The RMF Cybersecurity Analyst II supports Risk Management Framework (RMF) compliance activities, cyber compliance processes, and incident response efforts for networked systems and applications used by the organization. This role is responsible for maintaining RMF documentation and supporting records, supporting audit and review activities, tracking cyber-related workflows, and assisting with software and license compliance activities. The ideal candidate is an experienced cyber professional with knowledge of RMF processes, cybersecurity documentation, and compliance tools who can work effectively with technical staff, compliance personnel, and stakeholders in a regulated environment.
Key Responsibilities
- Support RMF compliance activities, including review of policy documents, package materials, supporting records, and maintenance of RMF artifacts and eMASS records
- Support RMF package reviews, laboratory audit activities, and follow-up documentation requirements
- Review, monitor, and track cyber-related tickets, incident response actions, and associated workflows
- Support cyber compliance activities related to software and license records, unit-level audits, STIG remediation, and documentation updates
- Work with technical staff, compliance personnel, and stakeholders to collect required information, identify documentation gaps, and support follow-up actions
Requirements
- Bachelor’s degree or equivalent work experience
- 3–5 years of relevant experience in cybersecurity, RMF, cyber compliance, incident response support, vulnerability management, or related cyber operations
- Must possess an active DoD 8570.01-M IAT Level II certification, such as Security+
- Familiarity with NIST SP 800-37 and NIST SP 800-53 Revision 5
- Experience maintaining cybersecurity documentation, supporting artifacts, and records in eMASS or similar compliance environments
- Familiarity with ACAS, Trellix ePO, STIG compliance, and cyber-related ticket workflows
- Ability to work effectively with technical staff, compliance personnel, and stakeholders in a regulated environment
- Must possess or be able to obtain any required security clearance or access required for the position
Preferred Qualifications
- Experience supporting RMF packages, POA&M updates, security control documentation, or audit follow-up activities
- Experience supporting laboratory, research, or other regulated IT environments
- Familiarity with incident documentation, vulnerability tracking, forensics concepts, or Department of War cybersecurity compliance processes
- Experience maintaining hardware/software inventories, system lists, topology documentation, or proficiency with Microsoft Visio or Microsoft Project
Benefits
Benefits Include:
- Covers 100% of employee benefit premiums, including Medical (PPO or HDHP Option), Vision, Dental
- Matching 401K
- Short- and Long-Term Disability
- Pet Insurance
- Professional Development/Education Reimbursement
- Parking and Transit Benefits for NY, NJ, ATL, and DC Metro areas
Other Duties:
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.
Skills Required
- Bachelor's degree or equivalent work experience
- 3–5 years of relevant experience in cybersecurity, RMF, cyber compliance, incident response support, vulnerability management, or related cyber operations
- Active DoD 8570.01-M IAT Level II certification, such as Security+
- Familiarity with NIST SP 800-37 and NIST SP 800-53 Revision 5
- Experience maintaining cybersecurity documentation, supporting artifacts, and records in eMASS or similar compliance environments
- Familiarity with ACAS, Trellix ePO, STIG compliance, and cyber-related ticket workflows
- Ability to work effectively with technical staff, compliance personnel, and stakeholders in a regulated environment
- Possess or be able to obtain any required security clearance or access
- Experience supporting RMF packages, POA&M updates, security control documentation, or audit follow-up activities
- Experience supporting laboratory, research, or other regulated IT environments
- Familiarity with incident documentation, vulnerability tracking, forensics concepts, or Department of War cybersecurity compliance processes
- Experience maintaining hardware/software inventories, system lists, topology documentation, or proficiency with Microsoft Visio or Microsoft Project
What We Do
DNI (Delaware Nation Industries) is the parent organization for all Information Technology focused businesses owned by the Delaware Nation. Founded in 2014 DNI was created to support the rapid growth of the tribe’s first 8(a) technology firm, Indigenous Technologies, LLC. In 2011 Indigenous Technologies began several teaming partnerships with CSI, LLC. and was awarded 4 prime contracts with federal customers as a result of this arrangement. This partnership continued through the Fall of 2014 when DNI purchased CSI adding its capabilities and past performance to the growing Tribal IT Services division. As a result of this strategic acquisition by the Delaware Nation, CSI became the second Tribally owned technology focused LLC in the Delaware Nation portfolio. The third company under DNI operations is CreativeIT, LLC. CreativeIT is being built with an eye to the future and is focused on developing core competencies which supplement the strong capabilities of its sister organizations. DNI continues to build a strong team of companies, providing an all-inclusive suite of Information Technology services and capabilities to our clients.








