RMF IT Security Analyst with Security Clearance

apartmentSystem One Holdings, LLC placeBethesda calendar_month 
Job Title: RMF IT Security Analyst
Location: Bethesda, Maryland
Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings

Security Clearance: Public Trust Position Summary

The RMF IT Security Analyst serves as a mid-level cybersecurity professional. Working under Lead and Senior RMF personnel, the analyst independently supports RMF lifecycle activities, security assessments, continuous monitoring, and compliance initiatives while mentoring junior staff.
Work is primarily remote with occasional on-site meetings. Key Responsibilities
  • Support the implementation and maintenance of the NIST RMF program.
  • Develop, review, and maintain RMF documentation including SSPs, SARs, POA&Ms, and authorization packages.
  • Support system categorization, security control selection, assessments, authorization, and continuous monitoring.
  • Maintain the Risk Management Register and track remediation activities.
  • Support cybersecurity audits and assessments conducted by NIH, HHS, OIG, GAO, and other oversight organizations.
  • Support Cybersecurity Supply Chain Risk Management (C-SCRM) activities, including vendor documentation and SBOM reviews.
  • Manage or assist with Risk Mitigation Waivers, documentation, approvals, annual reviews, and tracking.
  • Coordinate contingency plan testing and document results and corrective actions.
  • Communicate risk posture and compliance status while collaborating with system owners, ISSOs, and technical teams.
  • Provide technical guidance and mentoring to junior analysts. Required Qualifications
Bachelor's degree in a related technical field (or equivalent experience) and 3–5 years supporting RMF, cybersecurity compliance, or information security programs. Preferred Qualifications
  • Experience supporting federal civilian agencies, including NIH, HHS, or other Federal agencies.
  • Familiarity with NIST RMF, NIST SP 800-37, NIST SP 800-53 Rev. 5, and the Joint Cybersecurity Assessment Methodology (JCAM).
  • Experience using eMASS or similar Governance, Risk, and Compliance (GRC) platforms.
  • Experience supporting cybersecurity audits, POA&M management, continuous monitoring, and contingency planning.
  • Knowledge of Cybersecurity Supply Chain Risk Management (C-SCRM).
  • Experience developing or reviewing SSPs, SARs, SAPs, POA&Ms, and Authorization Packages. Desired Certifications
  • ISC2 Certified in Cybersecurity (CC)
  • CompTIA Security+
  • CompTIA CySA+
  • CompTIA SecurityX (formerly CASP+)
  • CompTIA PenTest+
  • CAP/CGRC
  • CISSP
  • CISM Knowledge, Skills, and Abilities

Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity compliance. Ability to collaborate with system owners, ISSOs, and technical teams.

Work Environment

This position is primarily remote with occasional on-site meetings or support activities as required.

business_centerHigh salary

Security Guard

placeBethesda (MD)
orders. These duties may include:  •  3 Bethesda Metro Station  •  Friday and Saturday  •  2300 TO 0700  •  Payrate - $21.50 per hour  •  Access control for guests, tenants and vendors.  •  Enforcement of Client and Company policies and procedures.  •  Observation...
placeBethesda (MD)
About Us: At J.Jill, we believe our associates should be seen, valued, and celebrated. We support the advancement of our associates by harnessing their unique contributions to grow and improve, and our success is guided by a culture that values...
placeBethesda (MD)
Overview: The Front Desk Receptionist is responsible for greeting patients and completing their check-in and check-out process and will enter new patient information into the computer and review patient charts for accuracy and verification, ensure...