ISSO / RMF Cybersecurity Analyst

Posted 3hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

ISSO/RMF Cybersecurity Analyst guiding federal IT systems through RMF and ATO compliance. Managing security controls, vulnerabilities, continuous monitoring, and incident response for Xcelerate Solutions.

Responsibilities:

  • Lead system categorization, security control selection, implementation, assessment, and continuous monitoring across the RMF lifecycle
  • Develop, update, and maintain Security Authorization Packages, including SSPs, SARs, POA&Ms, and continuous monitoring plans
  • Use government systems of record such as eMASS to document and track compliance packages
  • Coordinate and conduct vulnerability scans using ACAS, Nessus, and SCAP Compliance Checker
  • Analyze scan results, coordinate vulnerability remediation with technical teams, and document exceptions or POA&Ms
  • Review DISA STIGs and SRGs to ensure secure system configurations
  • Monitor and assess security controls continuously
  • Assist with identifying, investigating, and reporting security incidents or anomalies
  • Ensure log management, system auditing, and boundary protections comply with federal guidelines
  • Advise technical development, systems engineering, and management teams on cybersecurity
  • Ensure software features, infrastructure changes, and system updates follow security-by-design principles
  • Support planning and execution of security control assessments conducted by external assessment teams

Requirements:

  • Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field; equivalent professional experience may be considered
  • Minimum of 5+ years of experience in cybersecurity, information assurance, or IT compliance
  • 3+ years of direct, hands-on experience guiding systems through the RMF process (Steps 1 through 7) to successful ATO determinations
  • Deep working knowledge of NIST SP 800-37, NIST SP 800-53, and CNSSI 1253
  • Direct experience using automated vulnerability assessment tools such as Nessus, ACAS, or SCC
  • Proven experience managing and navigating security control databases such as eMASS
  • Solid understanding of operating system security configurations for Windows and Linux
  • Solid understanding of network security architectures
  • Strong technical writing skills and ability to produce clear, structured compliance documentation
  • Excellent communication and interpersonal skills
  • Active DoD 8570.01-M / DoD 8140 IAM Level II certification or higher, or willingness to obtain
  • U.S. citizenship
  • Public Trust or favorably adjudicated Secret Clearance minimum to start
  • Ability to adhere to government cybersecurity policies, OPSEC rules, and secure system access regulations
  • Preferred: experience with FedRAMP, AWS GovCloud, Azure Government, secure software development, DevSecOps, Docker, Kubernetes, Section 508, defense contract execution, or secure federal program architectures

Benefits:

  • Growth and development opportunities
  • Great Place to Work certified company
  • Reasonable accommodation if needed because of an applicant's or an employee's disability