openleverjobgether
RMF / CSAM Analyst
Jobgether
LocationUS
EmploymentFull-time
Posted2026-08-25T08:49:17.497000+00:00
Last observed2026-08-26 21:51:40.410433
Job idjobgether-jobgether:lever:728923db-e840-4371-8969-14e706e806cc
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a RMF / CSAM Analyst based in United States. This role supports the continuous security authorization, compliance, and protection of a cloud-based federal identity and access management environment. You will help maintain alignment with federal cybersecurity frameworks, regulatory requirements, and security best practices. The position plays a key role in managing RMF and CSAM activities, security controls, POA&Ms, vulnerability remediation, and continuous monitoring. You will collaborate with security teams, ISSOs, technical stakeholders, and program leaders to identify risks and drive corrective actions. The role combines detailed compliance management with hands-on analysis of security findings, documentation, and reporting. Success requires strong organization, technical understanding, and the ability to respond effectively to both routine compliance activities and emerging security needs. This is an opportunity to contribute directly to the security and compliance of critical federal identity services in a structured, mission-focused environment. Manage and maintain Risk Management Framework (RMF) and Cyber Security Assessment and Management (CSAM) activities to support continuous authorization and compliance of the IAM environment. Ensure security and compliance alignment with FedRAMP, FISMA, NIST SP 800-63, OMB M-24-15, OMB M-21-31, and applicable federal cloud security requirements. Maintain security controls, inheritance statements, authorization documentation, and evidence required to sustain the Authority to Operate (ATO). Track, analyze, and support remediation of Plan of Action and Milestones (POA&M) items, vulnerability findings, CDM results, and Common Vulnerabilities and Exposures (CVEs). Analyze security scan results, develop corrective action plans, monitor remediation progress, and escalate unresolved risks as appropriate. Support security incident management, continuous monitoring, cybersecurity reporting, and maintenance of the required Cybersecurity Framework (CSF) scorecard. Oversee compliance requirements related to event logging, encryption of data at rest and in transit, protection of sensitive user information, and secure handling of federal data. Support supply chain risk management, federal records requirements, Controlled Unclassified Information (CUI) handling, Section 508 accessibility, and technology business management reporting. Maintain accurate project, risk, schedule, compliance, and environment-support documentation needed for ongoing security authorization. Collaborate closely with ISSOs, cybersecurity teams, technical stakeholders, and program leadership to communicate risks, requirements, findings, and remediation status. Respond effectively to urgent security and compliance issues while maintaining consistent execution of recurring reporting and monitoring activities. Requirements: Bachelor’s degree in cybersecurity, information technology, computer science, or a related discipline, with at least 2 years of relevant professional experience. Required Public Trust clearance and ability to operate effectively within a federal government security environment. Strong knowledge of the NIST Risk Management Framework (RMF) and experience working with the CSAM tool or comparable security compliance platforms. Experience with FedRAMP, FISMA, POA&M management, security control assessments, control inheritance, and continuous monitoring. Familiarity with NIST SP 800-63, OMB M-21-31, OMB M-24-15, cloud security requirements, and federal cybersecurity policies. Understanding of data encryption, secure logging, vulnerability management, cybersecurity controls, and compliance reporting. Ability to analyze vulnerability and security assessment results, develop corrective action plans, and track remediation through completion. Strong documentation, organization, recordkeeping,
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.