What are the responsibilities and job description for the RMF Cybersecurity Analyst position at Kana Systems?
WHO WE ARE
At Kana Systems we empower trusted, smart decisions with innovative technology solutions for customers in the realm of data analytics, business intelligence, and software development. Our products harness AI/ML features offering a no-code interface that empowers people to navigate, analyze, and leverage data - including sensitive data. A key area of our business is defense and national security solutions.
We are agile-powered, with a focus on user-centered design and lean product development. Our core values are Aloha Spirit, Grit, and Results-Driven. Aloha Spirit is helping others to flourish.
WHO WE'RE LOOKING FOR
Kana Systems is seeking a driven RMF Cybersecurity Analyst (1099 Contractor) to take ownership of our RMF (Risk Management Framework) process. In this role you will manage our eMASS (Enterprise Mission Assurance Support Service) packet, oversee ATO (Authority to Operate) controls, and collaborate closely with SCARs (Security Control Assessor Representatives) to manage software controls and build out a clear roadmap toward ATO Granted status.
The ideal candidate takes genuine pride in their work, holds themselves to a high standard, and is motivated to push both our company and our security posture forward. This position reports directly to our VP of Technology and collaborates closely with our VP of Product Engineering and the broader Solutions Team.
Are you...
- Detail-oriented with good time management habits?
- A helpful and empathetic problem solver?
- An expert communicator, collaborator, and relationship builder?
- Open to new experiences and a technology early adopter?
- A self-starter who has worked on something of your own, such as a startup, an open-source project, or something else? We love initiative!
HOW HYBRID IS THIS ROLE?
The majority of the work completed will be performed in a remote environment, however, there are a few key reasons that you might be expected to occasionally attend in-person interactions, such as:
- Customer specific meetings (e.g., stakeholder discussions, discovery interviews and/or observations, software development on classified networks).
- Company culture events (e.g., holiday parties, company anniversaries).
- In-house hackathons.
- Developer brainstorm and whiteboard sessions.
WHAT YOU WILL DO
- Live out Kana Systems' Core Values and culture with every interaction and task.
- Guide Kana Systems through all seven RMF steps: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor - with the end goal of achieving an ATO / ATO with Conditions efficiently and timely.
- Serve as our primary POC (Point of Contact) for RMF status in coordinating between ISSO (Information System Security Officer), ISSM (Information System Security Manager), AO (Authorizing Official), and system owners.
- Build out and maintain the system of record in eMASS, or equivalent GRC (Governance, Risk, and Compliance) tool.
- Upload and organize required artifacts: SSP (System Security Plan), SAR (Security Assessment Report), POA&M (Plan of Action and Milestones), contingency plan, configuration management plan, incident response plan, etc.
- Track package status and push it through each review stage toward authorization.
- Assess implementation status of each applicable NIST (National Institute of Standards and Technology) 800-53 control.
- Write / update control implementation narratives with supporting evidence.
- Identify control gaps and coordinate remediation timelines and milestones.
- Cross-walk NIST 800-53 controls to applicable frameworks DoD / DoW (Department of Defense / Department of War) agency overlays including, but not limited to:
- CNSSI (Committee on National Security Systems Instruction) 1253
- FedRAMP (Federal Risk and Authority Management Program)
- CMMC (Cybersecurity Maturity Model Certification)
- Build and maintain a RTM (Requirements Traceability Matrix) linking control to system features, policies, and technical configurations.
- Coordinate assessment scheduling, scope, and evidence requests.
- Walk assessors through system architecture, data flows, and control implementation.
- Track and respond to assessment findings, coordinating remediation with technical teams.
- Develop a project plan and timeline showing all remaining steps to authorization: control implementation --> assessment --> POA&M closure --> AO decision.
- Identify critical path items and dependencies (e.g., pending SCAR assessment, unresolved high-risk findings).
- Brief stakeholders regularly on ATO readiness status and risk posture.
COMPENSATION & BENEFITS
- $55 - $75 per hour, commensurate based on experience.
- Employment classification: 1099 Contractor, hourly
- Expected hours: 30 - 40 per week
QUALIFICATIONS
Required
- Must be a U.S. citizen.
- 3 years of experience in DoD / DoW cybersecurity and system accreditation standards including: RMF, NIST, CMMC, and FedRAMP.
- Strong working knowledge of NIST SP 800-37, 800-53, 800-53A, and 800-30 (risk assessment).
- Experience with eMASS (or similar GRC platforms).
- Strong documentation and project-tracking discipline.
- Familiarity with Continuous Monitoring (ConMon) requirements post-ATO.
- Experience with DoD / DoW cybersecurity and secure deployment environments.
- Certification in at least one or more: IAT (Information Assurance Technical) Level II for DoD / DoW.
- CompTIA Security CE (Computing Technology Industry Association Security plus Continuing Education).
- CompTIA CySA (Computing Technology Industry Association Security Analyst plus).
- CISSP (Certified Information Systems Security Professional).
- Strong understanding of modern and secure software development practices and architectures.
- Track record of delivering and maintaining secure software development practices and architectures.
- Track record of delivering and maintaining secure software in commercial and government sectors.
Preferred
- Location: Lincoln and Omaha, NE area.
- Bachelor's degree in Cybersecurity, Information Technology, or Computer Science.
- Certification (at least one or more of the following):
- CISM (Certified Information Security Manager).
- CISA (Certified Information System Auditor).
- GIAC (Global Information Assurance Certification) Security Essentials.
- Proven experience with DevSecOps, infrastructure as code, Kubernetes, containerization, cluster RBAC (Role Based Access Control), APIs, and CI/CD (Continuous Integration and Continuous Delivery/Deployment) security.
- Prior experience in a cybersecurity leadership role in a startup environment.
Nice-to-Haves
- Prior experience in military / DoD / DoW, IT, network administration, or systems administration.
- Active security clearance (Secret or TS/SCI) or eligibility to obtain one.
- Prior experience in defense or government.
- Prior experience with full-stack software engineering, AI/ML technologies and frameworks, and related industries.
We are an equal opportunity employer committed to diversity and inclusion in the workplace.
Salary : $55 - $75