1

Rmf Analyst Jobs (NOW HIRING)

Job Overview Job Title: Cyber Security Analyst - RMF (ISSO) Location : MacDill, FL This position is pending contract award. Job Responsibilities Trace Systems is seeking an experienced ISSO - RMF ...

Cyber Analyst

Honolulu, HI · On-site

$120 - $130/hr

The Cyber Analyst will provide cybersecurity oversight, RMF support, and program-level security guidance for critical Army and DoD systems and networks. This is an opportunity to directly support ...

New

Showing results 21-40

Rmf Analyst information

See salary details

$39.5K

$107.3K

$141K

How much do rmf analyst jobs pay per year?

As of Aug 21, 2026, the average yearly pay for rmf analyst in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is an RMF analyst?

An RMF (Risk Management Framework) Analyst is responsible for ensuring IT systems comply with security regulations and frameworks, such as NIST 800-53. They assess risks, implement security controls, and help organizations maintain authorization to operate (ATO) for their systems. RMF Analysts work closely with security teams, auditors, and system owners to document risks and remediation efforts. Their role is crucial in maintaining cybersecurity compliance for government and private-sector organizations handling sensitive data.

What are the typical daily responsibilities of an RMF analyst?

As an RMF Analyst, your daily responsibilities often include conducting security assessments, preparing documentation to support system accreditation, reviewing compliance with information security policies, and coordinating with system owners to address security risks. You may also be responsible for monitoring ongoing system changes, updating risk assessment reports, and supporting remediation activities based on audit findings. Most RMF Analysts work as part of a cybersecurity or compliance team, collaborating closely with IT personnel, auditors, and management to maintain a secure organizational environment. The work requires a mix of independent analysis and team-oriented problem-solving, making communication and attention to detail key to your success.

What are the key skills and qualifications needed to thrive in the RMF analyst position, and why are they important?

To thrive as an RMF Analyst, you need a thorough understanding of the Risk Management Framework (RMF), information security policies, and federal compliance standards such as NIST SP 800-53. Familiarity with security assessment tools, vulnerability scanning software, and certifications like CompTIA Security+ or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication are important soft skills in this position. These abilities are crucial for accurately evaluating security risks, maintaining regulatory compliance, and effectively collaborating with both technical and non-technical stakeholders.

What does an RMF analyst do?

An RMF analyst is responsible for implementing and managing the Risk Management Framework (RMF) to ensure the security of information systems. They assess security controls, conduct risk assessments, and prepare documentation to meet compliance standards, often using tools like NIST guidelines. This role requires knowledge of cybersecurity principles and attention to detail to protect organizational assets.
More about Rmf Analyst jobs

What cities are hiring for Rmf Analyst jobs?

Cities with the most Rmf Analyst job openings:

What are the most commonly searched types of Rmf Analyst jobs?

The most popular types of Rmf Analyst jobs are:

What states have the most Rmf Analyst jobs?

States with the most job openings for Rmf Analyst jobs include:

Infographic showing various Rmf Analyst job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, 5% Part Time, and 6% Contract. Highlights an 80% Physical, 9% Hybrid, and 11% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.

RMF Analyst II with Security Clearance

American Systems Corporation

Oak Ridge, TN • On-site

$70K - $100K/yr

Other

Medical, Retirement, PTO

Posted 23 days ago


Job description

Now Hiring at AMERICAN SYSTEMS Epsilon, Inc. has joined AMERICAN SYSTEMS! As one organization, we offer expanded resources, streamlined operations, and increased opportunities for growth and development. Join us to be part of a dynamic, collaborative environment dedicated to innovation and customer success. Responsibilities An Average Day: As the RMF Analyst II you will directly liaison with the government customer to manage the review, audit, and authorization of Risk Management Framework (RMF) assessment and authorization (A&A)/ATO Packages and for IT systems of varying size and complexity. In this role you will perform hands-on artifact review along with package management and review. Additionally, in this position you will: * Directly support the customer in the oversight of multiple system boundaries. * Make recommendations regarding the selection of cost-effective security controls to mitigate risk (e.g., protection of information, systems and processes). * Ensure consistent application of cybersecurity standards across multiple information systems. * Ensure all new cybersecurity projects meet or integrate cybersecurity standards into their development. * Author detailed security assessment reports and plans of action and milestones (POA&Ms), Risk Assessment Reports (RARs), and other artifacts associated with the RMF process. * Conduct in-depth analysis of complex systems and their interconnections through RMF. * Participate in high-level discussions about organizational risk management strategies. * Recommend improvements to RMF processes and tools to enhance efficiency and effectiveness. * Review and approve system security plans and other RMF documentation. * Make recommendations regarding the selection of cost-effective security controls to mitigate risk (e.g., protection of information, systems and processes). Qualifications * As a requirement of this position, all candidates must be a U.S. Citizen. In accordance with 8 U.S.C. 1324b(a)(2)(C) , Epsilon will not consider candidates for this position who do not meet the aforementioned conditions. * Must be able to attain and retain DoE L, or DoD Secret clearance. * Five (5) or more years of experience in the Cybersecurity field or combination of related education and experience. * Active Certified Information Systems Security Professional (CISSP) certification from ISC2. * Experience with assessment and authorization (A&A). * Experience with assessing and validating RMF, NIST, and other security controls. * RMF experience in package generation and assessment. * Visio diagram creation and modification. * RMF documentation creation and modification (SSP, CCB, COOP, etc.). * Familiarity with NIST 800-53 controls and applicable overlays. * Ability to provide security assessment reports that cover risks that the client should be aware of and mitigate risk with residual risks remaining. * Desired security certifications and qualifications: Security+ Ce, CySA+, SSCP, GSEC, GICSP, CND, CCNA Security, or equivalent. * Must be within a 2-hour commute of the customer location and will be required to travel onsite based on customer request. Pay Transparency Statement AMERICAN SYSTEMS is committed to pay transparency for our applicants and employee-owners. The salary range for this position is USD $70,000.00/Yr. - USD $100,000/Yr. Actual compensation will be determined based on several factors permitted by law. AMERICAN SYSTEMS provides for the welfare of its employees and their dependents through a comprehensive benefits program by offering healthcare benefits, paid leave, retirement plans, insurance programs, and education and training assistance. EEO Statement EEO Race/Sex/Disability Status/Veteran Status