Jobs · Business Development · Virginia

RMF and POAM Analyst

Guidehouse · McLean, VA · 2 days ago
On-siteBusiness DevelopmentFull-time

What You Will Do

  • Lead and/or support the development of RMF and A&A documentation including SSPs, control implementation matrices, SARs, POA&Ms, and risk acceptance materials.
  • Support authorization of on premise and cloud services leveraging FedRAMP packages, considering agency specific control requirements, and support 3PAO readiness assessments and SAR development for cloud platforms.
  • Interpret and operationalize FISMA, NIST RMF, FedRAMP, and OSCAL standards to guide application enhancements, evidence automation, and RMF workflow modernization across a GRC platform.
  • Ensuring consistency and compliance across multi‑tenant GRC environments, helping Components and customer agencies implement security controls, maintain accurate documentation, and sustain reliable continuous monitoring.
  • Collaborating across Agile teams to embed RMF discipline, support backlog refinement, and validate that modernization activities remain compliant with Federal requirements.
  • Coordinate A&A activities and requirements with System Owners, ISSOs, IAMs, and third-party assessors, reducing manual burden for ISSOs and system owners by shaping automated workflows, improving evidence pathways, and strengthening data integrity used for scoring, dashboards, and compliance reporting.
  • Providing compliance and RMF subject matter guidance throughout sprint cycles, planning, testing activities, and release readiness processes, ensuring enhancements align with RMF control requirements and governance expectations.
  • Supporting continuous authorization (cATO) goals through integration of automated control validation, vulnerability data ingestion, security tooling alignment, and machine‑readable artifacts (OSCAL).

What You Will Need

  • An ACTIVE and CURRENT Federal or DoD Public Trust
  • Bachelor’s Degree AND Five (5) years of relevant cybersecurity experience, OR a Master’s Degree AND Three (3) years of relevant experience
  • Experience as an RMF or POAM Analyst (current or past)
  • Excellent verbal and written communication skills, specifically in report writing
  • Ability to commute to client office as needed per week

What Would Be Nice To Have

  • Security+, CAP, or equivalent certification, and strong working knowledge of NIST SP 800 37, 800 53, FISMA, and FedRAMP.
  • Familiarity with ServiceNow, GRC platforms, or audit tracking tools.
  • Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department of Homeland Security related to GRC implementations
  • Demonstrated experience in the areas of external client-facing management and/or consulting for large firms

What We Offer

  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend

Similar jobs

RMF Analyst

CVP (Customer Value Partners)United States· 1 mo ago
RemoteBusiness Developmentapply on careers-cvpcorp.icims.com

RMF / CSAM Analyst

JobgetherUnited States· 2 days ago
RemoteBusiness Development$75k–$104k/yrapply on jobs.lever.co

RMF Analyst II

AMERICAN SYSTEMSOak Ridge, TN· 1 mo ago
Sales$70k/yrapply on careers-americansystems.icims.com

RMF Analyst II

Chenega MIOS SBUHuntsville, AL· 2 mo ago
Business Developmentapply on chenega.jibeapply.com

RMF Security Analyst

LeidosOdenton, MD· 1 mo ago
Information Technology$70k–$126k/yrapply on careers.leidos.com