Quick Overview
Job Description
An Average Day
As the RMF Analyst II you will directly liaison with the government customer to manage the review, audit, and authorization of Risk Management Framework (RMF) assessment and authorization (A&A)/ATO Packages and for IT systems of varying size and complexity. In this role you will perform hands-on artifact review along with package management and review. Additionally, in this position you will: Directly support the customer in the oversight of multiple system boundaries.
Make recommendations regarding the selection of cost-effective security controls to mitigate risk (e.g., protection of information, systems and processes). Ensure consistent application of cybersecurity standards across multiple information systems. Ensure all new cybersecurity projects meet or integrate cybersecurity standards into their development. Author detailed security assessment reports and plans of action and milestones (POA&Ms), Risk Assessment Reports (RARs), and other artifacts associated with the RMF process.
Conduct in-depth analysis of complex systems and their interconnections through RMF. Participate in high-level discussions about organizational risk management strategies. Recommend improvements to RMF processes and tools to enhance efficiency and effectiveness. Review and approve system security plans and other RMF documentation. Make recommendations regarding the selection of cost-effective security controls to mitigate risk (e.g., protection of information, systems and processes). As a requirement of this position, all candidates must be a U.S. Citizen.
In accordance with 8 U.S.C. 1324b(a)(2)(C), Epsilon will not consider candidates for this position who do not meet the aforementioned conditions. Must be able to attain and retain DoE L, or DoD Secret clearance. Five (5) or more years of experience in the Cybersecurity field or combination of related education and experience. Active Certified Information Systems Security Professional (CISSP) certification from ISC2. Experience with assessment and authorization (A&A). Experience with assessing and validating RMF, NIST, and other security controls.
RMF experience in package generation and assessment. Visio diagram creation and modification. RMF documentation creation and modification (SSP, CCB, COOP, etc.). Familiarity with NIST 800-53 controls and applicable overlays. Ability to provide security assessment reports that cover risks that the client should be aware of and mitigate risk with residual risks remaining. Desired security certifications and qualifications: Security+ Ce, CySA+, SSCP, GSEC, GICSP, CND, CCNA Security, or equivalent.
Must be within a 2-hour commute of the customer location and will be required to travel onsite based on customer request.
Similar jobs
- AG
Business Analyst - Security/Governance Analyst
NewAgile Global Solutions, Inc
United States🇺🇸Remote19 hours agoAgileOperations & Project Management - SE
Cerner IT Security Analyst
NewSunRay Enterprise Inc
United States🇺🇸Remote19 hours agoTechnology - JV
Senior Information Systems Security Officer (ISSO-3)
J VERS LLC
MD🇺🇸$107.9k - $195.1k/yrHybrid3 days agoTechnology - JV
Senior Information System Security Engineer (ISSE)
J VERS LLC
Alexandria, VA🇺🇸$131.3k - $237.3k/yrHybrid3 days agoDockerAWSEncryption+11Technology - TS
Security Analyst
NewThoughtwave Software and Solutions
San Antonio, TX🇺🇸Hybrid19 hours agoTechnology - 4C
Information Security Analysts
New4 Consulting Inc
Columbia, MD🇺🇸On-site19 hours agoStakeholder ManagementTechnology