1

Rmf Analyst Jobs in Silver Spring, MD (NOW HIRING)

... SP 800-53 / 800-37 RMF, FedRAMP baselines, ICD 503 • Perform risk assessments, control ... analyses • Implement and manage RMF lifecycle activities (Categorize → Monitor) • Track and ...

RMF Engineering is an innovative, top-ranked, national engineering firm that specializes in ... Problem analysis and assessment capability * Appropriate decision making when required * Planning ...

... SP 800-53 / 800-37 RMF, FedRAMP baselines, ICD 503 • Perform risk assessments, control ... analyses • Implement and manage RMF lifecycle activities (Categorize → Monitor) • Track and ...

Senior HR Generalist

Baltimore, MD · On-site

$80K - $90K/yr

RMF Engineering is an innovative, top-ranked, national engineering firm that specializes in ... Analysis Market trends and advise management on key metrics * Implementation and maintenance of ...

... SP 800-53 / 800-37 RMF, FedRAMP baselines, ICD 503 • Perform risk assessments, control ... analyses • Implement and manage RMF lifecycle activities (Categorize → Monitor) • Track and ...

RMF Engineering is an innovative, top-ranked, national engineering firm that specializes in ... Problem analysis and assessment capability * Appropriate decision making when required * Planning ...

In this role, you will perform cybersecurity and Risk Management Framework (RMF) activities, while ... As a Cybersecurity Analyst , you will be part of an integrated government team where you will ...

In this role, you will perform cybersecurity and Risk Management Framework (RMF) activities, while ... As a Cybersecurity Analyst , you will be part of an integrated government team where you will ...

Showing results 41-60

Rmf Analyst information

See Silver Spring, MD salary details

$40.8K

$111K

$145.8K

How much do rmf analyst jobs pay per year?

As of Aug 8, 2026, the average yearly pay for rmf analyst in Silver Spring, MD is $110,960.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,600.00 and $134,400.00 per year, depending on experience, location, and employer.

What are the typical daily responsibilities of an RMF analyst?

As an RMF Analyst, your daily responsibilities often include conducting security assessments, preparing documentation to support system accreditation, reviewing compliance with information security policies, and coordinating with system owners to address security risks. You may also be responsible for monitoring ongoing system changes, updating risk assessment reports, and supporting remediation activities based on audit findings. Most RMF Analysts work as part of a cybersecurity or compliance team, collaborating closely with IT personnel, auditors, and management to maintain a secure organizational environment. The work requires a mix of independent analysis and team-oriented problem-solving, making communication and attention to detail key to your success.

What is an RMF analyst?

An RMF (Risk Management Framework) Analyst is responsible for ensuring IT systems comply with security regulations and frameworks, such as NIST 800-53. They assess risks, implement security controls, and help organizations maintain authorization to operate (ATO) for their systems. RMF Analysts work closely with security teams, auditors, and system owners to document risks and remediation efforts. Their role is crucial in maintaining cybersecurity compliance for government and private-sector organizations handling sensitive data.

What are the key skills and qualifications needed to thrive in the RMF analyst position, and why are they important?

To thrive as an RMF Analyst, you need a thorough understanding of the Risk Management Framework (RMF), information security policies, and federal compliance standards such as NIST SP 800-53. Familiarity with security assessment tools, vulnerability scanning software, and certifications like CompTIA Security+ or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication are important soft skills in this position. These abilities are crucial for accurately evaluating security risks, maintaining regulatory compliance, and effectively collaborating with both technical and non-technical stakeholders.

What are popular job titles related to Rmf Analyst jobs in Silver Spring, MD? For Rmf Analyst jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Rmf Analyst jobs in Silver Spring, MD look for? The top searched job categories for Rmf Analyst jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Rmf Analyst jobs? Cities near Silver Spring, MD with the most Rmf Analyst job openings:
Infographic showing various Rmf Analyst job openings in Silver Spring, MD as of August 2026, with employment types broken down into 85% Full Time, 7% Part Time, 1% Temporary, and 7% Contract. Highlights an 81% Physical, 7% Hybrid, and 12% Remote job distribution, with an average salary of $110,960 per year, or $53.3 per hour.

Security Analyst

Core One

Mclean, VA • On-site

Full-time

Re-posted 14 days ago


Job description

Job Summary:
Core One is a dynamic company focused on providing analytical, operational, and technical solutions to national security challenges. They are seeking a Security Analyst to support cybersecurity operations, compliance, and risk management for FedRAMP-authorized and Intelligence Community systems, ensuring adherence to stringent federal security requirements.
Responsibilities:
• Lead and support FedRAMP Moderate/High and IC ATO authorization processes
• Develop, review, and maintain security documentation: System Security Plans (SSP), Security Assessment Reports (SAR), Plan of Action & Milestones (POA&M)
• Ensure compliance with NIST SP 800-53 / 800-37 RMF, FedRAMP baselines, ICD 503
• Perform risk assessments, control assessments, and gap analyses
• Implement and manage RMF lifecycle activities (Categorize → Monitor)
• Track and manage POA&M remediation activities
• Facilitate security control inheritance and shared responsibility models
• Execute continuous monitoring strategies and reporting
• Analyze security posture using Vulnerability scans and Configuration compliance
• Produce monthly/quarterly ConMon deliverables
• Monitor and analyze security events and alerts
• Support incident response and forensic analysis
• Coordinate with SOC teams and stakeholders for threat mitigation
• Conduct root cause analysis and lessons learned
• Secure cloud environments aligned with FedRAMP controls
• Implement identity and access controls
• Support 3PAO assessments and audits
• Prepare evidence artifacts for FedRAMP JAB/Agency ATO reviews and Inspector General (IG) audits
• Coordinate with internal/external auditors
• Utilize security tools for monitoring and compliance: Splunk, Sentinel, Vulnerability management tools, RSA Archer, ServiceNow
• Support automation of compliance and reporting workflows
• Act as liaison between Engineering teams, ISSOs / ISSMs, and Compliance and audit teams
• Provide security guidance during system design and change management
• Mentor junior analysts and support team development
• Promote a culture of security-first engineering and compliance excellence
• Contribute to security governance and policy development
Qualifications:
Required:
• Active TS/SCI with Polygraph
• Bachelor's degree or higher in Cybersecurity, IT, or related field and 5+ years' experience in Cybersecurity in federal or IC environments OR Masters and 3+ years of experience in Cybersecurity in federal or IC environments
• Strong Knowledge of NIST RMF (800-37), NIST 800-53 controls, and FedRAMP requirements
• At least one of the following certifications: CISM or CISA, CompTIA Security+ (baseline), Certified Authorization Professional (CAP), CCSP (cloud security)
• Experience in the following tools: NIST 800-53, RMF, FedRAMP, ICD 503, RSA Archer, ServiceNow GRC, Splunk, Azure Sentinel, Nessus, ACAS, AWS GovCloud, Azure Government, GCP, SCAP, STIG Viewer
Preferred:
• Experience with cloud-native security tools
• Knowledge of Zero Trust Architecture
• Experience with cross-domain solutions
• Experience with ICD 503
• Familiarity with DevSecOps pipelines in regulated environments
Company:
Core One is the frontier of innovative ideas and creative solutions to solve our nation's most complex challenges. Founded in 2014, the company is headquartered in Sterling, USA, with a team of 201-500 employees. The company is currently Growth Stage.

Core One logo

About Core One

Sourced by ZipRecruiter

Industry

Guided missile and space vehicle manufacturing

Company size

51 - 200 Employees

Headquarters location

Sterling, VA, US