1

Rmf Analyst Jobs (NOW HIRING)

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

The RMF Cyber Security Analyst Senior will provide support for a program, an organization, system, or an enclave; provides support for proposing, coordinating, implementing, and enforcing information ...

Posted today

We are seeking a highly skilled Cyber Analyst - RMF Specialist in Colorado Springs, CO to support the critical North American Aerospace Defense Command and United States Northern Command (N&NC ...

New

We are seeking a highly skilled Cyber Analyst - RMF Specialist in Colorado Springs, CO to support the critical North American Aerospace Defense Command and United States Northern Command (N&NC ...

New

Showing results 41-60

Rmf Analyst information

See salary details

$39.5K

$107.3K

$141K

How much do rmf analyst jobs pay per year?

As of Aug 21, 2026, the average yearly pay for rmf analyst in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is an RMF analyst?

An RMF (Risk Management Framework) Analyst is responsible for ensuring IT systems comply with security regulations and frameworks, such as NIST 800-53. They assess risks, implement security controls, and help organizations maintain authorization to operate (ATO) for their systems. RMF Analysts work closely with security teams, auditors, and system owners to document risks and remediation efforts. Their role is crucial in maintaining cybersecurity compliance for government and private-sector organizations handling sensitive data.

What are the typical daily responsibilities of an RMF analyst?

As an RMF Analyst, your daily responsibilities often include conducting security assessments, preparing documentation to support system accreditation, reviewing compliance with information security policies, and coordinating with system owners to address security risks. You may also be responsible for monitoring ongoing system changes, updating risk assessment reports, and supporting remediation activities based on audit findings. Most RMF Analysts work as part of a cybersecurity or compliance team, collaborating closely with IT personnel, auditors, and management to maintain a secure organizational environment. The work requires a mix of independent analysis and team-oriented problem-solving, making communication and attention to detail key to your success.

What are the key skills and qualifications needed to thrive in the RMF analyst position, and why are they important?

To thrive as an RMF Analyst, you need a thorough understanding of the Risk Management Framework (RMF), information security policies, and federal compliance standards such as NIST SP 800-53. Familiarity with security assessment tools, vulnerability scanning software, and certifications like CompTIA Security+ or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication are important soft skills in this position. These abilities are crucial for accurately evaluating security risks, maintaining regulatory compliance, and effectively collaborating with both technical and non-technical stakeholders.

What does an RMF analyst do?

An RMF analyst is responsible for implementing and managing the Risk Management Framework (RMF) to ensure the security of information systems. They assess security controls, conduct risk assessments, and prepare documentation to meet compliance standards, often using tools like NIST guidelines. This role requires knowledge of cybersecurity principles and attention to detail to protect organizational assets.
More about Rmf Analyst jobs

What cities are hiring for Rmf Analyst jobs?

Cities with the most Rmf Analyst job openings:

What are the most commonly searched types of Rmf Analyst jobs?

The most popular types of Rmf Analyst jobs are:

What states have the most Rmf Analyst jobs?

States with the most job openings for Rmf Analyst jobs include:

Infographic showing various Rmf Analyst job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, 5% Part Time, and 6% Contract. Highlights an 80% Physical, 9% Hybrid, and 11% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.

Risk Management Framework Analyst

Booz Allen Hamilton, Inc.

Suffolk, VA • On-site, Remote

$86K - $198K/yr

Full-time, Part-time

Medical, Life, Retirement, PTO

Posted 10 days ago


Booz Allen Hamilton rating

8.9

Company rating: 8.9 out of 10

Based on 49 frontline employees who took The Breakroom Quiz

10th of 72 rated business consultants


Job description


Remote Work:
No
Job Number:
R0246612
Location:
Suffolk,VA,US
Share job via:
Share
Risk Management Framework Analyst
The Opportunity:
Function as a Risk Management Framework (RMF) Analyst as part of a team ensuring National Institute of Standards and Technology (NIST) management, operation, technical, and privacy security control implementation compliance for complex DoD information systems. Provide support for executing full Authority to Operate (ATO) certification package and risk management functions, measuring risk, examining system documentation, and reviewing appropriate system, testing system technical security configuration settings, reviewing scan results, Platform IT (PIT), and developing findings reports. Demonstrate subject matter expertise in NIST security guidance using the NIST Risk Management Framework (RMF) and Cybersecurity Framework (CSF).
You Have:
  • 5+ years of experience with providing security guidance using NIST, RMF, CSF, DoW, and local security policies
  • Experience with using Enterprise Mission Assurance Support Service (eMASS) to document and track the RMF process for an ATO package
  • Experience with planning and executing applicable security controls, analyzing assessment procedures, and identification and using required tools
  • Experience in interfacing with information assurance managers, including preparing and reviewing documentation, including Systems Security Plans (SSPs), Risk Assessment Reports, Implementation Plan, Assessment and Authorization (A&A), Certification and Accreditation (C&A) packages, and Plan of Actions and Milestones (POA&Ms)
  • Knowledge of NIST Contingency Planning, POA&M management, and DoD continuous auditing, monitoring, and assurance
  • Top Secret clearance
  • Bachelor's degree in an Engineering, Computer Science, Cybersecurity, Information Technology, or Information Systems field and 5+ years of experience in national level intelligence, tactical or strategic communications systems, Command and Control applications and architectures, and serving in senior level positions, or 10+ years of experience in national level intelligence, tactical or strategic communications systems, Command and Control applications and architectures, and serving in senior level positions in lieu of a degree
  • Cybersecurity DoDM 8140 Intermediate or Advanced level Certifications, such as CGRC/CAP, Security+, Security X, CASP+, Cloud+, CISA, CISM, or CISSP

Nice If You Have:
  • Experience with DoD Cybersecurity policies, directives, and DoD STIGs or SRGs
  • Experience with running scans using Tenable ACAS, Trellix ePO, ENS, ESS/HBSS, or Tanium
  • Experience with assessing organizational risks and recommending mitigation strategies

Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Top Secret clearance is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,800.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.
Identity Statement
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Candidate AI Usage Policy
AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.
Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.

Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
Not ready to apply? Join our Talent Community and sign up for job alerts.

What Booz Allen Hamilton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Booz Allen Hamilton logo

About Booz Allen Hamilton

Sourced by ZipRecruiter

Booz Allen Hamilton is a leading provider of management and technology consulting services to the US government in defense, intelligence, and civil markets. Headquartered in McLean, Virginia, the firm also serves major corporations, institutions, and not-for-profit organizations. Founded in 1914 by Edwin G. Booz, the company has a long-standing tradition of helping clients achieve success by delivering a wide range of consulting services that include strategic planning, human capital and learning, communication, systems development, and others. The company's mission is to empower people to change the world, and it has a reputation for maintaining the highest standards of integrity and-excellence.

Industry

It services

Company size

10,000+ Employees

Headquarters location

McLean, VA, US

Year founded

1914