Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Wintrio LLC

Security Analyst Risk Management Framework (RMF) / Assessment & Authorization

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
72
out of 100
Average of individual scores

Were these scores useful?

Job Description

Security Analyst Risk Management Framework (RMF) / Assessment & Authorization at Wintrio LLC Security Analyst Risk Management Framework (RMF) / Assessment & Authorization at Wintrio LLC in Cambridge, Massachusetts Posted in 10 days ago.

Type:

full-time

Position Title:

Security Analyst Risk Management Framework (RMF) /

Assessment & AuthorizationLocation:

Remote with Hybrid Work in

MarylandCitizenship:

U.S. Citizenship required

Employment Type:

Full-TimeHow to Apply your resume: careers@wintrio.comPosition OverviewWINTrio is seeking an experienced Security Analyst with strong Risk Management Framework (RMF), Assessment & Authorization (A&A), and Authority to Operate (ATO) experience to support USDA information systems.



The position requires hands-on experience developing and maintaining Federal RMF/A&A packages and working with NIST and agency security requirements. USDA RMF and

USDA CSAM

experience are highly desirable.



Key ResponsibilitiesCollect, review, and update system information.



Create and maintain system records in Cybersecurity Assessment and Management System (CSAM).Develop/update and upload Privacy Threshold Analyses (PTAs).Perform and document system security categorization.



Develop/update Privacy Impact Assessments (PIAs).Develop/update E-Authentication Risk Assessments.



Maintain system identification information and system/technical narratives within CSAM.Identify common and inherited security controls.



Develop and maintain compliance descriptions for security controls.



Support security-control tailoring.



Develop compensating controls where required.

Develop/update:

Contingency Plans (CP)CP test, training, and exercise documentationSystem of Records Notices (SORN)Configuration Management Plans (CMP)Incident Response Plans (IRP)Business Impact Assessments (BIA)Interconnection Security Agreements (ISA)Finalize System Security Plan (SSP) compliance descriptions.



Finalize Contingency Plans.



Finalize CMPs, IRPs, and Disaster Recovery Plans where applicable.



Review RMF packages for completeness and readiness.



Assist

USDA REE

stakeholders in resolving findings and updating documentation during concurrence review.



Required QualificationsWorking knowledge of:


NIST Risk Management Framework

FIPS PUB 199NIST SP 800-53

Rev. 4/5NIST

SP 800-37

Rev. 2NIST

SP 800-171

Rev. 2NIST

SP 800-47

Rev. 1Experience developing security-control implementation/compliance descriptions.



Experience developing Federal security and authorization documentation such as SSPs, CPs, CMPs, IRPs, BIAs, PIAs, ISAs, and related RMF artifacts.



Experience using CSAM or a comparable Federal governance, risk, and compliance/RMF system.



Experience completing all aspects of the

NIST RMF

process.



Ability to work collaboratively with system owners, ISSOs/ISSMs, technical teams, privacy personnel, and Government security stakeholders.



Strong technical writing, documentation, analytical, and quality-assurance skills.



Must be able to satisfy applicable background investigation/Public Trust, HSPD-12, PIV, and facility/system access requirements.



Highly Desired QualificationsPrevious experience supporting

USDA RMF

programs.



Working knowledge of:


USDA Risk Management Framework 2.0USDA Six-Step RMF ProcessUSDA Departmental Regulation 3540-003, Security Assessment and Authorization

USDA POA&M

proceduresHands-on experience with the

USDA CSAM

instance.



Previous USDA or other Federal civilian agency cybersecurity experience.



Experience obtaining ATOs for FedRAMP products, platforms, or solutions.



Experience supporting FISMA-regulated Federal systems.



Prior participation in similar Federal RMF/A&A projects.



Work EnvironmentFull-time position.



Primarily remote within the United States.



Occasional on-site support may be requested in the Washington, DC / Northern Virginia area.



Standard Federal business hours.



All work must be performed within the United States.



WINTrio BenefitsHealthcare, Medical, Dental, and VisionFSA and HSA options401(k) Retirement PlanAnnual Bonus and Profit Sharing OpportunitiesPaid Time OffEmployee Assistance ProgramLife and Disability InsuranceEqual Opportunity EmployerWINTrio LLC is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by applicable law. recblid dztfdahvmczqs7cwh3sg9zhbui06j6

Benefits

  • Paid Time Off (PTO)
  • Employee Stock Options (ESOs)
  • Health and Wellness Programs
  • Health Insurance