Risk Management Framework Cybersecurity Analyst

Booz Allen Hamilton

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Washington, DC
Salary
$99,000–$225,000 / yr
Employment
Full-time
Posted
6 days ago
Freshness
Confirmed live yesterday
Closes
Dec 26, 2026

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $154k
This role $162k
$84k most similar roles pay here $240k

This role pays more than 62% of similar roles. Most pay $123,750–$184,325 — the shaded band above. At the midpoint, this role pays about $162k versus about $154k for comparable roles.

Based on 240 similar postings.

Employer

About Booz Allen Hamilton

Booz Allen Hamilton is a management and technology consulting firm that provides analytics, digital, engineering, and cybersecurity solutions primarily to U.S. government agencies and commercial clients. Industry: Management & Technology Consulting

Booz Allen Hamilton currently has 1240 open roles on FindRole.

Listed pay typically runs $86,800–$198,000 across 817 roles with salary data.

Most-posted roles

View all roles at Booz Allen Hamilton

At a glance

TL;DR · Risk Management Framework Cybersecurity Analyst

As a Risk Management Framework Cybersecurity Analyst, you will serve as the primary operational counterpart to the Information Systems Security Officer to manage daily compliance and strategic Authorization to Operate renewals. You will lead RMF processes across multiple systems' lifecycles, managing cybersecurity assessments, Assessment and Authorization activities, and the implementation of security policies. Your daily work involves validating security control implementations, performing system verification testing, and developing technical remediation strategies. You will evaluate ACAS scans, STIGs, and other controls to engineer mitigations while translating complex risks into status reports for stakeholders. Required expertise includes RMF A&A, eMASS, and drafting System Security Plans. Technical tools include SCAP, VRAM, HBSS, and the PPSM matrix. This role ensures compliance with CNSSI-1253, NIST 800-37, and NIST 800-53 standards to protect critical information systems.

What you'll do

  • Lead and drive RMF and Authorization to Operate (ATO) processes across the entire system lifecycle.
  • Manage cybersecurity assessments and Assessment and Authorization (A&A) activities for multiple systems.
  • Enforce compliance with CNSSI-1253, NIST 800-37, and NIST 800-53 standards.
  • Validate security control implementations through system verification, testing, and technical remediation strategies.
  • Analyze ACAS scans, STIGs, and security controls to identify vulnerabilities and engineer mitigations.
  • Develop RMF body of evidence documentation including System Security Plans (SSP) and Control Family Plans.
  • Manage and submit RMF ATO packages within the Enterprise Mission Assurance Support Service (eMASS).
  • Translate complex technical risks into clear status reports for stakeholders and Authorizing Officials.

What we're looking for

  • TS/SCI clearance is required.
  • High school diploma or GED.
  • 3+ years of experience in RMF A&A.
  • Experience executing manual and automated A&A processes, including developing localized workflows and artifact generation.
  • Experience independently developing cybersecurity RMF body of evidence documentation such as System Security Plans (SSP) and RMF Control Family Plans.
  • Knowledge of managing and submitting RMF ATO packages within the eMASS system.
  • Experience formally serving as an ISSO, ISSM, or ISSE (preferred).
  • Experience with USCG RMF processes, STIGs, SCAP, ACAS, VRAM, HBSS, and PPSM matrix (preferred).

More like this

Similar roles

Cybersecurity Engineer and Risk Analyst

Booz Allen Hamilton

San Diego, CA 45 days ago $69,300–$158,000
Risk Management Framework (RMF) ACAS STIG eMASS Vulnerability Assessment Network Security Big Data Analytics Windows Linux Intrusion Prevention Systems Firewalls Web Proxy Cybersecurity Compliance Systems Development Lifecycle Data Flow Diagrams Boundary Diagrams
4+ yrs exp

Cybersecurity Engineer and Risk Analyst

Booz Allen Hamilton

San Diego, CA 73 days ago
Risk Management Framework ACAS STIGing eMASS Network Security System Administration Windows Linux DevSecOps Firewalls Intrusion Prevention Systems Configuration Management Data Flow Diagrams Boundary Diagrams Big Data Analytics
3+ yrs exp

Cybersecurity Engineer and Risk Analyst

Booz Allen Hamilton

San Diego, CA 45 days ago
RMF ACAS STIG eMASS DevSecOps Vulnerability Assessment Network Security Linux Windows Virtualization Intrusion Prevention Systems Firewalls Big Data Analytics Cybersecurity Policy Systems Development Lifecycle
4+ yrs exp

Senior ISSO Cybersecurity Engineer

Booz Allen Hamilton

Aberdeen Proving Ground, MD +1 19 days ago
RMF NIST SP 800-53 eMASS STIG ACAS Nessus SCAP AWS Linux Windows Containerization TCP, IP PKI ICAM MFA Firewalls Encryption Cybersecurity
5+ yrs exp

Cybersecurity Engineer, Lead

Booz Allen Hamilton

Aberdeen Proving Ground, MD +1 18 days ago
RMF eMASS NIST SP 800-53 STIG ACAS SCAP Nessus AWS Linux Windows Containerization PKI ICAM MFA TCP, IP Firewalls Encryption Security+ CISSP CASP+
8+ yrs exp