Diligent Corporation

Senior RMF Security Analyst

Diligent Corporation$110K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • U.S. citizenship required.
  • Bachelor's degree with a minimum of eight years of cybersecurity experience.
  • Extensive knowledge of the NIST Risk Management Framework (RMF).
  • Hands-on experience with federal A&A and authorization packages.
  • Proficiency in using CSAM and developing RMF documentation.

Responsibilities

  • Collect and update system information and records.
  • Develop contingency plans and related test documentation.
  • Determine compliance with NIST SP 800-53 controls and tailor them as necessary.
  • Finalize System Security Plan compliance descriptions and documentation for reviews.
  • Coordinate with stakeholders to ensure documentation readiness for authorization.

Benefits

  • Work in a hybrid environment allowing for flexibility.
  • Engagement with government cybersecurity stakeholders.
  • Opportunity to develop high-quality security documentation.
  • Chance to enhance skills in federal A&A processes.
Full Job Description
ITLE: Senior RMF Security Analyst

LOCATION: Hybrid (Beltsville, Maryland)

Position Overview

We are seeking a senior, hands-on RMF Security Analyst to support federal information systems through RMF Steps 1-3. The analyst will work closely with government cybersecurity stakeholders to develop and maintain the security documentation required to achieve, maintain, and renew system Authorities to Operate (ATOs).

The ideal candidate will have extensive federal A&A experience and the ability to independently develop high-quality RMF documentation across multiple information systems.

Responsibilities

RMF Step 1 - Categorize the System
  • Collect and update general system information.
  • Create and maintain system records in CSAM, including system identification information, system descriptions, and technical narratives.
  • Prepare and update Privacy Threshold Analyses (PTAs) and Privacy Impact Assessments (PIAs).
  • Perform and update FIPS 199 security categorizations.
  • Perform and update E-Authentication Risk Assessments.

RMF Step 2 - Select Security Controls
  • Identify common and inherited security controls, including controls inherited from FedRAMP-authorized services.
  • Develop and update compliance descriptions for applicable NIST SP 800-53 controls, including tailoring decisions.
  • Develop compensating controls when required.
  • Develop and update Contingency Plans and related testing and training documentation.
  • Develop and update System of Records Notices, Configuration Management Plans, Incident Response Plans, Business Impact Assessments, and Interconnection Security Agreements.

RMF Step 3 - Implement and Support Review
  • Finalize System Security Plan compliance descriptions.
  • Finalize Contingency Plans, Configuration Management Plans, Incident Response Plans, and Disaster Recovery Plans, as required.
  • Assist government stakeholders in addressing findings and updating documentation during concurrence and authorization reviews.
  • Coordinate with technical and business stakeholders to ensure RMF documentation is accurate, complete, consistent, and ready for authorization review.


Required Qualifications
  • U.S. citizenship.
  • Bachelor's degree and at least eight years of relevant cybersecurity experience.
  • Experience completing all aspects of the NIST Risk Management Framework for federal information systems.
  • Hands-on experience developing and maintaining federal A&A and authorization packages.
  • Working knowledge of:
    • NIST Risk Management Framework
    • FIPS PUB 199
    • NIST SP 800-53 Rev. 4 and/or Rev. 5
    • NIST SP 800-37 Rev. 2
    • NIST SP 800-171 Rev. 2
    • NIST SP 800-47 Rev. 1
    • Other publications and guidance related to the federal RMF process
  • Hands-on experience using the Cybersecurity Assessment and Management System (CSAM).
  • Experience supporting ATOs involving FedRAMP-authorized products, solutions, or platforms.
  • Experience developing SSPs, contingency plans, incident response plans, configuration management plans, business impact assessments, interconnection security agreements, and privacy documentation.
  • Strong technical-writing skills and the ability to produce accurate, complete, and Section 508-compliant documentation.
  • Ability to appropriately handle Controlled Unclassified Information and other sensitive government information.
  • Ability to successfully obtain and maintain the required federal background investigation, suitability determination, facility access, and PIV credential.


Preferred Qualifications
  • Prior federal civilian-agency A&A experience.
  • Prior USDA cybersecurity or RMF experience is a plus.
  • Experience with the USDA Six-Step RMF Process or USDA CSAM instance is a strong plus.
  • Experience independently supporting RMF activities across multiple federal information systems.
  • Active certification such as CISSP, CGRC (formerly CAP), or CISM.
  • Current or prior federal Public Trust investigation.


Skills & Requirements Qualifications

About Diligent Corporation

Diligent Corporation is a software company that provides secure corporate governance and collaboration solutions for boards and senior executives. The company's solutions are used by over 19,000 organizations and 650,000 leaders in more than 90 countries. Diligent's products include Diligent Boards, a board portal that provides secure access to board materials and collaboration tools, and Diligent Messenger, a secure messaging and collaboration platform. Diligent Corporation was founded in 2001 and is headquartered in New York City. The company has offices in the United States, Canada, Europe, and Asia-Pacific. Diligent Corporation is a privately held company and is not traded on any stock exchange.
Learn more about Diligent Corporation
Size
2,000 employees
Industry

Similar Jobs

More Jobs at Diligent Corporation

More Information Technology Jobs

Find similar Senior RMF Security Analyst jobs: