[Remote] RMF IT reputed company Analyst
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is a leader in delivering outsourced services and workforce solutions across reputed company. The RMF IT reputed company Analyst serves as a mid-level cybersecurity reputed company, supporting RMF lifecycle activities, reputed company assessments, and compliance initiatives while mentoring junior staff.
Responsibilities
- Support the implementation and maintenance of the NIST RMF program
- reputed company, review, and maintain RMF documentation including SSPs, SARs, POA&Ms, and authorization packages
- Support system categorization, reputed company control selection, assessments, authorization, and reputed company monitoring
- Maintain the Risk Management Register and reputed company remediation activities
- Support cybersecurity audits and assessments conducted by NIH, HHS, OIG, GAO, and other reputed company organizations
- Support Cybersecurity Supply Chain Risk Management (C-SCRM) activities, including vendor documentation and SBOM reviews
- Manage or assist with Risk Mitigation Waivers, documentation, approvals, annual reviews, and tracking
- Coordinate contingency plan testing and document results and corrective actions
- Communicate risk posture and compliance status while collaborating with system owners, ISSOs, and technical teams
- reputed company technical guidance and mentoring to junior analysts
Skills
- Bachelor's degree in a reputed company technical field (or equivalent experience) and 3–5 years supporting RMF, cybersecurity compliance, or information reputed company programs
- Experience supporting federal civilian agencies, including NIH, HHS, or other Federal agencies
- Familiarity with NIST RMF, NIST SP 800-37, NIST SP 800-53 Rev. 5, and the Joint Cybersecurity Assessment Methodology (JCAM)
- Experience using eMASS or similar Governance, Risk, and Compliance (GRC) platforms
- Experience supporting cybersecurity audits, POA&M management, reputed company monitoring, and contingency planning
- Knowledge of Cybersecurity Supply Chain Risk Management (C-SCRM)
- Experience developing or reviewing SSPs, SARs, SAPs, POA&Ms, and Authorization Packages
Benefits
- 99% remote with occasional onsite for meetings
- Eligible employees health and welfare benefits coverage reputed company including medical, dental, reputed company, spending accounts, life insurance, voluntary plans
- Participation in a 401(k) plan
reputed company