RMF / A&A Analyst

eTelligent Group LLC

• $90K — $100K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree and 4+ years of Risk Management Framework (RMF) or Authorization and Accreditation (A&A) experience in a federal environment.
  • Proficient in NIST SP 800-37 Rev 2, 800-53 Rev 5, 800-53A, and FISMA compliance standards.
  • Hands-on experience in Plan of Action & Milestones (POA&M) management and familiarity with CSAM or comparable Governance, Risk, and Compliance (GRC) tools.
  • Possess Security+ or CAP/CGRC certification for validation of security expertise.
  • Must have a current T2 (background investigation) or higher, acceptable through reciprocity.

Responsibilities

  • Map NIH's FISMA systems to Zero Trust controls and document inherited, hybrid, and uncovered controls for remediation.
  • Analyze residual gaps based on FIPS 199 impact, data sensitivity, and internet exposure.
  • Support the project management phases for the Task 4 pipeline, including time analysis and documentation workflows.
  • Create mappings and evidence expectations for Zero Trust Architecture (ZTA) overlays and participate in three-system pilot.
  • Maintain an updated shared control library for NIH's ZTA initiatives.
  • Develop templates for necessary documentation (SSP, SAP/SAR, POA&M) and monitoring processes as per SP 800-137.
  • Manage content updates on the OCIO ZTA Wiki and serve as a point of contact for ZTA-related inquiries.

Benefits

  • Hybrid work environment with on-site requirements primarily in Bethesda, MD.
  • Opportunity to work within the prestigious NIH and contribute to federal cybersecurity initiatives.
  • Engagement in cutting-edge projects related to Zero Trust Architecture and Risk Management.
  • Access to continuous professional development through certifications and training.
  • Collaboration with experienced professionals in the field of information security and compliance.
Full Job Description
Work Location and On-Site/Telework Requirements: Hybrid - NIH, Bethesda, MD. On site for A&A working sessions and pilots (typically 1-2 days/week during the first 120 days, then as scheduled).

Citizenship: U.S. Citizenship required

Clearance: All staff must obtain NIH suitability and a PIV credential and be fluent in English. Anyone doing risk or vulnerability testing needs a current T2 (BI) or higher investigation.

Salary Range: $90,000-$100,000 yearly salary

Overview:

You will map NIH's FISMA systems to the Zero Trust controls they can inherit and help make Zero Trust assessable inside NIH's A&A process under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). You will work in the Risk & Policy Pod on Task 4 and Subtasks 2.5 and 1.2, reporting technically to the Security Lead.

Responsibilities:
  • Pull the CSAM inventory and map the control set of each of NIH's 72 FISMA-registered systems against the Centrally Provided Services Matrix. Identify inherited, hybrid, and uncovered controls for the Inherited Controls Mapping and Remediation Roadmap (Subtask 2.5, due at 120 days, refreshed quarterly).
  • Score residual gaps by FIPS 199 impact, data sensitivity, and internet exposure.
  • Support the Task 4 pipeline baseline: time per phase, rework loops, inherited versus re-documented controls, and upcoming authorizations.
  • Build the ZTA Overlay mappings and evidence expectations, tagging each control as central, hybrid, or system-specific. Support the CSAM import and the three-system pilot.
  • Maintain records in the shared NIH ZTA control library.
  • Develop package templates (SSP, SAP/SAR, POA&M) and continuous-monitoring cadences (SP 800-137) for the three authorization tiers.
  • Keep the IC-inheritable controls content current on the OCIO ZTA Wiki, and answer control questions routed from the ZTA help desk.


Tools & Technology Environment: CSAM (primary), Xacta, RSA/SGRC Archer, ServiceNow; Excel and Power BI; Confluence/SharePoint and the OCIO ZTA Wiki.

Required Qualifications:
  • Bachelor's degree plus 4+ years of RMF/A&A experience in a federal environment.
  • Working knowledge of NIST SP 800-37 Rev 2, 800-53 Rev 5, 800-53A, and FISMA.
  • Hands-on POA&M management and experience with CSAM or a comparable GRC tool.
  • Security+ or CAP/CGRC certification.
  • Current T2 (BI) or higher federal background investigation, acceptable through reciprocity.


Preferred Qualifications:
  • HHS or NIH A&A experience in CSAM.
  • Common-control and inheritance modeling; experience with Zero Trust control mapping.
  • FedRAMP experience; CGRC or CISA certification.
  • Current National Institutes of Health (NIH) or U.S. Department of Health and Human Services (HHS) experience is highly preferred.


Similar Jobs

More Jobs at eTelligent Group LLC

More Education, Government & Non-Profit Jobs

Find similar RMF / A&A Analyst jobs: