Creative Global Consulting
Job Details: Role: Sr. Security RMF Audit Analyst POP: 12+ months Location: Remote SCOPE: As an US Citizen, the Sr. Security RMF Audit Analyst will lead audit preparation and execution, support continuous RMF lifecycle activities, and oversee compliance with federal cybersecurity requirements across on-premises, virtual, and cloud-hosted systems. REQUIRED SKILLS: Bachelor’s or Associate’s degree in Computer Science, Math, Information Technology, Engineering, or related field. Two (2) years of directly relevant experience may substitute for one (1) year of formal education. CompTIA Security+ required Minimum of five (5) years of experience in Information security with auditing and IT controls design experience. Minimum of five (5) years of experience with Security Information and Event Management (SIEM). Minimum of five (5) years of experience in the risk management framework. Hands-on experience with Active Directory, Windows/UNIX systems, and relational databases in secure environments. Advanced knowledge of NIST RMF, NIST SP 800-37, 800-53, DHS 4300A, and FISMA compliance. Experience preparing and maintaining RMF ATO documentation and conducting system assessments. Familiarity with Security Information and Event Management (SIEM) platforms for log analysis and incident monitoring. Proficient in evaluating and documenting security configurations and technical implementations for federal systems. Strong understanding of cybersecurity audit workflows, control testing, and risk-based prioritization of vulnerabilities. Excellent writing and communication skills, capable of producing technical documentation and executive summaries. Experience in Agile or DevSecOps environments, with a strong understanding of security integration within CI/CD pipelines.
