RMF Analyst

Isys Technologies

Colorado Springs (CO)

On-site

USD 100,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

I2X Technologies is seeking an on-site RMF Analyst in Colorado Springs, CO to support a DoD customer. The role requires active TS/SCI clearance and hands-on RMF lifecycle management across enterprise systems.

Responsibilities include managing eMASS registrations, baselines, and evidence; driving continuous monitoring and ATO sustainment; developing SSPs, applying STIGs, and coordinating POA&Ms to closure with system owners and engineers.

Qualifications

  • Bachelor’s degree in information assurance, cybersecurity, or a related field plus 3–5 years of relevant experience; or a high school diploma or equivalent plus 7–10 years of relevant information assurance or cybersecurity experience.
  • At least 2 years of direct experience serving as an ISSO or cybersecurity practitioner supporting DoD systems.
  • Direct experience managing RMF lifecycle artifacts and end-to-end eMASS package management across multiple concurrent systems.

Responsibilities

  • Lead RMF process across enterprise systems and enclaves, maintaining registrations, baselines, and evidentiary records in eMASS.
  • Drive continuous monitoring and ATO sustainment with ISSO-level ownership.
  • Develop, validate, and maintain SSPs with STIGs applied.
  • Manage POA&Ms from identification to closure with stakeholders.

Skills

RMF process
eMASS
POA&Ms management
System Security Plans
Interpersonal collaboration

Education

Bachelor's degree in information assurance, cybersecurity, or related field
High school diploma or equivalent plus 7–10 years of relevant information assurance or cybersecurity experience

Tools

eMASS
STIG Viewer
ACAS/SCAP

Job description

Minimum Clearance Required

Top Secret SCI

Responsibilities

I2X Technologies is a reputable technology services company to the Federal Government. Whether the focus is on space exploration, national security, cyber security, or cutting-edge engineering applications, I2X is ready to offer you the chance to make a real-world impact in your field and for your country. We provide long-term growth and development. Headquartered in Colorado, I2X is engaged in programs across the country and in more than 20 states. Our programs support multiple Federal agencies, the Department of Defense and often focused on the space initiatives of our government customers.

I2X Technologies is seeking an RMF Analyst to support ongoing activities for a customer in Colorado Springs, CO. This position will be on-site and will require an active TS/SCI.

  • Supporting and executing the RMF process across multiple enterprise systems and enclaves by maintaining system registrations, security baselines, and evidentiary records within the Enterprise Mission Assurance Support Service (eMASS).
  • Operating with ISSO-level ownership to independently drive continuous monitoring and Authority to Operate (ATO) sustainment, ensuring an uninterrupted and robust security posture.
  • Ensuring cybersecurity standards and operational hygiene are consistently maintained to support a Cyber Operational Readiness Assessment (CORA)-ready posture.
  • Managing the continuous cybersecurity posture of enterprise systems and identifying mitigations necessary to meet Department of Defense Directive (DoDD) 8500.01, Department of Defense Instruction (DoDI) 8510.01, DoDD 8140.01, and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 requirements.
  • Analyzing and correlating scan results from the Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP), and other approved tools to evaluate system risk, determine security posture, and maintain ATO and Assess Only authorizations.
  • Assisting with system categorization in accordance with Committee on National Security Systems Instruction (CNSSI) 1253, including confidentiality, integrity, and availability impact levels, as information types, mission profiles, and system interconnections evolve.
  • Leading the development, maintenance, and technical validation of System Security Plans (SSPs), ensuring evidentiary artifacts accurately reflect current technical architectures and that applicable Security Technical Implementation Guides (STIGs) are implemented.
  • Exercising end-to-end ownership of Plans of Action and Milestones (POA&Ms) by systematically evaluating deficiencies, determining risk impacts, and coordinating with technical stakeholders to drive findings to timely closure.
  • Collaborating proactively with system administrators, network engineers, and leadership to remediate STIG findings, vulnerability scan results, and architectural deficiencies.
  • Providing strategic cybersecurity guidance, risk assessments, and status updates to system owners and leadership.
  • Providing weekly status reports that summarize accomplishments across assigned packages, risk posture, issues, and paths forward.
  • Creating, refining, and enforcing the operational policies, procedures, and artifacts necessary to ensure security controls are fully implemented and audit-ready.
Qualifications
  • Certification required in accordance with DoD Manual (DoDM) 8140.03 at the Intermediate level, such as CompTIA Security+ or an equivalent certification.
  • Bachelor’s degree in information assurance, cybersecurity, or a related field, plus 3–5 years of relevant experience; or a high school diploma or equivalent plus 7–10 years of relevant information assurance or cybersecurity experience.
  • At least 2 years of direct experience serving as an ISSO or cybersecurity practitioner supporting DoD systems, including:
  • Direct experience managing RMF lifecycle artifacts and end-to-end eMASS package management across multiple concurrent systems.
  • Proven experience authoring, tracking, and coordinating technical remediation to drive POA&Ms to validated completion.
  • Demonstrated ability to operate with a high degree of autonomy, self-direct work, and lead cross-functional technical teams through complex authorization lifecycles.

Desired Experience and Skills

  • Ability to work effectively in a team-focused, dynamic, high-tempo operational environment.
  • Experience using STIG Viewer and automated compliance tools.
  • Prior experience participating in Change Advisory Boards (CABs).

Essential Requirements:

  • US Citizenship is required
  • Active TS/SCI clearance is required

Additional Information:In compliance with Colorado’s Equal Pay for Equal Work Act, the annual base salary range for this position is listed. Please note that the salary information is a general guideline only. I2X Technologies considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer.

Physical Demands:

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job with or without reasonable accommodation.

While performing the duties of this job, the employee will regularly sit, walk, stand and climb stairs and steps. May require walking long distance from parking to work station. Occasionally, movement that requires twisting at the neck and/or trunk more than the average person, squatting/ stooping/kneeling, reaching above the head, and forward motion will be required. The employee will continuously be required to repeat the same hand, arm, or finger motion many times. Manual and finger dexterity are essential to this position. Specific vision abilities required by this job include close, distance, depth perception and telling differences among colors. The employee must be able to communicate through speech with clients and public. Hearing requirements include conversation in both quiet and noisy environments. Lifting may require floor to waist, waist to shoulder, or shoulder to overhead movement of up to 20 pounds. This position demands tolerance for various levels of mental stress.

I2X Technologies does not discriminate, and the company provides equal employment opportunity for all employees and applicants without regard to race, religion, color, sex, gender, sexual orientation, national origin, citizenship status, age, marital status, pregnancy or parenthood, handicap or disability, genetics, veteran status or any other legally protected characteristic.

I2X Technologies adheres to all federal, state and local laws regarding equal employment opportunity and will not discriminate against you in violation of these laws. I2X Technologies reserves the right to apply CIRI Shareholder preference to qualified Shareholders in employment and advancement opportunities.

I2X Technologies participates in E-Verify. We will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS), with information from each new employee's Form I-9 to confirm work authorization.

Reasonable Accommodation:

I2X Technologies will provide reasonable accommodations, according to applicable state and federal laws, to all qualified individuals with physical or mental disabilities. In compliance with the ADA Amendments Act (ADAAA), if you have a disability and would like to request an accommodation in order to apply for a position with I2X Technologies, please email I2XHR@i2xisys.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

Isys Technologies • Odenton (MD)

On-site
USD 120,000 - 180,000
Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

Isys Technologies • Corridor North (MD)

On-site
USD 110,000 - 170,000
Information Security Systems Officer (ISSO)
Information Security Systems Officer (ISSO)

Isys Technologies • Boulder (CO)

On-site
USD 150,000 - 190,000
Senior Level Intelligence Analyst
Senior Level Intelligence Analyst

Isys Technologies • Omaha (NE)

On-site
USD 120,000 - 180,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Isys Technologies • Schriever Space Force Base (CO)

On-site
USD 90,000 - 130,000
Technical Support Program Engineer
Technical Support Program Engineer

Isys Technologies • Corridor North (MD)

On-site
USD 90,000 - 130,000
Systems Administrator
Systems Administrator

Isys Technologies • Orlando (FL)

On-site
USD 70,000 - 110,000
Technical Support Program Engineer
Technical Support Program Engineer

Isys Technologies • Odenton (MD)

On-site
USD 100,000 - 140,000
Senior Network Solutions Engineer
Senior Network Solutions Engineer

Isys Technologies • Fort Meade (MD)

On-site
USD 120,000 - 170,000
Joint Operations Center Communication Technician
Joint Operations Center Communication Technician

Socket.dev • Colorado Springs (CO)

On-site
USD 90,000 - 130,000
E-Verify
Equal opportunity employer