About The Position

The Service Delivery Center is made up of high-performing, US-based resources who work closely with our experienced professionals to deliver project-based work and managed services to our federal clients. The Service Delivery Center is a core component of the Government & Public Sector practice (GPS). This role is part of our Cybersecurity – Strategy, Risk, Compliance & Resiliency (“SRC&R”) team within our Service Delivery Center. This team assists our clients with aligning a security management strategy with their business goals by assessing, designing, training, implementing and operating cybersecurity processes and solutions. This function is supported by our strategic alliances with third-party vendors and leveraging cybersecurity frameworks (e.g. NIST CSF, NIST 800-53r5, NIST 800-37r2). The Analyst supports Information System Security Officer (ISSO) and and Security Control Assessment (SCA) support across the NIST Risk Management Framework (RMF) lifecycle. Working under the direction of senior team members, the Analyst helps maintain authorization documentation, organize and evaluate evidence, prepare systems for assessment, track remediation activities, execute continuous monitoring tasks and keep system records current. This role is designed for an early-career practitioner who wants to build strong, hands-on federal RMF delivery experience.

Requirements

  • Working knowledge of federal cybersecurity requirements and standards, including NIST SP 800-37, NIST SP 800-53 and 800-53A, FIPS 199 and 200, and FISMA.
  • Understanding of the NIST Risk Management Framework lifecycle and the roles of system owners, ISSOs, ISSMs, assessors and Authorizing Officials.
  • Ability to analyze technical and procedural information and translate it into clear, accurate security documentation.
  • Strong attention to detail when reviewing evidence, maintaining trackers and updating authorization artifacts.
  • Ability to organize multiple assignments, meet deadlines and follow established quality-control procedures.
  • Clear written and verbal communication with technical stakeholders, client personnel and engagement team members.
  • Bachelor's degree in cybersecurity, information technology, information systems, computer science, engineering, business or a related field.
  • 1-3+ years of experience in cybersecurity, technology risk, compliance or information technology, including hands-on experience supporting federal RMF activities.
  • Ability to obtain and maintain a secret level clearance
  • Must be comfortable working in a hybrid environment
  • Experience developing or maintaining RMF documentation, collecting and organizing control evidence, supporting assessment readiness, tracking POA&Ms or executing continuous monitoring activities.
  • Experience in one or more of the following areas: Federal authorization package development and maintenance. NIST SP 800-53 control implementation statements and evidence mapping. Security control assessment preparation and response coordination. POA&M tracking, remediation support or continuous monitoring reporting. Federal governance, risk and compliance tools such as eMASS, JCAM, CSAM or Xacta. Technical security artifacts such as network diagrams, inventories, vulnerability scans, STIG or CIS benchmark results, change records or configuration data.
  • Flexibility to travel up to 20%.

Nice To Haves

  • CompTIA Security+, ISC2 CGRC or another relevant cybersecurity or risk management certification.
  • Prior experience supporting a federal agency, consulting engagement, service delivery center or managed service.

Responsibilities

  • Support RMF delivery for assigned federal information systems by maintaining documentation, tracking actions and helping system owners and government security personnel complete authorization activities.
  • Support RMF Prepare activities by maintaining system information, stakeholder lists, asset and component inventories, authorization boundary information, data-flow documentation, interconnections and risk context.
  • Assist with information-type identification, NIST SP 800-60 mapping and FIPS 199 security categorization, and document the rationale and supporting information for review.
  • Support control baseline selection and tailoring by documenting overlays, scoping decisions, organization-defined parameters, common controls and system-specific responsibilities.
  • Draft and update authorization artifacts, including System Security Plans, control implementation statements, inventories, diagrams, assessment-readiness materials and supporting appendices.
  • Collect, organize and map policies, procedures, configurations, screenshots, tickets, scan outputs and other evidence to applicable NIST SP 800-53 controls and assessment objectives.
  • Review implementation statements and evidence for completeness, consistency and traceability, and elevate gaps or conflicting information to senior team members.
  • Prepare evidence packages, interview materials, document-request trackers and response logs to help systems move efficiently through security control assessments.
  • Participate in evidence-gathering sessions and control interviews with system owners, engineers, application teams and assessors; capture decisions, action items and follow-up requests.
  • Assist with drafting assessment responses, findings, risk statements and corrective actions while preserving the independence of the assessment team.
  • Create and maintain POA&M records, including weaknesses, responsible parties, milestones, scheduled completion dates, remediation evidence and closure documentation.
  • Track POA&M progress, follow up on overdue actions, validate that required evidence has been provided and escalate schedule or risk issues.
  • Execute continuous monitoring activities, including scheduled control reviews, vulnerability and configuration reporting, evidence refreshes and recurring status deliverables.
  • Support security impact analyses for proposed system changes and document the affected components, controls, evidence and authorization artifacts.
  • Review vulnerability scan results, STIG or CIS benchmark results and configuration data; help connect technical findings to NIST controls and remediation activities.
  • Maintain accurate system records, workflows and authorization artifacts in federal governance, risk and compliance tools such as eMASS, JCAM, CSAM or Xacta.
  • Perform first-level quality checks using established templates and checklists to identify missing information, inconsistent dates, unsupported conclusions and formatting issues.
  • Track assigned deliverables and commitments, communicate progress clearly and raise blockers or emerging risks promptly.
  • Collaborate effectively with engagement team members and client stakeholders, incorporate feedback and complete assigned work within expected timeframes.
  • Stay current on federal cybersecurity requirements and actively develop technical, writing and RMF delivery skills.

Benefits

  • medical and dental coverage
  • pension and 401(k) plans
  • a wide range of paid time off options
  • flexible vacation policy
  • time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service