Guidehouse

RMF and POAM Analyst

Guidehouse$100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Active and current Federal or DoD Public Trust clearance
  • Bachelor's degree plus 5 years relevant cybersecurity experience or Master's degree plus 3 years
  • Experience as an RMF or POAM Analyst
  • Strong verbal and written communication skills, especially in report writing
  • Willingness to commute to client office as required

Responsibilities

  • Lead the development of RMF and A&A documentation such as SSPs and SARs
  • Support authorization of cloud services using FedRAMP packages
  • Interpret and operationalize FISMA, NIST RMF, and FedRAMP standards
  • Ensure compliance across multi-tenant GRC environments
  • Collaborate with Agile teams to maintain RMF discipline
  • Coordinate A&A activities with system stakeholders to automate workflows
  • Provide RMF subject matter guidance during sprint cycles
  • Support continuous authorization goals through automated control validation

Benefits

  • Medical, RX, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life Insurance
  • Health Savings Account and flexible spending accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend
Full Job Description

Job Family:

Technology Consulting


Travel Required:

Up to 10%


Clearance Required:

Active Public Trust

What You Will Do:

  • Lead and/or support the developmentof RMF and A&A documentation including SSPs, control implementation matrices, SARs, POA&Ms, and risk acceptance materials.

  • Support authorization of on premise and cloud services leveraging FedRAMP packages, considering agency specific control requirements, and support 3PAO readiness assessments and SAR development for cloud platforms.

  • Interpret and operationalize FISMA, NIST RMF, FedRAMP, and OSCAL standards to guide application enhancements, evidence automation, and RMF workflow modernization across a GRC platform.

  • Ensuring consistency and compliance across multi‑tenant GRC environments, helping Components and customer agencies implement security controls, maintain accurate documentation, and sustain reliable continuous monitoring.

  • Collaborating across Agile teams to embed RMF discipline, support backlog refinement, and validate that modernization activities remain compliant with Federal requirements.

  • Coordinate A&A activities and requirements with System Owners, ISSOs, IAMs, and third-party assessors, reducing manual burden for ISSOs and system owners by shaping automated workflows, improving evidence pathways, and strengthening data integrity used for scoring, dashboards, and compliance reporting.

  • Providing compliance and RMF subject matter guidance throughout sprint cycles, planning, testing activities, and release readiness processes, ensuring enhancements align with RMF control requirements and governance expectations.

  • Supporting continuous authorization (cATO) goals through integration of automated control validation, vulnerability data ingestion, security tooling alignment, and machine‑readable artifacts (OSCAL).


What You Will Need:

  • An ACTIVE and CURRENT Federal or DoD Public Trust

  • Bachelor’s Degree AND Five (5) years of relevant cybersecurity experience, OR a Master’s Degree AND Three (3) years of relevant experience

  • Experience as an RMF or POAM Analyst (current or past)

  • Excellent verbal and written communication skills, specifically in report writing

  • Ability to commute to client office as needed per week


What Would Be Nice To Have:

  • Security+, CAP, or equivalent certification, and strong working knowledge of NIST SP 800 37, 800 53, FISMA, and FedRAMP.

  • Familiarity with ServiceNow, GRC platforms, or audit tracking tools.

  • Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department of Homeland Security related to GRC implementations

  • Demonstrated experience in the areas of external client-facing management and/or consulting for large firms


What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:

  • Medical, Rx, Dental & Vision Insurance

  • Personal and Family Sick Time & Company Paid Holidays

  • Position may be eligible for a discretionary variable incentive bonus

  • Parental Leave and Adoption Assistance

  • 401(k) Retirement Plan

  • Basic Life & Supplemental Life

  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts

  • Short-Term & Long-Term Disability

  • Student Loan PayDown

  • Tuition Reimbursement, Personal Development & Learning Opportunities

  • Skills Development & Certifications

  • Employee Referral Program

  • Corporate Sponsored Events & Community Outreach

  • Emergency Back-Up Childcare Program

  • Mobility Stipend

About Guidehouse

Guidehouse is a management consulting firm headquartered in Washington, D.C. The firm provides consulting services to clients in the public and commercial sectors, with a focus on energy, financial services, healthcare, national security, and aerospace and defense. Guidehouse was founded in 2018 as a spin-off from PwC. The firm has over 7,000 employees and operates in more than 50 locations worldwide.
Learn more about Guidehouse
Size
8,000 employees
Industry
Founded
2018

Similar Jobs

More Jobs at Guidehouse

More Information Technology Jobs

Find similar RMF and POAM Analyst jobs: