Jobgether
Jobgether

RMF / CSAM Analyst

operationsfull-timeUS
SALARY
$75k – $104k/yr
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities:

    • Manage and maintain Risk Management Framework (RMF) and Cyber Security Assessment and Management (CSAM) activities to support continuous authorization and compliance of the IAM environment.
    • Ensure security and compliance alignment with FedRAMP, FISMA, NIST SP 800-63, OMB M-24-15, OMB M-21-31, and applicable federal cloud security requirements.
    • Maintain security controls, inheritance statements, authorization documentation, and evidence required to sustain the Authority to Operate (ATO).
    • Track, analyze, and support remediation of Plan of Action and Milestones (POA&M) items, vulnerability findings, CDM results, and Common Vulnerabilities and Exposures (CVEs).
    • Analyze security scan results, develop corrective action plans, monitor remediation progress, and escalate unresolved risks as appropriate.
    • Support security incident management, continuous monitoring, cybersecurity reporting, and maintenance of the required Cybersecurity Framework (CSF) scorecard.
    • Oversee compliance requirements related to event logging, encryption of data at rest and in transit, protection of sensitive user information, and secure handling of federal data.
    • Support supply chain risk management, federal records requirements, Controlled Unclassified Information (CUI) handling, Section 508 accessibility, and technology business management reporting.
    • Maintain accurate project, risk, schedule, compliance, and environment-support documentation needed for ongoing security authorization.
    • Collaborate closely with ISSOs, cybersecurity teams, technical stakeholders, and program leadership to communicate risks, requirements, findings, and remediation status.
    • Respond effectively to urgent security and compliance issues while maintaining consistent execution of recurring reporting and monitoring activities.
    • Requirements:

      • Bachelor’s degree in cybersecurity, information technology, computer science, or a related discipline, with at least 2 years of relevant professional experience.
      • Required Public Trust clearance and ability to operate effectively within a federal government security environment.
      • Strong knowledge of the NIST Risk Management Framework (RMF) and experience working with the CSAM tool or comparable security compliance platforms.
      • Experience with FedRAMP, FISMA, POA&M management, security control assessments, control inheritance, and continuous monitoring.
      • Familiarity with NIST SP 800-63, OMB M-21-31, OMB M-24-15, cloud security requirements, and federal cybersecurity policies.
      • Understanding of data encryption, secure logging, vulnerability management, cybersecurity controls, and compliance reporting.
      • Ability to analyze vulnerability and security assessment results, develop corrective action plans, and track remediation through completion.
      • Strong documentation, organization, recordkeeping, and attention-to-detail skills, particularly when managing security evidence and compliance artifacts.
      • Proficiency with Microsoft Office and compliance, security, or project-tracking tools.
      • Excellent written and verbal communication skills, with the ability to collaborate effectively with ISSOs, security professionals, technical teams, and other stakeholders.
      • Ability to balance recurring compliance responsibilities with urgent security issues and changing priorities.
      • Detail-oriented, dependable, collaborative, and committed to maintaining high cybersecurity standards in a federal environment.
      • Benefits:

        • Salary: $75,000–$104,000 USD annually, with final compensation determined by factors such as responsibilities, education, certifications, experience, internal equity, and market considerations.
        • Remote work environment.
        • 11 federal holidays.
        • Paid time off accrued each pay period.
        • Paid parental leave.
        • Three medical plan options with employer contributions.
        • Dental and vision insurance.
        • Company-paid short-term and long-term disability coverage.
        • Company-paid life and AD&D insurance.
        • 401(k) plan with competitive employer matching and vesting.
        • Continuing education assistance.
        • Medical, dependent care, and commuter Flexible Spending Accounts.
        • Employee Assistance Program.
        • Wellness benefits, including Calm Health and a WellHub gym subsidy.
        • 529 College Savings Plan.
        • Legal insurance.
        • Pet insurance.
        • Veterans are encouraged to apply
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
RMF / CSAM Analyst at Jobgether — Remote