ISSO / RMF Cybersecurity Analyst
Posted 3hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
ISSO/RMF Cybersecurity Analyst guiding federal IT systems through RMF and ATO compliance. Managing security controls, vulnerabilities, continuous monitoring, and incident response for Xcelerate Solutions.
Responsibilities:
- Lead system categorization, security control selection, implementation, assessment, and continuous monitoring across the RMF lifecycle
- Develop, update, and maintain Security Authorization Packages, including SSPs, SARs, POA&Ms, and continuous monitoring plans
- Use government systems of record such as eMASS to document and track compliance packages
- Coordinate and conduct vulnerability scans using ACAS, Nessus, and SCAP Compliance Checker
- Analyze scan results, coordinate vulnerability remediation with technical teams, and document exceptions or POA&Ms
- Review DISA STIGs and SRGs to ensure secure system configurations
- Monitor and assess security controls continuously
- Assist with identifying, investigating, and reporting security incidents or anomalies
- Ensure log management, system auditing, and boundary protections comply with federal guidelines
- Advise technical development, systems engineering, and management teams on cybersecurity
- Ensure software features, infrastructure changes, and system updates follow security-by-design principles
- Support planning and execution of security control assessments conducted by external assessment teams
Requirements:
- Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field; equivalent professional experience may be considered
- Minimum of 5+ years of experience in cybersecurity, information assurance, or IT compliance
- 3+ years of direct, hands-on experience guiding systems through the RMF process (Steps 1 through 7) to successful ATO determinations
- Deep working knowledge of NIST SP 800-37, NIST SP 800-53, and CNSSI 1253
- Direct experience using automated vulnerability assessment tools such as Nessus, ACAS, or SCC
- Proven experience managing and navigating security control databases such as eMASS
- Solid understanding of operating system security configurations for Windows and Linux
- Solid understanding of network security architectures
- Strong technical writing skills and ability to produce clear, structured compliance documentation
- Excellent communication and interpersonal skills
- Active DoD 8570.01-M / DoD 8140 IAM Level II certification or higher, or willingness to obtain
- U.S. citizenship
- Public Trust or favorably adjudicated Secret Clearance minimum to start
- Ability to adhere to government cybersecurity policies, OPSEC rules, and secure system access regulations
- Preferred: experience with FedRAMP, AWS GovCloud, Azure Government, secure software development, DevSecOps, Docker, Kubernetes, Section 508, defense contract execution, or secure federal program architectures
Benefits:
- Growth and development opportunities
- Great Place to Work certified company
- Reasonable accommodation if needed because of an applicant's or an employee's disability



















