RMF / CSAM Analyst
Summary
The RMF/CSAM Analyst supports the security authorization and compliance of a federal cloud-based identity and access management environment. The role involves managing RMF and CSAM activities, tracking POA&Ms, and ensuring alignment with federal cybersecurity frameworks like NIST and FedRAMP.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a RMF / CSAM Analyst based in United States.
This role supports the continuous security authorization, compliance, and protection of a cloud-based federal identity and access management environment.
You will help maintain alignment with federal cybersecurity frameworks, regulatory requirements, and security best practices.
The position plays a key role in managing RMF and CSAM activities, security controls, POA&Ms, vulnerability remediation, and continuous monitoring.
You will collaborate with security teams, ISSOs, technical stakeholders, and program leaders to identify risks and drive corrective actions.
The role combines detailed compliance management with hands-on analysis of security findings, documentation, and reporting.
Success requires strong organization, technical understanding, and the ability to respond effectively to both routine compliance activities and emerging security needs.
This is an opportunity to contribute directly to the security and compliance of critical federal identity services in a structured, mission-focused environment.
Accountabilities:
- Manage and maintain Risk Management Framework (RMF) and Cyber Security Assessment and Management (CSAM) activities to support continuous authorization and compliance of the IAM environment.
- Ensure security and compliance alignment with FedRAMP, FISMA, NIST SP 800-63, OMB M-24-15, OMB M-21-31, and applicable federal cloud security requirements.
- Maintain security controls, inheritance statements, authorization documentation, and evidence required to sustain the Authority to Operate (ATO).
- Track, analyze, and support remediation of Plan of Action and Milestones (POA&M) items, vulnerability findings, CDM results, and Common Vulnerabilities and Exposures (CVEs).
- Analyze security scan results, develop corrective action plans, monitor remediation progress, and escalate unresolved risks as appropriate.
- Support security incident management, continuous monitoring, cybersecurity reporting, and maintenance of the required Cybersecurity Framework (CSF) scorecard.
- Oversee compliance requirements related to event logging, encryption of data at rest and in transit, protection of sensitive user information, and secure handling of federal data.
- Support supply chain risk management, federal records requirements, Controlled Unclassified Information (CUI) handling, Section 508 accessibility, and technology business management reporting.
- Maintain accurate project, risk, schedule, compliance, and environment-support documentation needed for ongoing security authorization.
- Collaborate closely with ISSOs, cybersecurity teams, technical stakeholders, and program leadership to communicate risks, requirements, findings, and remediation status.
- Respond effectively to urgent security and compliance issues while maintaining consistent execution of recurring reporting and monitoring activities.
- Bachelor’s degree in cybersecurity, information technology, computer science, or a related discipline, with at least 2 years of relevant professional experience.
- Required Public Trust clearance and ability to operate effectively within a federal government security environment.
- Strong knowledge of the NIST Risk Management Framework (RMF) and experience working with the CSAM tool or comparable security compliance platforms.
- Experience with FedRAMP, FISMA, POA&M management, security control assessments, control inheritance, and continuous monitoring.
- Familiarity with NIST SP 800-63, OMB M-21-31, OMB M-24-15, cloud security requirements, and federal cybersecurity policies.
- Understanding of data encryption, secure logging, vulnerability management, cybersecurity controls, and compliance reporting.
- Ability to analyze vulnerability and security assessment results, develop corrective action plans, and track remediation through completion.
- Strong documentation, organization, recordkeeping, and attention-to-detail skills, particularly when managing security evidence and compliance artifacts.
- Proficiency with Microsoft Office and compliance, security, or project-tracking tools.
- Excellent written and verbal communication skills, with the ability to collaborate effectively with ISSOs, security professionals, technical teams, and other stakeholders.
- Ability to balance recurring compliance responsibilities with urgent security issues and changing priorities.
- Detail-oriented, dependable, collaborative, and committed to maintaining high cybersecurity standards in a federal environment.
- Salary: $75,000–$104,000 USD annually, with final compensation determined by factors such as responsibilities, education, certifications, experience, internal equity, and market considerations.
- Remote work environment.
- 11 federal holidays.
- Paid time off accrued each pay period.
- Paid parental leave.
- Three medical plan options with employer contributions.
- Dental and vision insurance.
- Company-paid short-term and long-term disability coverage.
- Company-paid life and AD&D insurance.
- 401(k) plan with competitive employer matching and vesting.
- Continuing education assistance.
- Medical, dependent care, and commuter Flexible Spending Accounts.
- Employee Assistance Program.
- Wellness benefits, including Calm Health and a WellHub gym subsidy.
- 529 College Savings Plan.
- Legal insurance.
- Pet insurance.
- Veterans are encouraged to apply
Requirements:
Benefits:
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company