Verified current Job

RMF / CSAM Analyst

Current RMF / CSAM Analyst opening at Api Lever Co Opportunities in Remote. Full employer-published role information has been imported from the public Lever posting.

Job Remote Full source details
Api Lever Co Opportunities Remote, United States Verified 12 hours ago Reference da7c38ba-5f9a-455a-ab2d-fe5099ad3b2b
✓ 90% verification score · Source: Api Lever Co Opportunities · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-Time
Work modeRemote / location-flexible
CountryUnited States
DepartmentUpcoming Work

Overview

Current RMF / CSAM Analyst opening at Api Lever Co Opportunities in Remote. Full employer-published role information has been imported from the public Lever posting.

Full job description

Full opportunity description

Location: Remote Required Clearance: Public Trust Required Education: Bachelors Degree Required Experience: 2 years

Position Description

The RMF / CSAM Analyst is responsible for ensuring the FSA IAM system maintains continuous security authorization and compliance through the Risk Management Framework (RMF) and the Cyber Security Assessment and Management (CSAM) tool. This role supports the secure operation of the new cloud-based IAM solution while meeting all federal standards for identity services.

Responsibilities

The RMF / CSAM Analyst ensures the IAM solution complies with FedRAMP requirements, OMB M-24-15 guidance, and NIST SP 800-63 Digital Identity Guidelines. They manage event logging to meet OMB M-21-31 standards and oversee proper encryption of data at rest (AES-256 with SHA-256) and data in transit (latest TLS protocols). The analyst supports Security Incident Management, maintains environment support documentation, and handles key user data encryption and protection requirements. In CSAM, they manage security controls and inheritance statements, track and remediate Plan of Action and Milestones (POA&M) items, support FISMA reporting and corrective action plans, address Continuous Diagnostics and Monitoring (CDM) findings, handle Common Vulnerabilities and Exposures (CVE) responses, and maintain the Cybersecurity Framework (CSF) scorecard at the required level or higher. Additional responsibilities include supporting supply chain risk management, data planning, federal records and Controlled Unclassified Information (CUI) handling, IT accessibility (Section 508), technology business management reporting, and project, risk, and schedule documentation needed to sustain the Authority to Operate (ATO).

Required Qualifications

  • Strong knowledge of NIST Risk Management Framework (RMF) and CSAM tool
  • Experience with FedRAMP, FISMA, POA&M management, and security control inheritance
  • Familiarity with NIST SP 800-63, OMB M-21-31, and cloud security requirements
  • Ability to analyze scan results, develop corrective action plans, and track remediation
  • Excellent documentation, organization, and attention to detail skills
  • Clear communication and collaboration with ISSOs, security teams, and stakeholders
  • Understanding of data encryption, logging, and compliance reporting
  • Proficiency with Microsoft Office tools and compliance tracking systems
  • Ability to work effectively on both routine compliance tasks and urgent security issues
  • Commitment to maintaining high cybersecurity standards in a federal environment
  • Detail-oriented with excellent documentation and tracking skills
  • Good understanding of federal cybersecurity policies and compliance requirements
  • Team player capable of supporting both routine compliance and urgent security tasks

About PingWind

PingWind is focused on delivering outstanding services to the federal government. We have extensive experience in the fields of cybersecurity, development, IT infrastructure, supply chain management and other professional services such as system design and continuous improvement. PingWind is an SBA certified Service-Disabled Veteran-Owned Small Business (SDVOSB) with offices in Northern Virginia and Huntsville AL. www.PingWind.com

Our benefits include:

· Eleven Federal Holidays · Paid Time Off accrued each pay period · Parental Leave · Three medical plan choices with generous employer contribution · Dental and Vision Insurance · Company paid Short-Term and Long-Term Disability · Company paid Life and AD&D Insurance · 401k with competitive matching and vesting schedule · Continuing education assistance · Short Term / Long Term Disability & Life Insurance · Medical, Dependent Care and Commuter Flexible Spending Accounts · Employee Assistance Program · Wellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass) · 529 College Savings Plan · Legal Insurance · Pet Insurance

Salary Range

$75k-$104K

The pay range for this job is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) job responsibilities, education, certifications, experience, as well as internal equity mapping and alignment with market data, or other applicable laws.

Veterans are encouraged to apply

PingWind, Inc. does not discriminate in employment opportunities, terms, and conditions of employment, or practices on the basis of race, age, gender, religious or political beliefs, national origin or heritage, disability, sexual orientation, or any characteristic protected by law. \n

\n

RMF / CSAM Analyst

Location: RemoteRequired Clearance: Public Trust Required Education: Bachelors DegreeRequired Experience: 2 years Position Description The RMF / CSAM Analyst is responsible for ensuring the FSA IAM system maintains continuous security authorization and compliance through the Risk Management Framework (RMF) and the Cyber Security Assessment and Management (CSAM) tool. This role supports the secure operation of the new cloud-based IAM solution while meeting all federal standards for identity services. Responsibilities The RMF / CSAM Analyst ensures the IAM solution complies with FedRAMP requirements, OMB M-24-15 guidance, and NIST SP 800-63 Digital Identity Guidelines. They manage event logging to meet OMB M-21-31 standards and oversee proper encryption of data at rest (AES-256 with SHA-256) and data in transit (latest TLS protocols). The analyst supports Security Incident Management, maintains environment support documentation, and handles key user data encryption and protection requirements. In CSAM, they manage security controls and inheritance statements, track and remediate Plan of Action and Milestones (POA&M) items, support FISMA reporting and corrective action plans, address Continuous Diagnostics and Monitoring (CDM) findings, handle Common Vulnerabilities and Exposures (CVE) responses, and maintain the Cybersecurity Framework (CSF) scorecard at the required level or higher. Additional responsibilities include supporting supply chain risk management, data planning, federal records and Controlled Unclassified Information (CUI) handling, IT accessibility (Section 508), technology business management reporting, and project, risk, and schedule documentation needed to sustain the Authority to Operate (ATO). Required Qualifications

  • Strong knowledge of NIST Risk Management Framework (RMF) and CSAM tool- Experience with FedRAMP, FISMA, POA&M management, and security control inheritance- Familiarity with NIST SP 800-63, OMB M-21-31, and cloud security requirements- Ability to analyze scan results, develop corrective action plans, and track remediation- Excellent documentation, organization, and attention to detail skills- Clear communication and collaboration with ISSOs, security teams, and stakeholders- Understanding of data encryption, logging, and compliance reporting- Proficiency with Microsoft Office tools and compliance tracking systems- Ability to work effectively on both routine compliance tasks and urgent security issues- Commitment to maintaining high cybersecurity standards in a federal environment- Detail-oriented with excellent documentation and tracking skills- Good understanding of federal cybersecurity policies and compliance requirements- Team player capable of supporting both routine compliance and urgent security tasks About PingWind PingWind is focused on delivering outstanding services to the federal government. We have extensive experience in the fields of cybersecurity, development, IT infrastructure, supply chain management and other professional services such as system design and continuous improvement. PingWind is an SBA certified Service-Disabled Veteran-Owned Small Business (SDVOSB) with offices in Northern Virginia and Huntsville AL.www.PingWind.com Our benefits include: · Eleven Federal Holidays· Paid Time Off accrued each pay period· Parental Leave· Three medical plan choices with generous employer contribution· Dental and Vision Insurance· Company paid Short-Term and Long-Term Disability· Company paid Life and AD&D Insurance· 401k with competitive matching and vesting schedule · Continuing education assistance· Short Term / Long Term Disability & Life Insurance· Medical, Dependent Care and Commuter Flexible Spending Accounts· Employee Assistance Program · Wellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass)· 529 College Savings Plan· Legal Insurance · Pet Insurance Salary Range $75k-$104K The pay range for this job is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) job responsibilities, education, certifications, experience, as well as internal equity mapping and alignment with market data, or other applicable laws.

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

Discovered directly from the employer’s public Lever Postings API. Full public description, role lists and additional information were normalized into safe candidate-facing content. Full details checked against the authoritative public source during this discovery run.

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Api Lever Co Opportunities ↗

Browse current Job and Scholarship listings from Api Lever Co Opportunities →

Related opportunities

Other current verified records you may want to review.

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books