Full-Time

Risk Management Framework Analyst

Posted on 3/14/2025

Booz Allen

Booz Allen

Consulting in strategy, technology, and engineering

Compensation Overview

$75.6k - $172kAnnually

Mid

Suffolk, VA, USA

The position may require travel CONUS and OCONUS.

US Top Secret Clearance Required

Category
Cybersecurity
IT & Security
Requirements
  • 3+ years of experience with independently performing validator activities defined in the Navy’s RMF Process Guide, SCA Risk Assessment Guide, and USN RMF SOPs, and applying RMF guidance to Navy or DoD A&A efforts
  • Experience with test and evaluation of security controls, developing and executing Security Assessment Plans (SAP), assessing the residual risk of information systems, and developing the Security Assessment Report (SAR) executive summary
  • Experience with Enterprise Mission Assurance Support Service (eMASS), DoD Assured Compliance Assessment Solution (ACAS) suite of tools, STIG Viewer, and eMASSter
  • Knowledge of the NIST Special Publication 800-53 Rev. 4 cataloging Security and Privacy Controls for Federal Information Systems and Organizations, NIST Special Publication 800-30 Rev. 1 Guide for Conducting Risk Assessments, DoD published STIG requirements and implementation or compliance process, and Defense Information System Network (DISN) Connection Process Guide
  • TS/SCI clearance
  • Bachelor’s degree
  • Cybersecurity Workforce (CSWF) and Cyber IT certified under 8570.1 IAM I or II Certification
Responsibilities
  • Support a Naval client by providing Navy Risk Management Framework (RMF) cybersecurity support for the Domain
  • Analyze, document, and validate services for Department of Navy (DON) IT solutions, including applications, networks, systems, architectures, and infrastructure to Navy organizations
  • Provide Information Assurance support to organizations, while serving independently as a Navy Qualified Validator, performing validation activities under RMF using Navy Security Control Assessor (SCA)-approved processes
  • Apply knowledge of DoD or DON network architectures and policy towards the assessment and identification of vulnerabilities as a means of improving the operational security posture
  • Execute and conduct analysis of network and system Assured Compliance Assessment Solution (ACAS) vulnerability scans, Security Content Automation Protocol (SCAP) scans, and Security Technical Implementation Guide (STIG) checklists to validate the appropriate implementation of security controls in accordance with National Institute of Standards and Technology (NIST), DoD, and DON publications
  • Analyze and execute security assessment plans to ensure proper orchestration of testing procedures in accordance with requirements set forth by DoD and DON information security authorities
  • Provide guidance to Navy programs regarding vulnerability remediation and determination of risk posture
Desired Qualifications
  • Knowledge of Navy systems, networks, and IT infrastructure, including the Navy-Marine Corps Internet (NMCI), OCONUS Navy Enterprise Network (ONE-NET), IT-21 or Afloat networks, Joint systems, and Platform IT, including Navy Control Systems and weapons platforms
  • Knowledge of Physical and Environmental Security requirements of DoD Environments
  • Ability to work in a fast-paced environment with competing priorities
  • Possession of excellent written and verbal communication skills
  • Navy Qualified Validator (NQV) designation

Booz Allen Hamilton provides consulting services focused on strategy, technology, and engineering. The firm works with a variety of clients, including government agencies, corporations, and non-profits, primarily in the defense, intelligence, and civil sectors. Their services help clients tackle complex technical and strategic issues, utilizing their expertise in areas like cybersecurity, data analytics, and digital transformation. Booz Allen's business model includes long-term contracts and project-based work, allowing them to generate revenue while delivering tailored solutions. What sets Booz Allen apart from competitors is their deep industry knowledge combined with advanced technological capabilities, which enables them to effectively address modern challenges. The company's goal is to help clients optimize their operations and navigate threats while fostering an inclusive and collaborative work environment for their employees.

Company Size

N/A

Company Stage

IPO

Headquarters

McLean, Virginia

Founded

1914

Simplify Jobs

Simplify's Take

What believers are saying

  • Increased demand for AI-driven cybersecurity solutions boosts Booz Allen's market potential.
  • Rising adoption of cloud-native technologies enhances Booz Allen's consulting opportunities.
  • Expansion of 5G networks creates demand for Booz Allen's advanced network security solutions.

What critics are saying

  • Increased competition in cybersecurity as major players expand capabilities through acquisitions.
  • Potential over-reliance on government contracts may impact revenue stability.
  • Integration challenges from recent acquisitions could disrupt operations and delay synergies.

What makes Booz Allen unique

  • Booz Allen excels in cybersecurity, data analytics, and digital transformation services.
  • The firm has a strong presence in defense, intelligence, and civil sectors.
  • Booz Allen's inclusive work environment fosters innovation and collaboration.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Life Insurance

Disability Insurance

401(k) Retirement Plan

Paid Vacation

Professional Development Budget

Remote Work Options

Flexible Work Hours

Company News

Business Wire
Mar 13th, 2025
Booz Allen Hamilton Announces Pricing of Senior Notes Offering

Booz Allen Hamilton Holding Corporation (NYSE: BAH) (“Booz Allen”) announced that its wholly-owned subsidiary, Booz Allen Hamilton Inc. (the “Issuer”)

Stock Titan
Feb 5th, 2025
Major Cybersecurity Deal: Cisco Snaps Up Booz Allen's SnapAttack Platform

Cisco completes acquisition of SnapAttack, a cyber threat hunting platform originally developed by Booz Allen Hamilton, strengthening its cybersecurity detection portfolio.

PR Newswire
Feb 3rd, 2025
Hidden Level Expands Role In National Security With $100M Investment In Drone Detection Systems

As Evolving Drone Threats Continue to Intensify, Hidden Level Sees Strategic Growth as it Executes on a Number of U.S. Government ContractsSYRACUSE, N.Y., Feb. 3, 2025 /PRNewswire/ -- Hidden Level, a leader in passive radar and radio frequency sensing technology for detecting and precisely locating drones and other threats around you, today announced $65 million in Series C funding led by DFJ Growth with participation from Booz Allen Ventures, Revolution Capital, Costanoa Ventures, Washington Harbour Partners, Veteran Ventures, Founders Circle Capital, and others. This investment comes on the heels of the company's $35 million Series B which closed only 6 months prior, bringing the company's funding over the last 12 months to $100M, solidifying its position as a robust technology player in the rapidly evolving national security and critical infrastructure landscape.The rapid proliferation of unmanned aerial systems (UAS) has introduced significant challenges to national security and the protection of critical infrastructure for the U.S. and its allies. From espionage to the potential for hostile actions, drones represent a growing threat in both military and civilian environments

The Quantum Insider
Jan 14th, 2025
SEEQC Secures $30M for Quantum Computing

SEEQC has secured $30 million in funding, led by NordicNinja and Booz Allen Ventures, to advance its digital Single Flux Quantum (SFQ) chip platform. This technology integrates quantum and classical functions on a single processor, reducing costs by up to 97% and energy usage by 100,000 times. With partnerships including NVIDIA and NASA, SEEQC aims to scale quantum computing to enterprise-grade systems, focusing on applications in AI and materials science.

TechCrunch
Nov 13th, 2024
Exclusive: Starfish Space raises $29M to launch satellite-servicing spacecraft missions

Starfish Space has closed a new tranche of funding led by a major defense tech investor as it looks to launch three full-size satellite servicing and