Senior RMF Security Analyst
Job Description
Diligent Solutions is seeking a Senior RMF Security Analyst to support federal information systems through RMF Steps 1–3. In this hands-on role, you will develop and maintain RMF security documentation to help systems achieve, maintain, and renew Authorities to Operate (ATOs).
This position is based in Gaithersburg, MD on a hybrid schedule, with work focused on producing accurate, complete, and review-ready authorization package artifacts.
Key Responsibilities
- Collect and update general system information for federal RMF documentation.
- Create and maintain system records in CSAM, including system identification information, system descriptions, and technical narratives.
- Prepare and update Privacy Threshold Analyses (PTAs) and Privacy Impact Assessments (PIAs).
- Perform and update FIPS 199 security categorizations.
- Perform and update E-Authentication Risk Assessments.
- Identify common and inherited security controls, including controls inherited from FedRAMP-authorized services.
- Develop and update compliance descriptions for applicable NIST SP 800-53 controls, including tailoring decisions.
- Develop and update compensating controls when required.
- Develop and update Contingency Plans and related testing and training documentation.
- Develop and update documentation including System of Records Notices, Configuration Management Plans, Incident Response Plans, Business Impact Assessments, and Interconnection Security Agreements.
- Finalize System Security Plan compliance descriptions.
- Finalize Contingency Plans, Configuration Management Plans, Incident Response Plans, and Disaster Recovery Plans, as required.
- Assist government stakeholders with addressing findings and updating documentation during concurrence and authorization reviews.
- Coordinate with technical and business stakeholders to ensure RMF documentation is accurate, complete, consistent, and ready for authorization review.
Requirements
- U.S. citizenship.
- Bachelor’s degree and at least eight years of relevant cybersecurity experience.
- Experience completing all aspects of the NIST Risk Management Framework for federal information systems.
- Hands-on experience developing and maintaining federal A&A and authorization packages.
- Working knowledge of the NIST Risk Management Framework.
- Working knowledge of FIPS PUB 199.
- Working knowledge of NIST SP 800-53 Rev. 4 and/or Rev. 5.
- Working knowledge of NIST SP 800-37 Rev. 2.
- Working knowledge of NIST SP 800-171 Rev. 2.
- Working knowledge of NIST SP 800-47 Rev. 1.
- Working knowledge of other publications and guidance related to the federal RMF process.
- Hands-on experience using Cybersecurity Assessment and Management System (CSAM).
- Experience supporting ATOs involving FedRAMP-authorized products, solutions, or platforms.
- Experience developing SSPs, contingency plans, incident response plans, configuration management plans, business impact assessments, interconnection security agreements, and privacy documentation.
- Strong technical-writing skills, with the ability to produce accurate, complete, and Section 508-compliant documentation.
- Ability to appropriately handle Controlled Unclassified Information and other sensitive government information.
- Ability to successfully obtain and maintain the required federal background investigation, suitability determination, facility access, and PIV credential.
Technology and Standards
- Cybersecurity Assessment and Management System (CSAM)
- FedRAMP
- NIST Risk Management Framework
- FIPS PUB 199
- NIST SP 800-53 Rev. 4 and NIST SP 800-53 Rev. 5
- NIST SP 800-37 Rev. 2
- NIST SP 800-171 Rev. 2
- NIST SP 800-47 Rev. 1
- Section 508
Location
- Hybrid (Beltsville, Maryland)
Preferred Qualifications
- Prior federal civilian-agency A&A experience.
- Prior USDA cybersecurity or RMF experience is a plus.
- Experience with the USDA Six-Step RMF Process or USDA CSAM instance is a strong plus.
- Experience independently supporting RMF activities across multiple federal information systems.
- Active certification such as CISSP, CGRC (formerly CAP), or CISM.
- Current or prior federal Public Trust investigation.