Cyber Security Analyst - RMF (ISSO)

Trace Systems Inc.

Goldsboro (NC)

On-site

USD 110,000 - 170,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Trace Systems Inc. is seeking a Cyber Security Analyst RMF - ISSO to support DoD networks around Fort Bragg, including enterprise, tactical, and transport infrastructures. The role covers RMF activities, ATO evidence, and continuous monitoring across both classified and unclassified environments.

It requires shift work and collaboration with engineers and government stakeholders. The ideal candidate has RMF and RMF artifact experience, strong communication skills, and a willingness to travel for

Qualifications

  • Active DoD environment RMF experience.
  • Proven ability to develop and maintain System Security Plans (SSPs) and RMF artifacts (SARs, POA&Ms).
  • Experience with eMASS, ACAS, HBSS/ESS, SCAP or similar tools.

Responsibilities

  • Support RMF activities throughout the system lifecycle, including system categorization, control implementation, assessment, authorization, and continuous monitoring.
  • Coordinate with system administrators, network engineers, cybersecurity teams, and government stakeholders to ensure secure, compliant operations.
  • Prepare and deliver cybersecurity status reports, risk assessments, and executive briefings to leadership.

Skills

RMF expertise
ATO documentation
Cybersecurity reporting
Communication skills

Education

Bachelor's degree in Computer Science or related field
DoD/Military training
Security certifications (e.g., Security+, CEH, GCED)

Job description

Job Overview

Job Title: Cyber Security Analyst RMF - ISSO

Location: Pope Army Airfield, Fort Bragg, NC

This position is pending contract award.

Job Responsibilities

Trace Systems is seeking an experienced ISSO - RMF Analyst to support a global transport network supporting the US Special Operations Command and mission partners. This role supports critical communications infrastructure and will require shift work. The ISSO will provide ISSO and RMF support for enterprise, tactical, and transport network infrastructures supporting mission-critical operations.

  • Support 24/7/365 cybersecurity operations and compliance activities in support of mission-critical systems and global operations.
  • Monitor, assess, and maintain the cybersecurity posture of information systems across classified and unclassified environments.
  • Support RMF activities throughout the system lifecycle, including system categorization, control implementation, assessment, authorization, and continuous monitoring.
  • Work closely with system administrators, network engineers, cybersecurity teams, government stakeholders, and OEM partners to ensure systems remain secure, compliant, and operationally available.
  • Perform root-cause analysis of cybersecurity incidents, vulnerabilities, compliance deficiencies, and operational disruptions while documenting findings and corrective actions.
  • Develop, maintain, and update Authorization to Operate (ATO) packages, security documentation, System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, and related RMF artifacts.
  • Support implementation and validation of NIST 800-53 security controls, DISA STIGs, Security Technical Implementation Guides (STIGs), and other cybersecurity requirements.
  • Conduct vulnerability assessments, security reviews, compliance audits, and risk assessments to identify and remediate security weaknesses.
  • Prepare and deliver cybersecurity status reports, risk assessments, compliance summaries, outage summaries, and executive briefings to customer leadership.
  • Provide cybersecurity guidance and technical assistance to users operating from headquarters, regional hubs, remote sites, and forward-deployed locations.
  • Participate in system upgrades, technology refresh efforts, patch management activities, and configuration management processes to maintain secure system operations.
  • Maintain cybersecurity documentation, architecture diagrams, standard operating procedures, security baselines, and knowledge management repositories.
  • Coordinate activities with engineering teams, cybersecurity personnel, logistics support teams, and program management staff to ensure mission success.
  • Support Information Assurance (IA), Risk Management Framework (RMF), Continuous Monitoring (ConMon), vulnerability management, and cybersecurity compliance activities.
  • Utilize eMASS, ACAS, HBSS/ESS, SCAP, and other cybersecurity tools to track system compliance, vulnerabilities, and remediation efforts.
  • Assist with security architecture reviews, system accreditation activities, risk mitigation planning, and modernization initiatives supporting customer objectives.
  • Support incident response activities, forensic investigations, corrective action planning, and cybersecurity reporting requirements as required.
  • Support occasional travel requirements, site surveys, security inspections, compliance assessments, and field cybersecurity support activities as required.
Minimum Qualifications
  • Active, in-scope US Government issued Secret clearance.
  • Due to the nature of the work and contract requirements, US Citizenship is required.
  • Candidates must meet the qualification requirements of DoDM 8140.03 511/ Intermediate for an applicable Cybersecurity, Information Systems Security, Security Control Assessment, or RMF-related work role (Education, DoD Military/Training, Certification, or a combination thereof), as defined by the applicable contract. Qualification Pathways (One or More May Apply)
  • Education (OR)
    • Bachelor’s degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, Software Engineering, or related technical field OR equivalent combination of education and experience.
    • DoD/Military Training (OR)
    • Certification such as CompTIA Security+, CEH(P), GMON, GRID, Cloud+, FITSP-O, GCED, GDSA, GSEC, PenTest+, or other approved cybersecurity certifications.
  • Ability to travel worldwide, including to remote or austere locations. Individual trips may extend up to two months, with the possibility of multiple trips per year.
  • 6+ years executing RMF Steps 1-6 with eMASS (SSP, SCTM/controls, SAR, POA&M, Continuous Monitoring
  • 5+ years producing ATO-quality evidence: STIG/SRG checklists, ACAS/Tenable outputs, scan/patch tracking, artifact curation
  • Proven expertise in audits and metrics, with advanced knowledge of inheritance and boundary documentation, and extensive experience collaborating with ISSO/ISSE and engineering teams.
  • Demonstrated experience supporting Risk Management Framework (RMF) activities, cybersecurity compliance efforts, and system authorization processes within DoD environments.
  • Hands-on experience supporting cybersecurity compliance programs, Authorization to Operate (ATO) packages, security control implementation, and continuous monitoring activities.
  • Working knowledge of NIST 800-53 security controls, RMF lifecycle processes, STIG implementation, vulnerability management, POA&M development, eMASS, and cybersecurity compliance requirements.
  • Experience conducting security control assessments, log reviews, vulnerability analysis, compliance audits, risk assessments, and root-cause investigations to identify and remediate cybersecurity findings.
  • Strong verbal and written communication skills with the ability to communicate effectively with technical and non-technical personnel.
Desired Qualification
  • Experience supporting SOCOM, CENTCOM, AFRICOM, TRANSCOM, Space Force, or other Combatant Command environments.
  • Experience supporting OCONUS operations and remote-site sustainment activities.
  • Prior military service or experience supporting DOD customers.
Trace Systems

Trace Systems Inc. was founded to support and defend our nation's security interests at home and abroad-- whenever and wherever. We provide enterprise IT, engineering, full life-cycle communications, cybersecurity, cloud and virtualization services and solutions to the United States Department of Defense and other federal agencies.

Trace Systems is an equal opportunity employer. Qualified candidates will be considered without regard to legally protected characteristics.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst - RMF (ISSO)
Cyber Security Analyst - RMF (ISSO)

Trace Systems • Goldsboro (NC)

On-site
USD 110,000 - 160,000
Cyber Security Analyst - RMF
Cyber Security Analyst - RMF

Trace Systems Inc. • Tampa (FL)

On-site
USD 110,000 - 150,000
Cyber Security Analyst - RMF (ISSO)
Cyber Security Analyst - RMF (ISSO)

Trace Systems Inc. • Goldsboro (NC)

On-site
USD 85,000 - 130,000
Cyber Security Analyst
Cyber Security Analyst

Trace Systems Inc. • Goldsboro (NC)

On-site
USD 90,000 - 150,000
RMF/ISSO Cyber Security Analyst — 24/7 Ops
RMF/ISSO Cyber Security Analyst — 24/7 Ops

Trace Systems • Goldsboro (NC)

On-site
USD 110,000 - 160,000
Cyber Lead
Cyber Lead

Trace Systems • Tampa (FL)

On-site
USD 110,000 - 165,000
RMF Cybersecurity Analyst (ISSO)
RMF Cybersecurity Analyst (ISSO)

Trace Systems Inc. • Goldsboro (NC)

On-site
USD 85,000 - 130,000
Cyber Lead
Cyber Lead

Trace Systems Inc. • Tampa (FL)

On-site
USD 120,000 - 150,000
Systems Administrator Lead
Systems Administrator Lead

Trace Systems Inc. • Goldsboro (NC)

On-site
USD 90,000 - 140,000
RMF Cybersecurity Analyst | 24/7 Ops & ATO Support
RMF Cybersecurity Analyst | 24/7 Ops & ATO Support

Trace Systems Inc. • Goldsboro (NC)

On-site
USD 110,000 - 170,000