Amentum

RiskManagementFrameworkAnalyst

$125–125k Norfolk, Virginia, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“Risk Management Framework Analyst at Amentum. Skills: Risk Management Framework (RMF) process, cybersecurity, Assessment & Authorization (A&A). Lead the execution of all steps of the RMF process, including system categorization, security control selection, implementation, assessment, authorization, and continuous monitoring.. Develop, review, and maintain comprehensive RMF documentation, including the System Security Plan (SSP), Security Assessment Report (SAR), and Plans of Action and Milestone”

What You'll Achieve.

ensure all systems achieve and maintain compliance with Department of War (DoW) policies, enterprise objectives, and established governance processes.; manage system security posture from categorization to continuous monitoring, ensuring risks are properly mitigated and documented.; achieve and maintain compliance; risks are properly mitigated and documented; system's authority to operate (ATO)

Industry & Context.

Eligibility Requirements

Active Top Secret/SCI US Government Clearance, US Citizenship

What They're Looking For.

Must Have

5 years experience in cybersecurity, with a focus on Assessment & Authorization (A&A) and RMF., Experience creating and managing RMF documentation and utilizing tools such as eMASS., Experience conducting security control assessments and analyzing results from vulnerability scanning tools., Bachelor’s degree in Cybersecurity, Information Technology, or a related field., DoD 8570/8140 IAT/IAM Level II certification (e. g. , CompTIA Security+, CySA+)., Active Top Secret/SCI US Government Clearance., US Citizenship

Nice to Have

Certified Information Systems Security Professional (CISSP) or Certified in Governance, Risk and Compliance (CGRC)., written and verbal communication skills, including preparation of reports, briefings, and documentation for Government stakeholders.

What You'll Do.

Lead the execution of all steps of the RMF process

including system categorization

security control selection

and continuous monitoring.

and maintain comprehensive RMF documentation

including the System Security Plan (SSP)

Security Assessment Report (SAR)

and Plans of Action and Milestones (POA&Ms).

Translate assessment outcomes into actionable product artifacts

including risk assessments

vulnerability reports

and recommendations for inclusion in the system's POAM.

Coordinate with development teams

and enterprise stakeholders to validate security control implementation

assess integration impacts

and ensure alignment with established architecture and configuration governance processes.

Prepare and deliver executive-level summaries and system security status briefings

capturing prioritized risks

and strategic decisions impacting the system's authority to operate (ATO).

How You'll Work.

Team & Collaboration

Coordinate with development teams, system owners, and enterprise stakeholders to validate security control implementation, assess integration impacts, and ensure alignment with established architecture and configuration governance processes.

Communication Scope

written and verbal communication skills; preparation of reports, briefings, and documentation for Government stakeholders; executive-level summaries; system security status briefings

Full Job Description

The RMF Analyst shall be responsible for providing cybersecurity expertise and RMF lifecycle management in support of NIWDC IWTTF systems. The analyst shall ensure all systems achieve and maintain compliance with Department of War (DoW) policies, enterprise objectives, and established governance processes. The analyst will manage system security posture from categorization to continuous monitoring, ensuring risks are properly mitigated and documented. **Responsibilities include:** * Lead the execution of all steps of the RMF process, including system categorization, security control selection, implementation, assessment, authorization, and continuous monitoring. * Develop, review, and maintain comprehensive RMF documentation, including the System Security Plan (SSP), Security Assessment Report (SAR), and Plans of Action and Milestones (POA&Ms). * Translate assessment outcomes into actionable product artifacts, including risk assessments, vulnerability reports, and recommendations for inclusion in the system's POAM. * Coordinate with development teams, system owners, and enterprise stakeholders to validate security control implementation, assess integration impacts, and ensure alignment with established architecture and configuration governance processes. * Prepare and deliver executive-level summaries and system security status briefings, capturing prioritized risks, compliance status, and strategic decisions impacting the system's authority to operate (ATO). **Minimum Experience and Requirements:** * 5 years experience in cybersecurity, with a focus on Assessment & Authorization (A&A) and RMF. * Experience creating and managing RMF documentation and utilizing tools such as eMASS. * Experience conducting security control assessments and analyzing results from vulnerability scanning tools. * Bachelor’s degree in Cybersecurity, Information Technology, or a related field. * DoD 8570/8140 IAT/IAM Level II certification (e.g., CompTIA Security+, CySA+). * Must have an Ac

Free ATS check

Applying for this Risk Management Framework Analyst role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Workday

  • Workday has a multi-step form — save your progress after every section.
  • "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
  • Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
  • Job requisition numbers are useful when following up with HR by email.

ANONYMOUS · UNFILTERED

What do employees actually say about Amentum?

Real rants from real employees. Read before you apply.

Read Company Rants →