RMF Analyst

ECS Tech IncSierra Vista, AZ
Onsite

About The Position

Everforth ECS is seeking a skilled RMF Analyst to support cybersecurity compliance and system authorization efforts for a Comply to Connect (C2C) system in the DoW environment. This role is responsible for executing Risk Management Framework (RMF) activities, managing security artifacts, and ensuring systems meet DoD cybersecurity requirements. The ideal candidate brings hands-on experience with eMASS, understands DoD cyber governance, and can bridge the gap between security compliance and operational system integration.

Requirements

  • Hands-on experience with RMF (Risk Management Framework)
  • Hands-on experience with eMASS
  • Hands-on experience with DoD cybersecurity governance (e.g., NIST 800-53, DoD 8510.01)
  • Experience supporting ATO processes and continuous monitoring
  • Familiarity with Comply to Connect (C2C) concepts or similar zero-trust/network access control frameworks, to best support the RMF activities for the C2C system
  • Ability to assess system changes for security risk and compliance impact
  • Strong written and verbal communication skills
  • Top Secret Security Clearance

Responsibilities

  • Execute RMF activities in alignment with NIST RMF and DoD 8510.01
  • Develop, maintain, and manage Body of Evidence (BoE) artifacts
  • Administer and maintain records in eMASS
  • Support full Authority to Operate (ATO) lifecycle: Initial authorization, ATO sustainment, Reauthorization activities
  • Maintain and update System Security Plans (SSPs), Security Control Assessments (SCAs) support artifacts, Plan of Action & Milestones (POA&M)
  • Perform and support continuous monitoring (ConMon) activities across multiple systems and enclaves
  • Track vulnerabilities, findings, and POA&M remediation efforts
  • Ensure systems maintain compliance with DoD cybersecurity
  • Conduct security impact analysis for infrastructure changes, system upgrades, configuration modifications, new technology integrations
  • Validate changes against RMF controls and requirements prior to production deployment
  • Provide guidance to engineering and operations teams on secure implementation strategies, Defense-in-depth principles, Security architecture best practices
  • Help maintain a secure, compliant, and defensible enterprise environment
  • Communicate technical findings clearly to both technical and non-technical stakeholders
  • Support coordination with Program Managers (PMs), Information System Security Officers (ISSOs), System Owners / Service Owners
  • Document findings and recommendations in clear, actionable formats
  • Work closely with cybersecurity, engineering, and operations teams
  • Contribute to process improvements, documentation, and best practices
  • Support knowledge sharing across teams and programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service