RMF Analyst IV

Chronos Operations, LLCRedstone Arsenal, AL
Onsite

About The Position

Chronos Operations, LLC is seeking an experienced RMF Analyst IV to provide oversight and resources needed to execute the contract requirements for the Army Materiel Command (AMC), Chief Information Office (CIO) across a wide range of cybersecurity tasks. The RMF Analyst IV conducts RMF analysis, System Security Plan development, and A&A coordination.

Requirements

  • Bachelor's degree in science, Technology, Engineering, Mathematics, IT, or business-related programs is required.
  • 8+ years of experience in Cybersecurity compliance/Risk Management Framework.
  • 8+ years of experience with RMF (NIST SP800-53, NIST SP 800-37 DoDI 8510.01), ATO packages, POA&M development, and system categorization is required.
  • Baseline and Full Computing Environment Certifications for IAT-II IAW DoD 8570.01-M (Security+ certification) required.
  • Must have an active Secret clearance with the ability to obtain TS with SCI eligibility.
  • Successfully pass background and drug screening
  • Experience with eMASS is required.
  • Must have high proficiency in the Microsoft Office suite and possess advanced skills and knowledge in programs like Word, Excel, PowerPoint, and Outlook
  • Experience extracting, transforming, and structuring data to support both exploratory analytics and operational reporting
  • Skillful time management and organizational skills to set and meet deadlines.
  • Ability to work both independently and within a team.
  • Ability to work effectively in a team environment encourages collaboration, innovation, and continuous improvement.
  • Ability to meet minimum clearance requirements.

Nice To Haves

  • 3+ years’ experience supporting DoD or federal programs is highly desirable
  • 3+ years’ experience supporting Army, DoD or federal programs is highly desirable
  • 3+ years’ experience with eMASS is preferred
  • Cybersecurity certifications like CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), or CISM (Certified Information Security Manager), or CGRC (Certified in Governance, Risk and Compliance), is required
  • Experience assessing Cyber Risk for Operational Technology (OT) such as Industrial Control Systems (ICS), SCADA, Facility-Related Control Systems (FRCS), and Platform IT (PIT) systems
  • Cybersecurity certifications like CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager), or CGRC (Certified in Governance, Risk and Compliance) are preferred.
  • Experience with cloud platforms like Amazon Web Services (AWS), Microsoft Azure, etc., and migrating customers/projects to the cloud
  • Experience working in a Unix/Linux environment
  • Experience working in cloud infrastructures
  • Must have an understanding of cloud technologies (e.g., AWS, Azure, GCP, Oracle) and Hybrid cloud environments

Responsibilities

  • Assist Senior RMF practitioner managing ATO packages, continuous monitoring plans, and eMASS documentation.
  • Deep understanding of cybersecurity frameworks, documentation, and technical validation processes, working closely with stakeholders and control assessors to ensure security and compliance.
  • Provide weekly reporting to senior task lead.
  • Assist in the optimization of current process to streamline approval process with Program Information Security System Manager (P-ISSM) prior to submissions to Authorizing Official (AO).
  • Track timely and high-quality completion of process tasks and milestones, and report on the status of key milestones to senior task lead.
  • Assist with overseeing the cybersecurity lifecycle from inception to completion.
  • Develop, review, and update documentation to ensure compliance with RMF and Continuous Monitoring requirements.
  • Evaluate and validate technical processes related to ATO (Authority to Operate) requirements, ensuring alignment with cybersecurity standards.
  • Assisting in the preparation and review of authorization information and documentation for RMF and Continuous Monitoring.
  • Assist with eMASS package completion and maintenance, including artifacts, self-assessments, and asset management.
  • Review project schedules, requirements, and risk assessments, offering recommendations to program stakeholders to enhance security posture.
  • Develop security plans, as well as assessment reports, plans of action, and milestones for remediation. Defines criticality or sensitivity of systems, performs categorization calculations, and recommends corrective action.
  • Recommend baseline security controls, assess changes in controls, and coordinate changes to security authorizations.
  • Conduct evaluations to verify that design and implementation meet requirements.
  • Confirm that all necessary supporting documents (e.g., Incident Response Plan, Configuration Management Plan, Contingency Plan) are present, complete, and have been reviewed and approved.
  • Confirm that every finding is identified and tracked in the POA&M. Ensure each POA&M item has a realistic mitigation strategy, defined resources, and a scheduled completion date.
  • Prepare test plans and conduct security control testing IAW with NIST SP800-53, DoDI 8510.01, NIST SP 800-37 Rev. 2
  • Supervisory duties as assigned.
  • Other duties as assigned.

Benefits

  • professional development is embedded in their employer’s core culture
  • opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world
  • on-the-job learning experiences
  • formal development programs
  • well-being programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service