RMF / CSAM Analyst
Core
Ensures the FSA IAM system maintains continuous security authorization and compliance through the Risk Management Framework (RMF) and the Cyber Security Assessment and Management (CSAM) tool.
Role type
Compliance and security operations analyst (IAM)
Builds
Secure operation of cloud-based IAM solutions meeting federal standards
Domain
Federal government cybersecurity and identity management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
NIST RMF, CSAM tool, FedRAMP, FISMA, POA&M management, security control inheritance, NIST SP 800-63, OMB M-21-31, cloud security, scan result analysis, corrective action planning, remediation tracking, data encryption, logging, compliance reporting, federal cybersecurity policies
Preferred skills
Security Incident Management, CDM findings, CVE responses, Cybersecurity Framework scorecard, supply chain risk management, CUI handling, IT accessibility (Section 508), technology business management reporting
Technologies
AES-256, SHA-256, TLS, Microsoft Office
Responsibilities
Manage event logging to meet OMB M-21-31 standards, oversee data encryption at rest and in transit, track and remediate POA&M items, support FISMA reporting and corrective action plans, address CDM findings, handle CVE responses, maintain CSF scorecard, support supply chain risk management and CUI handling, maintain documentation for Authority to Operate (ATO)
Seniority
Mid-level, hands-on IC