RMF Analyst
Listed on 2026-09-20
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Minimum Clearance Required
Top Secret SCI
ResponsibilitiesI2X Technologies is a reputable technology services company to the Federal Government. Whether the focus is on space exploration, national security, cyber security, or cutting-edge engineering applications, I2X is ready to offer you the chance to make a real-world impact in your field and for your country. We provide long-term growth and development. Headquartered in Colorado, I2X is engaged in programs across the country and in more than 20 states.
Our programs support multiple Federal agencies, the Department of Defense and often focused on the space initiatives of our government customers.
I2X Technologies is seeking an RMF Analyst to support ongoing activities for a customer in Colorado Springs, CO.
This position will be on-site and will require an active TS/SCI.
- Supporting and executing the RMF process across multiple enterprise systems and enclaves by maintaining system registrations, security baselines, and evidentiary records within the Enterprise Mission Assurance Support Service (eMASS).
- Operating with ISSO-level ownership to independently drive continuous monitoring and Authority to Operate (ATO) sustainment, ensuring an uninterrupted and robust security posture.
- Ensuring cybersecurity standards and operational hygiene are consistently maintained to support a Cyber Operational Readiness Assessment (CORA)-ready posture.
- Managing the continuous cybersecurity posture of enterprise systems and identifying mitigations necessary to meet Department of Defense Directive (DoDD) 8500.01, Department of Defense Instruction (DoDI) 8510.01, DoDD 8140.01, and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 requirements.
- Analyzing and correlating scan results from the Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP), and other approved tools to evaluate system risk, determine security posture, and maintain ATO and Assess Only authorizations.
- Assisting with system categorization in accordance with Committee on National Security Systems Instruction (CNSSI) 1253, including confidentiality, integrity, and availability impact levels, as information types, mission profiles, and system interconnections evolve.
- Leading the development, maintenance, and technical validation of System Security Plans (SSPs), ensuring evidentiary artifacts accurately reflect current technical architectures and that applicable Security Technical Implementation Guides (STIGs) are implemented.
- Exercising end-to-end ownership of Plans of Action and Milestones (POA&Ms) by systematically evaluating deficiencies, determining risk impacts, and coordinating with technical stakeholders to drive findings to timely closure.
- Collaborating proactively with system administrators, network engineers, and leadership to remediate STIG findings, vulnerability scan results, and architectural deficiencies.
- Providing strategic cybersecurity guidance, risk assessments, and status updates to system owners and leadership.
- Providing weekly status reports that summarize accomplishments across assigned packages, risk posture, issues, and paths forward.
- Creating, refining, and enforcing the operational policies, procedures, and artifacts necessary to ensure security controls are fully implemented and audit-ready.
- Certification required in accordance with DoD Manual (DoDM) 8140.03 at the Intermediate level, such as CompTIA Security+ or an equivalent certification.
- Bachelor’s degree in information assurance, cybersecurity, or a related field, plus 3–5 years of relevant experience; or a high school diploma or equivalent plus 7–10 years of relevant information assurance or cybersecurity experience.
- At least 2 years…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).