Risk Management Framework Cybersecurity Analyst

Booz Allen Hamilton•Washington, DC
•$99,000 - $225,000•Onsite

About The Position

The Opportunity: Are you looking for an opportunity to share your experience in Risk Management Framework (RMF) and cybersecurity to support our country and safeguard our nation? As a RMF Cybersecurity Analyst, you will serve as the primary operational counterpart to the current Information Systems Security Officer (ISSO), partnering to manage daily compliance and strategic ATO renewals. Work with us as we secure and protect the client for the better. This position is located in Washington, DC.

Requirements

  • 3+ years of experience in Risk Management Framework (RMF) Assessment and Authorization (A&A)
  • Experience executing manual and automated A&A processes, including developing localized workflows and manual artifact generation when automated tools are unavailable
  • Experience independently developing cybersecurity RMF body of evidence (BOE) documentation such as System Security Plans (SSP) and RMF Control Family Plans
  • Knowledge of developing, managing, and submitting RMF ATO packages within the Enterprise Mission Assurance Support Service (eMASS)
  • TS/SCI clearance
  • HS diploma or GED

Nice To Haves

  • Experience formally serving as an ISSO, ISSM, or ISSE
  • Experience with USCG RMF processes and specific overlays
  • Experience with Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP), Assured Compliance Assessment Solution (ACAS), Vulnerability Remediation Asset Manager (VRAM), and Host Based Security System (HBSS)
  • Experience managing the Ports, Protocols, and Services Management (PPSM) matrix
  • Knowledge of evaluating system compliance against the Risk Management Framework (RMF) using DoD cybersecurity policies and industry best practices

Responsibilities

  • Lead and progressively drive RMF and Authorization to Operate (ATO) processes for multiple systems across their entire lifecycle.
  • Manage cybersecurity assessments, Assessment & Authorization (A&A) activities, and the practical implementation of security policies.
  • Oversee and enforce compliance with CNSSI-1253, NIST 800-37, and NIST 800-53 standards.
  • Validate security control implementations, perform system verification and testing, and generate technical remediation strategies.
  • Assess ACAS scans, STIGs, and security controls to identify vulnerabilities and engineer mitigations.
  • Translate complex technical risks into clear cybersecurity status reports for stakeholders and Authorizing Officials (AOs).

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service