Decision Point Security, Inc Cybersecurity Compliance Analyst Remote·Full time Company website
We are looking for a driven, mid-level professional who brings a strong technical background to our dynamic team. This role bridges the gap between technical engineering and Risk Management Framework (RMF) compliance by conducting in-depth NIST 800-53 control reviews and SRG/STIG assessments on Department of War (DoW) cloud architectures. Unlike traditional compliance roles, this position is deeply integrated into the technical lifecycle. You will participate directly in engineering working groups, providing actionable recommendations to systems and software engineers to ensure our deployments are secure by design. If you possess strong written and oral communication skills, in-depth technical aptitude, and the ability to solve complex challenges in a fast-paced environment, we want you on our team!
About Decision Point Security, Inc
Decision Point team has over 150 years combined experience delivering solutions based on sound research principals and critical thinking. Members of the team have been trusted with hardening and assessment of some of our nation’s critical defense infrastructure and weapon systems.We understand that achieving and maintaining adequate security requires thorough understanding of people, processes, and systems.Challenges associated with each of these areas are dynamic and can be costly. Let our team work with you to deliver practical, cost effective solutions.
Description
Responsibilities
- Aid the Security Control Assessor (SCA) in the RMF process by performing Security Assessments, writing Security Assessment Reports (SAR), drafting authorization memorandums, reviewing Security Relevant Change (SRC) requests, and conducting determination briefs.
- Manage RMF documentation within eMASS, validating artifacts, coordinating plans, and maintaining compliance across all RMF control families.
- Conduct comprehensive security control assessments (SCA) on complex defense cloud environments in accordance with NIST SP 800-37 and NIST SP 800-53.
- Ensure compliance with DISA STIGs/SRGs, FISMA requirements, and the DoD Cloud Computing SRG across system lifecycles.
- Execute and review vulnerability scans utilizing tools such as ACAS/Tenable Security Center and SCAP Compliance Checker (SCC).
- Review system architectures, network diagrams, and data flows to identify vulnerabilities and translate compliance requirements into actionable technical safeguards for engineering teams.
- Perform continuous monitoring tasks required to maintain accurate system records and ensure ongoing authorization.
Required Qualifications
- 3-5+ years of experience in cybersecurity, information assurance, or RMF compliance within the Department of Defense (DoD) / Department of War (DoW) or Defense Industrial Base (DIB).
- DoDD 8570/8140 IAM or IAT Level II/III professional certification (e.g., Security+, CISSP, SecurityX).
- Deep, hands-on experience utilizing eMASS for RMF artifact management, POA&M tracking, ATO package development, reviewing control compliance, or reviewing POA&M updates.
- Strong proficiency with NIST SP 800-53, DISA STIGs, and vulnerability assessment tools (ACAS/Nessus, SCAP).
- Experience assessing cloud architectures (AWS, Azure, GCP, etc) and understanding the DoD Cloud Computing SRG.
- Exceptional ability to articulate complex security risks and deliver practical recommendations to both technical engineers and non-technical leadership.
- Active DoD Secret (or higher) security clearance.
Preferred Qualifications
- Previous experience as an Information Systems Security Officer (ISSO), Security Control Assessor (SCA), or RMF Information System Security Manager (ISSM).
- Familiarity with container orchestration (Kubernetes/docker) and securing CI/CD pipelines.
- Understanding of security engineering principles applied to Artificial Intelligence (AI) threat modeling and data pipeline security.
- Experience supporting secure system development by reviewing A&A artifacts such as Ports, Protocols, and Services (PPS) and Hardware/Software inventories.
- Generous 401(k) contribution, matching not required
- Company Paid Health Insurance
- Company Paid Dental insurance
- Company Paid Vision Insurance
- Company Paid Life Insurance
- Paid Training
- Home Office Stipend
- Paid Time Off
Location
- Remote within the United States with 10-20% travel