Information Security Analyst

Cybersecurity Jobs

Colorado Springs (CO)

On-site

USD 100,000 - 115,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

I2X Technologies is seeking an Information Security Analyst to support a Colorado Springs customer on-site. The role emphasizes RMF execution, continuous monitoring, and ATO sustainment, sustaining authorization artifacts for readiness.

The analyst will manage RMF across multiple systems using eMASS, maintain SSPs, and ensure STIG implementation. ATO readiness and CORA posture will be a core focus with DoD/NIST alignment.

Qualifications

  • DoD 8140.03 Intermediate level certification required (e.g., Security+ or equivalent).
  • 2+ years direct DoD RMF/ISSO experience with RMF artifacts and eMASS management.
  • Experience authoring and coordinating POA&Ms to closure; strong risk mindset.
  • Ability to lead cross-functional teams in complex authorization lifecycles.
  • Citizenship: US Citizenship; Clearance: TS/SCI required.

Responsibilities

  • Maintain RMF artifacts, registrations, baselines, and evidentiary records in eMASS.
  • Drive continuous monitoring and ATO sustainment with ISSO ownership.
  • Develop and validate System Security Plans (SSPs) reflecting current architectures.
  • Coordinate with admins and engineers to remediate STIG findings and scans.
  • Submit weekly status reports on risk posture, progress, and next steps.

Skills

RMF execution
eMASS
POA&M tracking
STIGs
Cross-functional leadership
Threat and vulnerability analysis
CAB participation
Independent ownership

Education

Bachelor's degree in information assurance or cybersecurity
3–5 years of relevant experience
HS diploma + 7–10 years information assurance experience

Tools

eMASS
ACAS
SCAP
STIG Viewer

Job description

I2X Technologies is seeking an Information Security Analyst to support a customer in Colorado Springs, Colorado on-site. This position focuses on Risk Management Framework (RMF) execution, continuous monitoring and Authority to Operate (ATO) sustainment, and maintaining authorization artifacts to support readiness.

Role Overview

The analyst will perform RMF-related activities across multiple enterprise systems and enclaves, using eMASS to manage system registrations, security baselines, and evidentiary records. The role also includes operating at an ISSO-level ownership model to sustain continuous monitoring and support a Cyber Operational Readiness Assessment (CORA)-ready posture.

Key Responsibilities
  • Support and execute the RMF process across multiple enterprise systems and enclaves by maintaining system registrations, security baselines, and evidentiary records within Enterprise Mission Assurance Support Service (eMASS).
  • Independently drive continuous monitoring and ATO sustainment with ISSO-level ownership to maintain a robust security posture.
  • Maintain cybersecurity standards and operational hygiene to support a Cyber Operational Readiness Assessment (CORA)-ready posture.
  • Support continuous posture management by identifying mitigations needed to meet DoDD 8500.01, DoDI 8510.01, DoDD 8140.01, and NIST SP 800-53 requirements.
  • Analyze and correlate scan results from ACAS, SCAP, and other approved tools to evaluate system risk, security posture, and maintain ATO and Assess Only authorizations.
  • Assist with system categorization in accordance with CNSSI 1253, including confidentiality, integrity, and availability impact levels, as information types, mission profiles, and system interconnections change.
  • Lead the development, maintenance, and technical validation of System Security Plans (SSPs), ensuring evidentiary artifacts reflect current technical architectures and applicable STIGs are implemented.
  • Exercise end-to-end ownership of Plans of Action and Milestones (POA&Ms) by evaluating deficiencies, determining risk impacts, and coordinating with technical stakeholders to achieve timely closure.
  • Coordinate with system administrators, network engineers, and leadership to remediate STIG findings, vulnerability scan results, and architectural deficiencies.
  • Provide strategic cybersecurity guidance, risk assessments, and status updates to system owners and leadership.
  • Submit weekly status reports summarizing accomplishments across assigned packages, risk posture, issues, and next steps.
  • Create, refine, and enforce operational policies, procedures, and artifacts to ensure security controls are implemented and audit-ready.
Required Qualifications
  • Certification (DoD 8140.03 Intermediate level): Certification required, such as CompTIA Security+ or equivalent.
  • Education and experience: Bachelor’s degree in information assurance, cybersecurity, or a related field plus 3–5 years of relevant experience; or high school diploma or equivalent plus 7–10 years of relevant information assurance or cybersecurity experience.
  • DoD systems experience: At least 2 years direct experience serving as an ISSO or cybersecurity practitioner supporting DoD systems, including direct experience managing RMF lifecycle artifacts and end-to-end eMASS package management across multiple concurrent systems.
  • Proven experience authoring, tracking, and coordinating technical remediation to drive POA&Ms to validated completion.
  • Demonstrated ability to operate with a high degree of autonomy and lead cross-functional technical teams through complex authorization lifecycles.
  • Ability to work effectively in a team-focused, dynamic, high-tempo operational environment.
  • Experience using STIG Viewer and automated compliance tools.
  • Prior experience participating in Change Advisory Boards (CABs).
  • Citizenship: US Citizenship required.
  • Clearance: Active TS/SCI clearance required.
Technologies
  • Enterprise Mission Assurance Support Service (eMASS)
  • Assured Compliance Assessment Solution (ACAS)
  • Security Content Automation Protocol (SCAP)
  • Security Technical Implementation Guides (STIGs)
  • STIG Viewer
Minimum Clearance
  • Top Secret SCI
Physical Demands
  • Regularly sit, walk, stand, and climb stairs and steps.
  • May require walking long distances from parking to the work station.
  • Occasionally requires twisting at the neck and/or trunk more than the average person, squatting/stooping/kneeling, reaching above the head, and forward motion.
  • Continuously requires repetition of the same hand, arm, or finger motion.
  • Manual and finger dexterity are essential.
  • Specific vision abilities required: close, distance, depth perception, and color differentiation.
  • Must communicate through speech with clients and public.
  • Hearing requirements include conversation in quiet and noisy environments.
  • Lifting may require floor to waist, waist to shoulder, or shoulder to overhead movement of up to 20 pounds.
  • Tolerance for various levels of mental stress is required.
Reasonable Accommodation
  • I2X Technologies will provide reasonable accommodations, according to applicable state and federal laws, to qualified individuals with physical or mental disabilities.
  • In compliance with the ADA Amendments Act (ADAAA), candidates who have a disability and would like to request an accommodation to apply should email I2XHR@i2xisys.com.
Additional Information
  • Colorado’s Equal Pay for Equal Work Act: annual base salary range is listed as USD 100,000 to 115,000.
  • I2X Technologies considers scope and responsibilities, candidate work experience, education/training, key skills, internal peer equity, and market/business considerations when extending an offer.
  • I2X Technologies participates in E-Verify: information from each new employee’s Form I-9 is provided to SSA and, if necessary, DHS to confirm work authorization.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Isys Technologies • Colorado Springs (CO)

On-site
USD 95,000 - 140,000
Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

Isys Technologies • Odenton (MD)

On-site
USD 120,000 - 180,000
Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

Isys Technologies • Corridor North (MD)

On-site
USD 110,000 - 170,000
Information Security Systems Officer (ISSO)
Information Security Systems Officer (ISSO)

Isys Technologies • Boulder (CO)

On-site
USD 150,000 - 190,000
Journeymen Analysts (Mid-Level)
Journeymen Analysts (Mid-Level)

Isys Technologies • Omaha (NE)

On-site
USD 90,000 - 150,000
Senior Level Intelligence Analyst
Senior Level Intelligence Analyst

Isys Technologies • Omaha (NE)

On-site
USD 120,000 - 180,000
Advanced Trainer
Advanced Trainer

Isys Technologies • United States

On-site
USD 110,000 - 140,000
DevSecOps Engineer
DevSecOps Engineer

Isys Technologies • Boulder (CO)

On-site
USD 140,000 - 190,000
Systems Administrator
Systems Administrator

Isys Technologies • Orlando (FL)

On-site
USD 70,000 - 110,000
Joint Operations Center Communication Technician
Joint Operations Center Communication Technician

Isys Technologies • Colorado Springs (CO)

On-site
USD 90,000 - 120,000