RMF / A&A Analyst

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in Bethesda, MD, USA
In-Office or Remote
90K-100K Annually
Mid level
Information Technology • Professional Services
The Role
Maps NIH FISMA systems to Zero Trust and inherited controls, identifies control gaps, manages POA&Ms, supports A&A pilots, develops SSP/SAP/SAR templates, maintains control libraries and documentation, and supports continuous monitoring. The role requires federal RMF/A&A experience, NIST and FISMA knowledge, GRC tool expertise, security certification, and a current T2 investigation or higher.
Summary Generated by Built In

Company Overview:

Over the past 15 years, eTel has delivered essential solutions for the federal government by securing and managing data, providing scalable identity access, modernizing legacy systems, and building high-performance platforms. By integrating new technologies and ensuring reliable operations we help agencies stay prepared for future challenges As a premier technology solutions and services company to the US federal government, eTel possesses longstanding relationships across the federal civilian marketplace. Other customers include the broader Treasury Department, Commerce Department, and State Department.


eTel offers integrated CMMI Level 3 processes, tools, and techniques with innovative, cost-efficient, and secure solutions to address complex challenges. eTel also holds ISO 9001:2015, ISO/IEC 27001:2013, and ISO/IEC 20000-1:2018 certifications, and offers dedicated subject matter experts (SMEs) and thought leaders that possess a deep understanding of customers’ environments and challenges.

Work Location and On-Site/Telework Requirements: Hybrid – NIH, Bethesda, MD. On site for A&A working sessions and pilots (typically 1–2 days/week during the first 120 days, then as scheduled).

Citizenship: U.S. Citizenship required

Clearance: All staff must obtain NIH suitability and a PIV credential and be fluent in English. Anyone doing risk or vulnerability testing needs a current T2 (BI) or higher investigation.

Salary Range: $90,000-$100,000 yearly salary

 

Overview:

You will map NIH's FISMA systems to the Zero Trust controls they can inherit and help make Zero Trust assessable inside NIH's A&A process under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). You will work in the Risk & Policy Pod on Task 4 and Subtasks 2.5 and 1.2, reporting technically to the Security Lead.

 

Responsibilities:

  • Pull the CSAM inventory and map the control set of each of NIH's 72 FISMA-registered systems against the Centrally Provided Services Matrix. Identify inherited, hybrid, and uncovered controls for the Inherited Controls Mapping and Remediation Roadmap (Subtask 2.5, due at 120 days, refreshed quarterly).
  • Score residual gaps by FIPS 199 impact, data sensitivity, and internet exposure.
  • Support the Task 4 pipeline baseline: time per phase, rework loops, inherited versus re-documented controls, and upcoming authorizations.
  • Build the ZTA Overlay mappings and evidence expectations, tagging each control as central, hybrid, or system-specific. Support the CSAM import and the three-system pilot.
  • Maintain records in the shared NIH ZTA control library.
  • Develop package templates (SSP, SAP/SAR, POA&M) and continuous-monitoring cadences (SP 800-137) for the three authorization tiers.
  • Keep the IC-inheritable controls content current on the OCIO ZTA Wiki, and answer control questions routed from the ZTA help desk.

Tools & Technology Environment: CSAM (primary), Xacta, RSA/SGRC Archer, ServiceNow; Excel and Power BI; Confluence/SharePoint and the OCIO ZTA Wiki.


Required Qualifications:

  • Bachelor's degree plus 4+ years of RMF/A&A experience in a federal environment.
  • Working knowledge of NIST SP 800-37 Rev 2, 800-53 Rev 5, 800-53A, and FISMA.
  • Hands-on POA&M management and experience with CSAM or a comparable GRC tool.
  • Security+ or CAP/CGRC certification.
  • Current T2 (BI) or higher federal background investigation, acceptable through reciprocity.

Preferred Qualifications:

  • HHS or NIH A&A experience in CSAM.
  • Common-control and inheritance modeling; experience with Zero Trust control mapping.
  • FedRAMP experience; CGRC or CISA certification.
  • Current National Institutes of Health (NIH) or U.S. Department of Health and Human Services (HHS) experience is highly preferred.

Commitment to Diversity -
eTelligent Group provides equal employment opportunities (EEO) to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, nations origin, age, disability, genetic information, marital status, amnesty, status as a covered veteran, and any other characteristic provided in accordance with applicable, federal, state and local laws.

Skills Required

  • Bachelor's degree
  • 4+ years of RMF/A&A experience in a federal environment
  • Working knowledge of NIST SP 800-37 Rev. 2, NIST SP 800-53 Rev. 5, NIST SP 800-53A, and FISMA
  • Hands-on POA&M management experience
  • Experience with CSAM or a comparable GRC tool
  • Security+ or CAP/CGRC certification
  • Current T2 (BI) or higher federal background investigation, acceptable through reciprocity
  • HHS or NIH A&A experience using CSAM
  • Common-control and inheritance modeling experience
  • Zero Trust control mapping experience
  • FedRAMP experience
  • CGRC or CISA certification
  • Current NIH or HHS experience
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Leesburg, VA
33 Employees
Year Founded: 2005

What We Do

eTelligent Group is a proven team of talented IT professionals providing reliable solutions for business & information technology (IT) management and services. We solve complex program and IT problems by implementing proven strategies & innovative solutions. We deliver IT services, agile and DevOps development, big data services, IT program management, and cyber security services. Working as a trusted partner of the Federal Government, we hold ourselves to the highest industry standards such as (CMMI Level 3 and PMBOK). We are proud of our outstanding past performance implementing client solutions that increase both reliability and security for our clients. We deliver professional services by applying our proven process methodologies to exceed performance standards. We partner with leading COTS solution providers such as webMethods, MuleSoft, and RedHat to provide Middleware, API-led integrations, and SOA-based solutions. We deliver cutting edge technical solutions, while meeting the core business needs of each client.

Similar Jobs

PingWind Logo PingWind

RMF / CSAM Analyst

Information Technology • Consulting
Remote
USA
142 Employees
75K-104K Annually

MetLife Logo MetLife

Site Reliability Engineer

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
111K-180K Annually

Applied Systems Logo Applied Systems

Consultant

Artificial Intelligence • Cloud • Payments • Software • Business Intelligence • Generative AI • Automation
Remote or Hybrid
United States
3116 Employees
85K-105K Annually
Easy Apply
Remote or Hybrid
USA
208 Employees
200K-300K Annually

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account