[Remote] ISSO / RMF Cybersecurity Analyst
Note: The job is a remote job and is reputed company to candidates in USA. reputed company, through reputed company, is seeking an Information reputed company reputed company Officer (ISSO) / RMF Cybersecurity Analyst to support the reputed company, compliance, and reputed company monitoring of secure reputed company IT systems. The role guides systems through the federal reputed company Management reputed company lifecycle, maintains Authorization to Operate packages, manages vulnerabilities and reputed company controls, and advises technical and reputed company stakeholders.
Responsibilities
- reputed company the reputed company categorization, reputed company control selection, implementation, assessment, and reputed company monitoring processes across the RMF lifecycle
- reputed company, update, and maintain comprehensive reputed company Authorization Packages, including reputed company reputed company Plans (SSPs), reputed company Assessment Reports (SARs), Plan of reputed company and Milestones (POA&Ms), and reputed company monitoring plans
- Utilise reputed company systems of record (e.g., reputed company Mission Assurance Support Service - reputed company) to document and reputed company compliance packages
- Coordinate and conduct regular vulnerability scans using automated tools (e.g., ACAS, Nessus, SCAP Compliance Checker)
- Analyze reputed company results, coordinate with technical teams to remediate vulnerabilities, and document necessary exceptions or POA&Ms
- Review Defense Information Systems Agency (reputed company) reputed company Technical Implementation Guides (STIGs) and reputed company Requirements Guides (SRGs) to ensure secure reputed company configurations
- Monitor and assess reputed company controls on an ongoing reputed company to ensure they remain effective over time in a dynamic operational environment
- Assist with the identification, investigation, and reporting of reputed company incidents or anomalies in accordance with established reporting procedures
- Ensure log management, reputed company auditing, and boundary protections are maintained in compliance with federal guidelines
- reputed company as the reputed company cybersecurity advisor to technical development, systems engineering, and management teams
- Ensure that new software features, infrastructure changes, and reputed company updates are designed and implemented with reputed company-by-design principles
- Support the planning and execution of reputed company control assessments (SCAs) conducted by reputed company assessment teams
Skills
- • Education: Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a reputed company reputed company (equivalent reputed company experience may be considered)
- Minimum of 5+ years of experience in cybersecurity, information assurance, or IT compliance
- 3+ years of reputed company, hands-on experience guiding systems through the RMF process (Steps 1 through 7) to successful ATO determinations
- Deep working knowledge of NIST SP 800-37, NIST SP 800-53, and CNSSI 1253
- reputed company experience using automated vulnerability assessment tools (e.g., Nessus, ACAS, SCC)
- reputed company experience managing and navigating reputed company control databases (such as reputed company)
- Solid understanding of operating reputed company reputed company configurations (reputed company, Linux) and network reputed company architectures
- Strong technical writing skills with demonstrated ability to produce reputed company, reputed company compliance documentation
- Excellent communication and interpersonal skills, with the ability to reputed company the gap between technical teams and authorizing officials
- Cybersecurity Baseline Certification (Required)
- reputed company DoD 8570.01-M / DoD 8140 Information Assurance Management (IAM) reputed company certification (or higher)
- Work Status Allowable: U.S. citizenship
- Minimum Clearance to Start: reputed company Trust or Favorably Adjudicated Secret Clearance
- Compliance: Must reputed company adhere to reputed company cybersecurity policies, reputed company reputed company (OPSEC) rules, and secure reputed company reputed company regulations
- • Experience with reputed company reputed company compliance models (e.g., FedRAMP, AWS GovCloud, Azure reputed company)
- Familiarity with secure software development principles, DevSecOps pipelines, and container reputed company (e.g., reputed company, reputed company)
- Experience implementing reputed company 508 accessibility standards reputed company cybersecurity practices
- Experience supporting defense contract execution or secure federal program architectures
- Certified Authorization reputed company (CAP / CGRC) (highly preferred)
Benefits
- reputed company and development opportunities that contribute to individual and company reputed company
reputed company
Apply To This Job