RMF Analyst IV
Listed on 2026-01-02
-
IT/Tech
Cybersecurity, Information Security
RMF Analyst IV – Huntsville, AL
Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer’s core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting‑edge technology and take your career to the next level.
Chronos Operations (CO) is a wholly‑owned subsidiary of Chenega Corporation, an Alaska Native Corporation based in Anchorage, AK. Belonging to the Military, Intelligence, and Operations Support (MIOS) Strategic Business Unit (SBU), Chronos has a culture rooted in integrity, respect, and exceptional performance. Chronos is headquartered in Colorado Springs, CO, and provides mission‑critical services in Advanced Analytics & AI, Software Engineering, Cybersecurity, Information Technology, and Intelligence.
Chronos Operations, LLC is seeking an experienced RMF Analyst IV to provide oversight and resources needed to execute the contract requirements for the Army Materiel Command (AMC), Chief Information Office (CIO), across a wide range of cybersecurity tasks. The RMF Analyst IV conducts senior‑level RMF analysis, artifact generation, and control validation.
Responsibilities- Senior RMF practitioner managing ATO packages, continuous monitoring plans, and eMASS documentation.
- Leads RMF stakeholder coordination with AO/AODR and security teams.
- Deep understanding of cybersecurity frameworks, documentation, and technical validation processes, working closely with stakeholders and control assessors to ensure security and compliance.
- Track timely and high‑quality completion of process tasks and milestones, and report on the status of key milestones to performers and senior stakeholders.
- Oversee the cybersecurity lifecycle from inception to completion.
- Develop, review, and update documentation to ensure compliance with RMF and Continuous Monitoring requirements.
- Evaluate and validate technical processes related to ATO (Authority to Operate) requirements, ensuring alignment with cybersecurity standards.
- Provide direct support to Control Assessors, assisting in the preparation and review of authorization information and documentation for RMF and Continuous Monitoring.
- Assist with eMASS package completion and maintenance, including artifacts, self‑assessments, and asset management.
- Review project schedules, requirements, and risk assessments, offering recommendations to program stakeholders to enhance security posture.
- Develop security plans, as well as assessment reports, plans of action and milestones for remediation. Define criticality or sensitivity of systems, perform categorization calculations, and recommend corrective action.
- Recommend baseline security controls, assess changes in controls, and coordinate changes to security authorizations.
- Conduct evaluations to verify that design and implementation meet requirements.
- Prepare test plans and conduct security control testing in accordance with NIST SP800‑53.
- Other duties as assigned.
- Bachelor’s degree in science, technology, engineering, mathematics, IT, or business‑related programs.
- 8+ years of experience in Cybersecurity compliance/Risk Management Framework.
- 8+ years of experience with RMF (NIST 800‑53), ATO packages, POA&M development, and system categorization is required.
- 3+ years’ experience supporting DoD or federal programs is highly desirable.
- Cybersecurity certifications like CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager), or CGRC (Certified in Governance, Risk and Compliance) are required.
- Must have an active Secret clearance with the ability to obtain TS with SCI eligibility.
- Experience with eMASS and/or Xacta is required (preferably eMASS).
- Experience with cloud platforms like Amazon Web Services (AWS), Microsoft Azure, etc., and migrating customers/projects to the cloud.
- Experience working in a Unix/Linux environment.
- Experience working…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).