Summary
Semper Valens Solutions provides software, systems engineering, field support, training, and lifecycle support management to the Department of Defense and Department of Veterans Affairs. The company is seeking an RMF Analyst to support the assessment, authorization, and continuous monitoring of information systems under the NIST Risk Management Framework and federal cybersecurity guidelines. The role focuses on developing authorization documentation, assessing security controls, tracking vulnerabilities, and supporting Authorization to Operate activities.
Responsibilities
- Support execution of the RMF process across all six steps: Categorize, Select, Implement, Assess, Authorize, and Monitor
- Develop, review, and maintain security authorization documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports (RARs)
- Conduct security control assessments against NIST SP 800-53/800-53A control baselines and document findings
- Perform security categorization of information systems using FIPS 199/200 and NIST SP 800-60
- Coordinate with system owners, ISSOs, and ISSMs to identify, track, and remediate security vulnerabilities and control deficiencies
- Support continuous monitoring activities, including periodic control assessments, vulnerability scanning review, and configuration compliance checks
- Assist in the preparation and submission of Authorization to Operate (ATO), Interim ATO (IATO), and Authorization to Test (ATT) packages
- Utilize GRC tools (e.g., eMASS, Xacta, CSAM, Archer) to manage authorization packages and track compliance status
- Review and analyze security assessment results, audit logs, and scan reports (e.g., ACAS/Nessus, STIG checklists) to identify risks
- Support development and tracking of POA&Ms, ensuring timely remediation of identified weaknesses
- Ensure compliance with applicable frameworks, including FISMA, DoD RMF, CNSSI 1253, and agency-specific cybersecurity policies
- Prepare risk briefings and status reports for leadership, Authorizing Officials (AOs), and government stakeholders
- Stay current on evolving NIST guidance, DoD/agency policy updates, and emerging cybersecurity threats affecting authorization requirements
Skills
- Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field (or equivalent experience)
- 3+ years of experience supporting RMF, C&A/A&A processes within federal, DoD, or Intelligence Community environments
- Working knowledge of NIST SP 800-37, 800-53, 800-53A, 800-60, and FIPS 199/200
- Experience developing or reviewing SSPs, SARs, POA&Ms, and RAR documentation
- Familiarity with DoD or agency-specific implementation guides (e.g., DoDI 8510.01, ICD 503, CNSSI 1253)
- Hands-on experience with GRC/eMASS or equivalent RMF tracking tools
- Understanding of vulnerability management and STIG/SCAP compliance processes
- Active DoD 8570/8140-compliant certification (e.g., Security+, CySA+, or equivalent) - required or attainable within 6 months of hire
- Strong written communication skills for technical documentation and stakeholder reporting
- U.S. Citizenship required; active security clearance or eligibility to obtain one, per position requirements
- Active Secret clearance
- CISSP, CAP (Certified Authorization Professional), or CISM certification
- Experience with cloud authorization processes (FedRAMP, DoD Cloud Computing SRG)
- Familiarity with vulnerability scanning tools (ACAS/Nessus, Tenable) and SCAP compliance checkers
- Experience supporting Cybersecurity Service Provider (CSSP) or SOC operations
- Knowledge of Zero Trust Architecture principles and their application to RMF
- Experience working within Intelligence Community (IC) or Defense Industrial Base (DIB) environments
Qualifications
Must Haves
- Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field (or equivalent experience)
- 3+ years of experience supporting RMF, C&A/A&A processes within federal, DoD, or Intelligence Community environments
- Working knowledge of NIST SP 800-37, 800-53, 800-53A, 800-60, and FIPS 199/200
- Experience developing or reviewing SSPs, SARs, POA&Ms, and RAR documentation
- Familiarity with DoD or agency-specific implementation guides (e.g., DoDI 8510.01, ICD 503, CNSSI 1253)
- Hands-on experience with GRC/eMASS or equivalent RMF tracking tools
- Understanding of vulnerability management and STIG/SCAP compliance processes
- Active DoD 8570/8140-compliant certification (e.g., Security+, CySA+, or equivalent) - required or attainable within 6 months of hire
- Strong written communication skills for technical documentation and stakeholder reporting
- U.S. Citizenship required; active security clearance or eligibility to obtain one, per position requirements
Nice to Haves
- Active Secret clearance
- CISSP, CAP (Certified Authorization Professional), or CISM certification
- Experience with cloud authorization processes (FedRAMP, DoD Cloud Computing SRG)
- Familiarity with vulnerability scanning tools (ACAS/Nessus, Tenable) and SCAP compliance checkers
- Experience supporting Cybersecurity Service Provider (CSSP) or SOC operations
- Knowledge of Zero Trust Architecture principles and their application to RMF
- Experience working within Intelligence Community (IC) or Defense Industrial Base (DIB) environments
Benefits
- Full Time, Remote, San Antonio, TX area
- Active Secret clearance
- DoD 8570/8140-compliant certification (e.g., Security+, CySA+, or equivalent) - required or attainable within 6 months of hire