline: track remediation items, owners, due dates, status updates, and closure evidence.
  • Help ensure documentation, evidence, and system reality remain aligned as approved changes occur through normal governance and configuration management processes.
  • Support Continuous Monitoring activities by maintaining artifact freshness, tracking recurring deliverables, and helping prepare metrics and status updates.
  • Review vulnerability scan outputs, STIG findings, and remediation documentation to support compliance tracking and risk reduction efforts.
  • Coordinate with engineering, platform, and DevSecOps teams to gather evidence and confirm implementation details for security controls.
  • Support security documentation and control traceability for cloud-hosted environments, including systems using modern platforms and managed cloud services.
  • Contribute to process improvement efforts that reduce manual compliance work and improve quality, consistency, and audit readiness.
  • Build practical knowledge of DoD RMF, NIST SP 800-53, cloud security concepts, and real-world control implementation in operational environments.
QUALIFICATIONS:
  • Active Secret clearance.
  • Bachelor's degree in cybersecurity, information systems, computer science, engineering, or a related field, or equivalent relevant experience.
  • 2+ years of experience in cybersecurity, cloud security, compliance, risk management, IT operations, or related technical work.
  • Security+ certification.
  • Foundational knowledge of RMF, NIST SP 800-53, FedRAMP, or related cybersecurity/compliance frameworks.
  • Basic familiarity with one or more cloud platforms such as AWS, Azure, or GCP, active path to obtain professional-level Google certification within a defined period after hire, is preferred.
  • Familiarity with core security concepts such as access control, logging and monitoring, vulnerability management, configuration management, encryption, and incident response.
  • Strong writing and communication skills with the ability to produce clear, professional, customer-ready documentation with guidance.
  • Strong organizational skills, attention to detail, and follow-through across multiple tasks in a fast-moving environment.
  • Ability to learn quickly, accept coaching, and work effectively with both technical and non-technical stakeholders.
PAY RANGE:
The anticipated salary range for this position is $125,000 - $140,000 . This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range.
TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States.
"TDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws."