Risk Management Framework Cybersecurity Analyst

Booz Allen Hamilton•Usa, DC
•Onsite

About The Position

Risk Management Framework Cybersecurity Analyst The Opportunity: Are you looking for an opportunity to share your experience in Risk Management Framework ( RMF ) and cybersecurity to support our country and safeguard our nation? As an RMF Cybersecurity Analyst, you will serve as the primary operational counterpart to the current Information Systems Security Officer ( ISSO ) , partnering to manage daily compliance and strategic ATO renewals. Work with us as we secure and protect the client for the better. This position is located in Washington, DC.

Requirements

  • 3+ years of experience in RMF A & A
  • Experience executing manual and automated A & A processes, including developing localized workflows and manual artifact generation when automated tools are unavailable
  • Experience independently developing cybersecurity RMF body of evidence ( BOE ) documentation such as System Security Plans ( SSP ) and RMF Control Family Plans
  • Knowledge of developing, managing, and submitting RMF ATO packages within the Enterprise Mission Assurance Support Service ( eMASS )
  • TS/SCI clearance
  • HS diploma or GED

Nice To Haves

  • Experience formally serving as an ISSO, ISSM, or ISSE
  • Experience with USCG RMF processes and specific overlays
  • Experience with Security Technical Implementation Guides ( STIGs ) , Security Content Automation Protocol ( SCAP ) , Assured Compliance Assessment Solution ( ACAS ) , Vulnerability Remediation Asset Manager ( VRAM ) , and Host Based Security System ( HBSS )
  • Experience managing the Ports, Protocols, and Services Management ( PPSM ) matrix
  • Knowledge of evaluating system compliance against RMF using DoD cybersecurity policies and industry best practices

Responsibilities

  • Lead and progressively drive RMF and Authorization to Operate ( ATO ) processes for multiple systems across their entire lifecycle.
  • Manage cybersecurity assessments, Assessment and Authorization ( A & A ) activities, and the practical implementation of security policies .
  • Oversee and enforce compliance with CNSSI-1253, NIST 800-37, and NIST 800-53 standards.
  • Validate security control implementations, perform system verification and testing, and generate technical remediation strategies.
  • Assess ACAS scans, STIGs, and security controls to identify vulnerabilities and engineer mitigations.
  • Translate complex technical risks into clear cybersecurity status reports for stakeholders and Authorizing Offi cia ls ( AOs ) .

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service