Wintrio LLC Security Analyst – Risk Management Framework (RMF) / Assessment & Authorization Remote · Full time Company website

Position Overview WINTrio is seeking an experienced Security Analyst with strong Risk Management Framework (RMF), Assessment & Authorization (A&A), and Authority to Operate (ATO) experience to support USDA information systems. The position requires hands-on experience developing and maintaining Federal RMF/A&A packages and working with NIST and agency security requirements. USDA RMF and USDA CSAM experience are highly desirable.

About Wintrio LLC

WINTrio is an 8(a) and HUBZone organization with a successful record of delivering high-quality technical and professional services to federal and commercial customers including USCIS and Walmart. WINTrio manages and improves overall performance through IT Modernization practices. Our team of seasoned Cyber Security, Cloud/DevSecOps, software, and Support Experts helps your organization secure its digital environment with innovative and bleeding-edge technology solutions based on best practices and approved industry standards. We deliver a 360-degree spectrum of Systems Integration services from Inception to Project Delivery. At WINTrio we provide tailored customized services to meet all your business needs.

Description

Position Title: Security Analyst – Risk Management Framework (RMF) / Assessment & Authorization

Location: Remote with Hybrid Work in Maryland

Citizenship: U.S. Citizenship required

Employment Type: Full-Time

How to Apply

Email your resume: [email protected]

Position Overview

WINTrio is seeking an experienced Security Analyst with strong Risk Management Framework (RMF), Assessment & Authorization (A&A), and Authority to Operate (ATO) experience to support USDA information systems.

The position requires hands-on experience developing and maintaining Federal RMF/A&A packages and working with NIST and agency security requirements. USDA RMF and USDA CSAM experience are highly desirable.

Key Responsibilities


  • Collect, review, and update system information.
  • Create and maintain system records in Cybersecurity Assessment and Management System (CSAM).
  • Develop/update and upload Privacy Threshold Analyses (PTAs).
  • Perform and document system security categorization.
  • Develop/update Privacy Impact Assessments (PIAs).
  • Develop/update E-Authentication Risk Assessments.
  • Maintain system identification information and system/technical narratives within CSAM.
  • Identify common and inherited security controls.
  • Develop and maintain compliance descriptions for security controls.
  • Support security-control tailoring.
  • Develop compensating controls where required.
  • Develop/update:
  • Contingency Plans (CP)
  • CP test, training, and exercise documentation
  • System of Records Notices (SORN)
  • Configuration Management Plans (CMP)
  • Incident Response Plans (IRP)
  • Business Impact Assessments (BIA)
  • Interconnection Security Agreements (ISA)
  • Finalize System Security Plan (SSP) compliance descriptions.
  • Finalize Contingency Plans.
  • Finalize CMPs, IRPs, and Disaster Recovery Plans where applicable.
  • Review RMF packages for completeness and readiness.
  • Assist USDA REE stakeholders in resolving findings and updating documentation during concurrence review.

Required Qualifications


  • Working knowledge of:
  • NIST Risk Management Framework
  • FIPS PUB 199
  • NIST SP 800-53 Rev. 4/5
  • NIST SP 800-37 Rev. 2
  • NIST SP 800-171 Rev. 2
  • NIST SP 800-47 Rev. 1
  • Experience developing security-control implementation/compliance descriptions.
  • Experience developing Federal security and authorization documentation such as SSPs, CPs, CMPs, IRPs, BIAs, PIAs, ISAs, and related RMF artifacts.
  • Experience using CSAM or a comparable Federal governance, risk, and compliance/RMF system.
  • Experience completing all aspects of the NIST RMF process.
  • Ability to work collaboratively with system owners, ISSOs/ISSMs, technical teams, privacy personnel, and Government security stakeholders.
  • Strong technical writing, documentation, analytical, and quality-assurance skills.
  • Must be able to satisfy applicable background investigation/Public Trust, HSPD-12, PIV, and facility/system access requirements.

Highly Desired Qualifications


  • Previous experience supporting USDA RMF programs.
  • Working knowledge of:
  • USDA Risk Management Framework 2.0
  • USDA Six-Step RMF Process
  • USDA Departmental Regulation 3540-003, Security Assessment and Authorization
  • USDA POA&M procedures
  • Hands-on experience with the USDA CSAM instance.
  • Previous USDA or other Federal civilian agency cybersecurity experience.
  • Experience obtaining ATOs for FedRAMP products, platforms, or solutions.
  • Experience supporting FISMA-regulated Federal systems.
  • Prior participation in similar Federal RMF/A&A projects.

Work Environment


  • Full-time position.
  • Primarily remote within the United States.
  • Occasional on-site support may be requested in the Washington, DC / Northern Virginia area.
  • Standard Federal business hours.
  • All work must be performed within the United States.

WINTrio Benefits


  • Healthcare, Medical, Dental, and Vision
  • FSA and HSA options
  • 401(k) Retirement Plan
  • Annual Bonus and Profit Sharing Opportunities
  • Paid Time Off
  • Employee Assistance Program
  • Life and Disability Insurance

Equal Opportunity Employer

WINTrio LLC is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by applicable law.

Salary

$10,000 - $300,000 per year