RMF Quality Gate Analyst
big impact tech bitBaltimore (MD)
About the role
RMF Quality Gate Analyst
Location: Washington, DC (Hybrid)
Company: Big Impact Tech (BIT)
Clearance Required: Active Secret; must be able to obtain a TSA clearance About Big Impact TechBig Impact Tech (BIT) is a Small Business providing IT and business management consulting to federal and commercial clients. We deliver mission-focused solutions in data, cloud, cybersecurity, and program management.
Position Overview:
This position requires an active Secret clearance and the ability to obtain a TSA clearance. The RMF Quality Gate Analyst confirms that each system is ready for assessment by reviewing RMF Steps 0–3 documentation and signing off as the Compliance Contractor Support Specialist. This position sets the readiness decision factors before an assessment begins. The minimum 4 years of experience reflects the need for detailed knowledge of RMF artifacts and the judgment to identify gaps before they delay an authorization.
Responsibilities:
- Performs quality gate checks and sign-off for RMF Steps 0–3 (Prepare, Categorize, Select, Implement).
- Reviews FIPS 199 categorizations, PTAs/PIAs, and SSI threshold analyses.
- Reviews Business Impact Analyses (BIAs) and System Security Plans (SSPs).
- Reviews Configuration Management Plans (CMPs), Incident Response Plans (IRPs), and Contingency Plans and Contingency Plan Tests (CP/CPT).
- Reviews e-Authentication assessments and designation letters.
- Documents readiness decision factors before a system moves to assessment.
- Other duties as assigned.
Required Qualifications:
- BA/BS degree in Cybersecurity, Information Technology, or a related discipline.
- Minimum Experience Required:
- Minimum 4 years of experience in RMF, assessment and authorization (A&A), or federal IT compliance.
- Demonstrated knowledge of RMF Steps 0–3 and their required artifacts.
- Demonstrated experience reviewing FIPS 199, privacy (PTA/PIA), and contingency planning documentation.
- Demonstrated attention to detail in reviewing security documentation for gaps and inconsistencies. Additional Experience: Security+ or CGRC (formerly CAP) certification. CIPP/G certification for privacy reviews.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
