ISSO / RMF Cybersecurity Analyst

Xcelerate-Solutions-5

United States

Remote

USD 110,000 - 150,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Xcelerate Solutions in the United States is seeking an experienced ISSO / RMF Cybersecurity Analyst to lead risk management activities and maintain robust security controls across federal systems.

The role requires hands-on RMF guidance, experience with vulnerability management using tools like Nessus/ACAS, and a strong ability to coordinate with system admins, developers, and authorizing officials. Remote work options are available in this GovCon environment.

Qualifications

  • Bachelor’s degree or equivalent professional experience in cybersecurity/IA/IT.
  • Minimum of 5+ years in cybersecurity, IA, or IT compliance.
  • 3+ years guiding RMF processes (Steps 1-7) to ATO determinations.
  • Deep knowledge of NIST SP 800-37/800-53 and CNSSI 1253.

Responsibilities

  • Lead system categorization, security control selection, implementation, assessment and continuous monitoring across RMF lifecycle.
  • Develop, update, and maintain SSPs, SARs, POA&Ms, and continuous monitoring plans.
  • Utilize eMASS to document and track compliance packages and ensure timely updates.

Skills

Strong communication
Technical writing
Team collaboration
Problem solving

Education

Bachelor’s degree in Cybersecurity/Information Assurance/Computer Science/IT

Tools

NIST SP 800-37
NIST SP 800-53
CNSSI 1253
Nessus
ACAS
eMASS
SCC

Job description

Information Technology CareersRemote , Remote,United States

This position requires a deep understanding of federal cybersecurity policies, NIST Special Publications (specifically NIST SP 800-37 and NIST SP 800-53), and hands-on experience managing security controls. The ISSO will collaborate closely with system administrators, software developers, and government authorizing officials to identify risks, implement mitigation strategies, and maintain robust system defenses. Come join our award-winning organization and work with some of the most talented and brightest minds in the GovCon industry.

Key Responsibilities

In accordance with established cybersecurity performance standards, the ISSO / RMF Cybersecurity Analyst will perform the following duties:

  • Lead the system categorization, security control selection, implementation, assessment, and continuous monitoring processes across the RMF lifecycle.
  • Develop, update, and maintain comprehensive Security Authorization Packages, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action and Milestones (POA&Ms), and continuous monitoring plans.
  • Utilise government systems of record (e.g., Enterprise Mission Assurance Support Service - eMASS) to document and track compliance packages.
2. Vulnerability Management & Assessment
  • Coordinate and conduct regular vulnerability scans using automated tools (e.g., ACAS, Nessus, SCAP Compliance Checker).
  • Analyze scan results, coordinate with technical teams to remediate vulnerabilities, and document necessary exceptions or POA&Ms.
  • Review Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) to ensure secure system configurations.
  • Monitor and assess security controls on an ongoing basis to ensure they remain effective over time in a dynamic operational environment.
  • Assist with the identification, investigation, and reporting of security incidents or anomalies in accordance with established reporting procedures.
  • Ensure log management, system auditing, and boundary protections are maintained in compliance with federal guidelines.
4. Technical Collaboration & Advisory
  • Act as the primary cybersecurity advisor to technical development, systems engineering, and management teams.
  • Ensure that new software features, infrastructure changes, and system updates are designed and implemented with security-by-design principles.
  • Support the planning and execution of security control assessments (SCAs) conducted by external assessment teams.
Required Qualifications
  • Education: Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field (equivalent professional experience may be considered).
  • Experience:
    • Minimum of 5+ years of experience in cybersecurity, information assurance, or IT compliance.
    • 3+ years of direct, hands‑on experience guiding systems through the RMF process (Steps 1 through 7) to successful ATO determinations.
  • Technical Skills:
    • Deep working knowledge of NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
    • Direct experience using automated vulnerability assessment tools (e.g., Nessus, ACAS, SCC).
    • Proven experience managing and navigating security control databases (such as eMASS).
    • Solid understanding of operating system security configurations (Windows, Linux) and network security architectures.
  • Soft Skills:
    • Strong technical writing skills with demonstrated ability to produce clear, structured compliance documentation.
    • Excellent communication and interpersonal skills, with the ability to bridge the gap between technical teams and authorizing officials.
Preferred Qualifications
  • Experience with cloud security compliance models (e.g., FedRAMP, AWS GovCloud, Azure Government).
  • Familiarity with secure software development principles, DevSecOps pipelines, and container security (e.g., Docker, Kubernetes).
  • Experience implementing Section 508 accessibility standards within cybersecurity practices.
  • Experience supporting defense contract execution or secure federal program architectures.
Certifications

To meet federal cybersecurity and technical baseline requirements, candidates must possess or be willing to obtain:

1. Cybersecurity Baseline Certification (Required)

Active DoD 8570.01-M / DoD 8140 Information Assurance Management (IAM) Level II certification (or higher). Acceptable certifications include:

  • Certified Authorization Professional (CAP / CGRC) (highly preferred)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Security Leadership (GSLC)
Security & Clearance Requirements

Due to the secure nature of the enterprise environment and associated federal mandates:

  • Minimum Clearance to Start: Public Trust or Favorably Adjudicated Secret Clearance
  • Compliance: Must strictly adhere to government cybersecurity policies, operations security (OPSEC) rules, and secure system access regulations.
About Xcelerate Solutions:

Founded in 2009 and headquartered in McLean, VA, Xcelerate Solutions (www.xceleratesolutions.com) is one of America's fastest-growing companies. Xcelerate’s culture is defined by our diversified workforce of dynamic and versatile professionals, supported with growth and development opportunities that contribute to individual and company growth. This strong commitment to our employees has been recognized by our inclusion on the Washington Business Journal’s “50 Best Places to Work” list as well as being a “Great Place to Work” certified company with a 4.6 star, and a 99% CEO approval Glassdoor rating. Come find out why Xcelerate Solutions is one of thetop DC Metroemployers!

Xcelerate Solutions is an Equal Employment Opportunity/Affirmative Action Employer.We evaluate qualified applicants without regard to race, color, national origin, religion, age, equal pay, disability, veteran status, sex, sexual orientation, gender identity, genetic information, or expression of another protected characteristic. As part of this commitment to the full inclusion of all qualified individuals, Xcelerate Solutions provides reasonable accommodation if needed because of an applicant's or an employee's disability.
Pay Transparency Notice:Xcelerate Solutionswill not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

RMF Engineer - Intermediate
RMF Engineer - Intermediate

VMD Corp • Seaside (CA)

On-site
USD 94,000 - 127,000
Cyber Security Engineer - TS/SCI
Cyber Security Engineer - TS/SCI

VMD Corp • Bethesda (MD)

Hybrid
USD 140,000 - 180,000
Hybrid schedule
Professional development opportunities
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Bamboo Solutions • Washington

Hybrid
USD 130,000 - 180,000
Profit sharing
15 days PTO and 10 holidays
401(k) with employer matching
+2
Lead Information System Security Officer (ISSO) / Technical Program Lead
Lead Information System Security Officer (ISSO) / Technical Program Lead

Xtreme Solutions Inc • Washington

On-site
USD 150,000 - 190,000
Lead Information System Security Officer (ISSO) / Technical Program Lead
Lead Information System Security Officer (ISSO) / Technical Program Lead

Xtreme Solutions Corporate • Washington

On-site
USD 150,000 - 190,000
Lead Information System Security Officer (ISSO) / Technical Program Lead
Lead Information System Security Officer (ISSO) / Technical Program Lead

Xtreme Solutions, Inc. • Washington, Northern (KY)

Hybrid
USD 170,000 - 210,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

MBL Technologies, Inc. • Virginia (IL), Northern (KY)

Hybrid
USD 120,000 - 160,000
Remote work
401K
PTO
+2
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

MBL Technologies • Virginia (MN)

Hybrid
USD 110,000 - 170,000
Remote work
401K match
PTO
+1
Information Systems Security Officer (Technical ISSO / RMF Assessor)
Information Systems Security Officer (Technical ISSO / RMF Assessor)

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Eligibility for bonus plan
Cleared On Site Mid-Level Information Systems Security Officers (ISSO) (5358)
Cleared On Site Mid-Level Information Systems Security Officers (ISSO) (5358)

SMX • United States

On-site
USD 105,000 - 177,000
Health insurance
Paid leave
Retirement