Risk Management Framework Cybersecurity Analyst

Booz Allen Hamilton

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Washington, DC
Salary
$99,000–$225,000 / yr
Posted
2 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $154k
This role $162k
$84k most similar roles pay here $240k

This role pays more than 57% of similar roles. Most pay $122,818–$185,462 — the shaded band above. At the midpoint, this role pays about $162k versus about $154k for comparable roles.

Based on 240 similar postings.

Employer

About Booz Allen Hamilton

Booz Allen Hamilton is a management and technology consulting firm that provides analytics, digital, engineering, and cybersecurity solutions primarily to U.S. government agencies and commercial clients. Industry: Management & Technology Consulting

Booz Allen Hamilton currently has 793 open roles on FindRole.

Listed pay typically runs $86,800–$198,000 across 768 roles with salary data.

Most-posted roles

View all roles at Booz Allen Hamilton

At a glance

TL;DR · Risk Management Framework Cybersecurity Analyst

Risk Management Framework Cybersecurity Analyst serves as the primary operational counterpart to the Information Systems Security Officer to manage daily compliance and strategic Authorization to Operate renewals. The role involves leading Risk Management Framework and Authorization to Operate processes across multiple systems throughout their entire lifecycle. Key responsibilities include managing cybersecurity assessments, implementing security policies, and validating control implementations through system verification and testing. The analyst will also perform technical remediation strategies, assess ACAS scans and STIGs, and translate complex risks into status reports for stakeholders. Required expertise includes the RMF body of evidence documentation, eMASS submissions, and familiarity with CNSSI-1253, NIST 800-37, and NIST 800-53 standards. Technical tools include SCAP, VRAM, HBSS, and PPSM matrices. This role addresses critical cybersecurity compliance and risk mitigation within a high-security environment requiring a TS/SCI clearance.

What you'll do

  • Lead and drive RMF and Authorization to Operate (ATO) processes across the entire system lifecycle.
  • Manage cybersecurity assessments and Assessment & Authorization (A&A) activities for multiple systems.
  • Enforce compliance with CNSSI-1253, NIST 800-37, and NIST 800-53 standards.
  • Validate security control implementations and develop technical remediation strategies based on system testing.
  • Analyze ACAS scans, STIGs, and security controls to identify vulnerabilities and engineer mitigations.
  • Develop RMF body of evidence documentation including System Security Plans (SSP) and Control Family Plans.
  • Manage and submit RMF ATO packages within the Enterprise Mission Assurance Support Service (eMASS).
  • Translate complex technical risks into clear cybersecurity status reports for stakeholders and Authorizing Officials.

What we're looking for

  • 3+ years of experience in Risk Management Framework (RMF) Assessment and Authorization (A&A).
  • Experience executing manual and automated A&A processes, including developing localized workflows and manual artifact generation.
  • Experience independently developing cybersecurity RMF body of evidence documentation such as System Security Plans and RMF Control Family Plans.
  • Knowledge of developing, managing, and submitting RMF ATO packages within the eMASS system.
  • HS diploma or GED.
  • Experience formally serving as an ISSO, ISSM, or ISSE (preferred).
  • Experience with USCG RMF processes, STIGs, SCAP, ACAS, VRAM, HBSS, and PPSM matrix (preferred).
  • TS/SCI clearance.

More like this

Similar roles

Cybersecurity Analyst

Leidos

Remote 3 days ago $69,550–$125,725
Risk Management Framework (RMF) NIST SP 800-53 NIST SP 800-171 FISMA FedRAMP Tenable Nessus ACAS AWS Azure Linux Windows Vulnerability Management Security Accreditation Incident Response
3+ yrs exp Remote

Cybersecurity Engineer and Risk Analyst

Booz Allen Hamilton

San Diego, CA 38 days ago $99,000–$225,000
RMF ACAS STIG eMASS DevSecOps Vulnerability Assessment Network Security Linux Windows Virtualization Intrusion Prevention Systems Firewalls Big Data Analytics Cybersecurity Policy Systems Development Lifecycle
4+ yrs exp

Cybersecurity Engineer and Risk Analyst

Booz Allen Hamilton

San Diego, CA 38 days ago $69,300–$158,000
RMF eMASS ACAS STIG Evaluate-STIG Network Security Big Data Analytics Windows Linux Firewalls Intrusion Prevention Systems Cybersecurity Policy Systems Development Lifecycle Information Technology
4+ yrs exp

Senior ISSO Cybersecurity Engineer

Booz Allen Hamilton

Aberdeen Proving Ground, MD +1 12 days ago $99,000–$225,000
RMF NIST SP 800-53 eMASS STIG ACAS Nessus SCAP AWS Linux Windows Containerization TCP, IP PKI ICAM MFA Firewalls Encryption Cybersecurity
5+ yrs exp

Cybersecurity Compliance and Risk Manager

Booz Allen Hamilton

Newport, RI 41 days ago $61,900–$141,000
RMF NIST SP 800-53 ACAS eMASS VRAM STIGs SRGs Xacta ESS Altiris ServiceNow VMware Cisco TCP, IP VLANs Firewalls ConMon POA&M
Hybrid

Senior Information System Security Manager

Leidos

Fort George G. Meade, MD 6 days ago $107,900–$195,050
RMF NIST 800-53 FISMA eMASS PPSM IAVMS ATO JSIG ICD 503 SIEM IDS/IPS Firewalls Endpoint Protection Vulnerability Assessment Configuration Management Change Management cATO
8+ yrs exp