AMERICAN SYSTEMS

RMF Analyst II

AMERICAN SYSTEMS$70K — $100K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • U.S. Citizenship required due to government contract restrictions.
  • Must attain and retain DoE L or DoD Secret clearance.
  • 5+ years in Cybersecurity or related experience.
  • Active Certified Information Systems Security Professional (CISSP) certification required.
  • Experience with assessment and authorization (A&A) required.
  • Familiar with RMF, NIST, and relevant security controls.
  • Proficient in creating and modifying RMF-related documentation.

Responsibilities

  • Liaise with government customers on RMF assessment and authorization packages.
  • Support oversight of multiple system boundaries.
  • Recommend cost-effective security controls to mitigate risk.
  • Ensure cybersecurity standards are consistently applied across systems.
  • Author security assessment reports and plans of action and milestones.
  • Conduct in-depth analysis of complex systems within the RMF framework.
  • Participate in discussions about organizational risk management strategies.

Benefits

  • Healthcare benefits for employees and dependents.
  • Comprehensive paid leave policy.
  • Retirement plans available.
  • Insurance programs offered.
  • Education and training assistance provided.
Full Job Description
Responsibilities

An Average Day:As the RMF Analyst II you will directly liaison with the government customer to manage the review, audit, and authorization of Risk Management Framework (RMF) assessment and authorization (A&A)/ATO Packages and for IT systems of varying size and complexity. In this role you will perform hands-on artifact review along with package management and review. Additionally, in this position you will:
  • Directly support the customer in the oversight of multiple system boundaries.
  • Make recommendations regarding the selection of cost-effective security controls to mitigate risk (e.g., protection of information, systems and processes).
  • Ensure consistent application of cybersecurity standards across multiple information systems.
  • Ensure all new cybersecurity projects meet or integrate cybersecurity standards into their development.
  • Author detailed security assessment reports and plans of action and milestones (POA&Ms), Risk Assessment Reports (RARs), and other artifacts associated with the RMF process.
  • Conduct in-depth analysis of complex systems and their interconnections through RMF.
  • Participate in high-level discussions about organizational risk management strategies.
  • Recommend improvements to RMF processes and tools to enhance efficiency and effectiveness.
  • Review and approve system security plans and other RMF documentation.
  • Make recommendations regarding the selection of cost-effective security controls to mitigate risk (e.g., protection of information, systems and processes).


Qualifications

  • As a requirement of this position, all candidates must be a U.S. Citizen. In accordance with 8 U.S.C. 1324b(a)(2)(C), Epsilon will not consider candidates for this position who do not meet the aforementioned conditions.
  • Must be able to attain and retain DoE L, or DoD Secret clearance.
  • Five (5) or more years of experience in the Cybersecurity field or combination of related education and experience.
  • Active Certified Information Systems Security Professional (CISSP) certification from ISC2.
  • Experience with assessment and authorization (A&A).
  • Experience with assessing and validating RMF, NIST, and other security controls.
  • RMF experience in package generation and assessment.
  • Visio diagram creation and modification.
  • RMF documentation creation and modification (SSP, CCB, COOP, etc.).
  • Familiarity with NIST 800-53 controls and applicable overlays.
  • Ability to provide security assessment reports that cover risks that the client should be aware of and mitigate risk with residual risks remaining.
  • Desired security certifications and qualifications: Security+ Ce, CySA+, SSCP, GSEC, GICSP, CND, CCNA Security, or equivalent.
  • Must be within a 2-hour commute of the customer location and will be required to travel onsite based on customer request.


Pay Transparency Statement

AMERICAN SYSTEMS is committed to pay transparency for our applicants and employee-owners. The salary range for this position is USD $70,000.00/Yr. - USD $100,000/Yr. Actual compensation will be determined based on several factors permitted by law. AMERICAN SYSTEMS provides for the welfare of its employees and their dependents through a comprehensive benefits program by offering healthcare benefits, paid leave, retirement plans, insurance programs, and education and training assistance.

About AMERICAN SYSTEMS

AMERICAN SYSTEMS is a government IT solutions provider. The Company provides solutions in national security, healthcare, and public sector markets. Its services include acquisition and lifecycle support, enterprise IT, healthcare IT, intelligence analysis, and training and simulation. The Company's customers include the Department of Defense, Department of State, Department of Justice, and Department of Homeland Security. AMERICAN SYSTEMS was founded in 1975 and is headquartered in Chantilly, Virginia.
Learn more about AMERICAN SYSTEMS
Size
1,500 employees
Industry
Founded
1975

Similar Jobs

More Jobs at AMERICAN SYSTEMS

More Information Technology Jobs

Find similar RMF Analyst II jobs: