RMF Cyber Security Analyst
Quantico, VA
Full Time
Mid Level
RMF Cyber Security Analyst 2026-170
This position is 100% on-site at RKB, Quantico, VA
Clearance: Active Secret
Required Certification: DoD 8570-M/8140-M IAT Level II
Job Description
Nationwide IT Services, NIS, seeks a Cybersecurity Analyst who will:
Minimum Qualifications:
About Nationwide IT Services
NIS is a CVE-verified Service-Disabled Veteran-Owned Small Business and an IT and management consulting company. Our mission is to deliver value-added services to our customers, leveraging technology, people, and industry best practices to implement innovative solutions through our trusted employees and team members.
Our benefits package includes medical, dental, and vision insurance; life and disability insurance; a 401(k) plan with employer match; paid holidays; PTO (sick/vacation); commuter benefits; an employee assistance program (EAP); educational reimbursement; and pet insurance.
Salary range $100,000 to $110,000 annually
The salary range is a general guideline. We consider several factors when determining base salary offers, including the position's scope and responsibilities, the candidate's experience, education, and skills, and current market conditions.
This position is 100% on-site at RKB, Quantico, VA
Clearance: Active Secret
Required Certification: DoD 8570-M/8140-M IAT Level II
Job Description
Nationwide IT Services, NIS, seeks a Cybersecurity Analyst who will:
- Provide support for a program, an organization, system, or an enclave.
- Provide support for proposing, coordinating, implementing, and
enforcing information systems or enclave cybersecurity policies, standards, and
methodologies. - Maintain operational security posture for an information system,
program, or enclave to ensure cybersecurity standards and procedures are established and followed. - Perform day-to-day security operations of the system or enclave.
- Perform IT security control assessments.
- Provide configuration management (CM) for information system security software, hardware, and firmware; manage changes to the system and assess the security impact of those changes.
- Prepare and review documentation to include Systems Security Plans (SSPs) and Security Assessment & Authorization (SA&A) packages in accordance with DoD Risk Management Framework (RMF) procedures.
- Interface with Project/Program Managers, Subject Matter Experts (SME), and
Information System Security Managers (ISSM) on Major Application / General
Enclave issues and updates. - Drive the 7 steps of the RMF lifecycle (Prepare, Categorize, Select, Implement,
Assess, Authorize, and Monitor). - Create and maintain security packages in eMASS.
- Review vulnerability scan results (using tools like ACAS or Nessus) and
coordinate remediation. - Act as a bridge between technical engineers, Information System Security
Officers (ISSOs), and executive leadership. - Track and report on Plan of Action and Milestone (POA&M) items; RMF Status,
Annual Assessments, Authority to Operate (ATO) and Continuous Monitoring
actions. - Responsible for documentation compliance and review to ensure programs
receive ATOs for multiple systems. - Prepare briefs and A&A documents for approval in support of RMF reporting and
policy development. - Perform ISSO Type duties as defined in DoD 8510 & 8500.
- Provide risk mitigation strategies.
- Perform quality checks on POA&Ms, risk assessments, and documentation.
Conduct security control and risk assessments to support authorizations. - Review existing documentation bi-annually for accuracy and relevance to current DoD and DCSA mandates.
- Assist with research on cybersecurity items of interest.
- Perform other duties as related to risk management, communication, and
assessments.
Minimum Qualifications:
- Secret clearance
- Bachelor’s degree in information technology, Information Systems Management,
Cyber Security, or some other related field, or additional years of experience in
lieu of a degree - A minimum of 5 years of hands-on technical Cyber Security Experience and knowledge with DISA Security Technical Information Guides, DoD A&A Process, NIST SP 800-53, IA Technical Framework, and applicable DoD Cyber Security / Risk
Management policies (must have DoD or eMASS experience) - A minimum of (1) year of knowledge of current security tools,
hardware/software security implementation, communication protocols, and
Microsoft Office suite - Must meet DoD 8570-M/8140-M IAT Level II
About Nationwide IT Services
NIS is a CVE-verified Service-Disabled Veteran-Owned Small Business and an IT and management consulting company. Our mission is to deliver value-added services to our customers, leveraging technology, people, and industry best practices to implement innovative solutions through our trusted employees and team members.
Our benefits package includes medical, dental, and vision insurance; life and disability insurance; a 401(k) plan with employer match; paid holidays; PTO (sick/vacation); commuter benefits; an employee assistance program (EAP); educational reimbursement; and pet insurance.
Salary range $100,000 to $110,000 annually
The salary range is a general guideline. We consider several factors when determining base salary offers, including the position's scope and responsibilities, the candidate's experience, education, and skills, and current market conditions.
Apply for this position
Required*