RMF and A&A Analyst
Core
Apply the NIST Risk Management Framework to federal systems and maintain authorization packages.
Role type
RMF and A&A Analyst
Builds
System security plans, plans of action and milestones, and authorization packages for federal agencies
Domain
Federal government cybersecurity and compliance
Required skills
NIST Risk Management Framework application, system security plan development, Plan of Action and Milestones (POA&M) creation, federal GRC platform usage, continuous monitoring, annual reauthorization support
Preferred skills
Bachelors degree in cybersecurity or IT, CGRC certification, Security+ certification, federal GRC platform experience, cloud authorization experience
Technologies
Cloud Support Security
Responsibilities
Develop and maintain system security plans, plans of action and milestones, and supporting authorization materials; Track control implementation and remediation across multiple system boundaries; Maintain current authorization records in a federal governance, risk, and compliance platform; Prepare authorization packages for independent assessment and provide assessors with supporting evidence; Support continuous monitoring and annual reauthorization activities