1

Rmf Analyst Jobs (NOW HIRING)

Privacy Analyst

Washington, DC ยท On-site

$94K - $111K/yr

Previous experience as a privacy analyst, system analyst, ISSO, security control assessor, RMF analyst, or federal GRC analyst. * Knowledge of the Privacy Act of 1974, E-Government Act privacy ...

Showing results 41-60

Rmf Analyst information

See salary details

$39.5K

$107.3K

$141K

How much do rmf analyst jobs pay per year?

As of Sep 13, 2026, the average yearly pay for rmf analyst in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is an RMF analyst?

An RMF (Risk Management Framework) Analyst is responsible for ensuring IT systems comply with security regulations and frameworks, such as NIST 800-53. They assess risks, implement security controls, and help organizations maintain authorization to operate (ATO) for their systems. RMF Analysts work closely with security teams, auditors, and system owners to document risks and remediation efforts. Their role is crucial in maintaining cybersecurity compliance for government and private-sector organizations handling sensitive data.

What are the typical daily responsibilities of an RMF analyst?

As an RMF Analyst, your daily responsibilities often include conducting security assessments, preparing documentation to support system accreditation, reviewing compliance with information security policies, and coordinating with system owners to address security risks. You may also be responsible for monitoring ongoing system changes, updating risk assessment reports, and supporting remediation activities based on audit findings. Most RMF Analysts work as part of a cybersecurity or compliance team, collaborating closely with IT personnel, auditors, and management to maintain a secure organizational environment. The work requires a mix of independent analysis and team-oriented problem-solving, making communication and attention to detail key to your success.

What are the key skills and qualifications needed to thrive in the RMF analyst position, and why are they important?

To thrive as an RMF Analyst, you need a thorough understanding of the Risk Management Framework (RMF), information security policies, and federal compliance standards such as NIST SP 800-53. Familiarity with security assessment tools, vulnerability scanning software, and certifications like CompTIA Security+ or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication are important soft skills in this position. These abilities are crucial for accurately evaluating security risks, maintaining regulatory compliance, and effectively collaborating with both technical and non-technical stakeholders.

What does an RMF analyst do?

An RMF analyst is responsible for implementing and managing the Risk Management Framework (RMF) to ensure the security of information systems. They assess security controls, conduct risk assessments, and prepare documentation to meet compliance standards, often using tools like NIST guidelines. This role requires knowledge of cybersecurity principles and attention to detail to protect organizational assets.
More about Rmf Analyst jobs

What cities are hiring for Rmf Analyst jobs?

Cities with the most Rmf Analyst job openings:

What are the most commonly searched types of Rmf Analyst jobs?

The most popular types of Rmf Analyst jobs are:

What states have the most Rmf Analyst jobs?

States with the most job openings for Rmf Analyst jobs include:

What are popular job titles related to Rmf Analyst jobs?

For Rmf Analyst jobs, the most frequently searched job titles are:

Infographic showing various Rmf Analyst job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 88% Full Time, 6% Part Time, 1% Temporary, and 4% Contract. Highlights an 80% Physical, 7% Hybrid, and 13% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.

RMF Cyber Security Analyst - 306210

Virginia Beach, VA โ€ข On-site

Delaware Nation Industries
501 - 1,000 employees

$110K - $115K/yr

Full-time

Medical, Dental, Vision, Retirement

Re-posted 26 days ago


Job description

Delaware Nation Industries is supporting the Naval Surface Warfare Center Dahlgren Division Dam Neck Activity (NSWCDD DNA). We are providing enterprise management and technical support of the Naval Surface Warfare Center Dahlgren Division Dam Neck Activity (NSWC DD DNA) by providing assistance in policy, procedures, seat refresh, engineering/technical solutions, ordering to Next Generation Enterprise Network (NGEN) and the Naval Networking Environment (NNE) strategy.

Job Summary:   The RMF Analyst will assist in developing RMF accreditation packages and assist in maintaining Authorization to Operate (ATO) certifications for networked systems and applications used by the organization. The RMF Analyst will assist in the development of information system documentation and the provision of a designated set of common controls for the authorization package, including the executive summary, system security plan, privacy plan, security control assessment, privacy control assessment, and any relevant plans of action and milestones. This system certification documentation must comply with DoD and Civilian Agency policy focused on NIST 800-37, NIST 800-53 rev 4.

Responsibilities:

  • Monitor and assess existing Information Security Management and Security Technical Architecture, regulations, and controls (FIPS, NIST, DISN Connection Process Guide(CPG), Navy RMF Process Guide (RPG), Navy Testing Guidance)
  • Assess proposed Information Security Management and Security Technical Architecture, regulations, and controls (FIPS, NIST, DISN CPG, Navy RPG, Navy Testing Guidance)
  • Maintain regular meetings/notes and informal dialog with RDT&E CORE/LAB managers and ISSOs to keep them abreast of upcoming Information System Security Manager (ISSM) requirements and to gather specifics on their capability and core support requirements and trends
  • Maintain records in the Enterprise Mission Assurance Support Service (eMASS)
  • Evaluating technical testing from Assured Compliance Assessment Solution (ACAS) scans, Evaluate STIG, eMASSter), and Security Technical Implementation Guide Viewer tool using FMATS or other NAVSEA or DoD-approved toolset.
  • Monitor security access, passwords, badges, log-ins, to keep a site or system safe
  • Use firewalls and information security standards to keep their organization secure
  • Perform security assessments, vulnerability testing and risk analysis
  • Conduct security audits internal and external
  • Identify the cause of security breaches

Requirements

  • DoD Top Secret Security Clearance
  • 5+ Years of Experience in Cyber Security
  • Cyber Security Workforce level IAM II/III CASP,CISM, or CISSP required
  • Bachelor Degree or Equivalent Work Experience
  • Familiarity with NIST IT Security Special Publication (SP) 800 Series with emphasis on NIST SP 800-37 and NIST SP 800-53 rev 4/5
  • Forensics analysis familiarity
  • Experienced STIG reviewer
  • Microsoft Visio and Microsoft Project user

Desired:

  • Navy Qualified Validator (NQV) Level II
  • Familiarity with ACAS, RedSeal, and Carbon Black
  • Familiarity with the Vulnerability Remediation Asset Manager (VRAM) web tool
  • Familiarity with the Continuous Monitoring and Risk Scoring (CMRS) web tool

Benefits

Benefits Include:

  • Covers 100% of employee benefit premiums, including Medical (PPO or HDHP Option), Vision, Dental
  • Matching 401K
  • Short- and Long-Term Disability
  • Pet Insurance
  • Professional Development/Education Reimbursement
  • Parking and Transit Benefits for NY, NJ, ATL, and DC Metro areas

Other Duties:

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

Salary Compensation: $110,000-$115,000