Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
M3

Jr. RMF IT Security Analyst

Merit 321
Location not stated
Remote
Junior
2 months ago
  • RMF
  • Risk Management Framework
  • NIST
  • Risk Management
  • CompTIA Security+
  • CySA+
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

JR. RMF IT Security Analyst

Position Summary


The RMF IT Security Analyst serves as a junior cybersecurity professional supporting the NIH Office of the Director (OD), Office of Information Technology (Client) Risk Management Framework (RMF) Program. Working under Lead and Senior RMF personnel, the analyst assists with RMF lifecycle activities, documentation, continuous monitoring, and compliance efforts while developing expertise in federal cybersecurity. Work is primarily remote with occasional on-site meetings.

Key Responsibilities

  • Support the implementation and maintenance of the NIST RMF program.
  • Develop, review, and maintain RMF documentation including SSPs, SARs, POA&Ms, and authorization packages.
  • Support system categorization, security control selection, assessments, authorization, and continuous monitoring.
  • Maintain the Risk Management Register and track remediation activities.
  • Support cybersecurity audits and assessments conducted by NIH, HHS, OIG, GAO, and other oversight organizations.
  • Support Cybersecurity Supply Chain Risk Management (C-SCRM) activities, including vendor documentation and SBOM reviews.
  • Manage or assist with Risk Mitigation Waivers, documentation, approvals, annual reviews, and tracking.
  • Coordinate contingency plan testing and document results and corrective actions.
  • Communicate risk posture and compliance status while collaborating with system owners, ISSOs, and technical teams.

Required Qualifications

Bachelor's degree in a related technical field (or equivalent experience) and 0–2 years supporting cybersecurity, compliance, or IT operations.

Preferred Qualifications

  • Experience supporting federal civilian agencies, including NIH, HHS, or other Federal agencies.
  • Familiarity with NIST RMF, NIST SP 800-37, NIST SP 800-53 Rev. 5, and the Joint Cybersecurity Assessment Methodology (JCAM).
  • Experience using eMASS or similar Governance, Risk, and Compliance (GRC) platforms.
  • Experience supporting cybersecurity audits, POA&M management, continuous monitoring, and contingency planning.
  • Knowledge of Cybersecurity Supply Chain Risk Management (C-SCRM).
  • Experience developing or reviewing SSPs, SARs, SAPs, POA&Ms, and Authorization Packages.

Desired Certifications

  • ISC2 Certified in Cybersecurity (CC)
  • CompTIA Security+
  • CompTIA CySA+
  • CompTIA PenTest+
  • CAP/CGRC

Knowledge, Skills, and Abilities

Strong analytical, organizational, and communication skills with knowledge of RMF processes, documentation, and federal cybersecurity compliance. Ability to collaborate with system owners, ISSOs, and technical teams.

Work Environment

This position is primarily remote with occasional on-site meetings or support activities as required.

Jr. RMF IT Security Analyst · Merit 321

Auto apply with Likeremote