RMF Information System Security Officer (ISSO)

Colsa-5

Albany (GA)

On-site

USD 110,000 - 150,000

Full time

22 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

COLSA is seeking an experienced RMF ISSO to support DoD RMF activities, develop A&A packages, and guide system owners through RMF steps. The role requires collaboration with ISSMs, validators, and stakeholders to maintain security posture.

The position emphasizes developing SSPs, SARs, and POA&Ms, conducting initial assessments, and managing vulnerabilities. On-site Albany, GA, full-time with secret clearance expectations.

Qualifications

  • Eight+ years of related DoD RMF/A&A experience.
  • Experience developing and maintaining RMF packages (SSPs, SARs, POA&Ms).
  • Experience with security control implementation, vulnerability management, and STIGs.
  • Clear and effective communication of technical findings.
  • Active Secret clearance; US citizenship required.

Responsibilities

  • Complete RMF authorization and assessment packages within 120 days of ATO expiration.
  • Guide information owners through RMF steps 0–2 and select security controls.
  • Develop SSPs, SARs, and POA&Ms with stakeholders and validators.
  • Lead initial control assessments and document findings in SAR.
  • Create and maintain POA&Ms, updating monthly with new scans and STIGs.
  • Monitor networks to detect security incidents and deviations from policy.
  • Perform audits and evaluations to ensure policy compliance.

Skills

RMF process knowledge
SSP development
Security assessment reports
POA&M management
Vulnerability management
Clearance communication

Education

Bachelor’s Degree in Cybersecurity/IT or related field

Tools

Compliance and Authorization Support Tool

Job description

RMF Information System Security Officer (ISSO)
Tracking Code

9753-987

Posted Date

8/31/2026

Job Location

Albany, Georgia

Location of Position

Albany, Georgia

Work Arrangement

On Site: 100%

Position Type

Full-Time/Regular

Clearance Required?

Yes

Level of Clearance Required

Secret

COLSA is seeking an experienced RMF Information System Security Officer (ISSO) to join our team and play a critical role in supporting cybersecurity and Risk Management Framework (RMF) activities. This position will provide expertise throughout the RMF authorization process, including developing and maintaining RMF Assessment and Authorization (A&A) packages, guiding information owners through RMF requirements, supporting security control assessments, and managing vulnerability and remediation activities. The RMF ISSO will work closely with ISSMs, Government RMF ISSOs, information owners, validators, and other stakeholders to support system authorization and maintain the security posture of assigned information systems.

This position is contingent upon contract award, with work anticipated to begin in March 2027. The selected candidate will be proposed as Key Personnel in accordance with proposal requirements.
  • Completes authorization and assessment packages within 120 days of system ATO expiration.
  • Ensures stakeholders are kept informed of risk, status, and roles and responsibilities throughout the RMF process
  • Guides information owners through completion of Step 0 System Registration in Compliance and Authorization Support Tool
  • Guides information owners through Step 1, System Categorization, based on information provided by the information owner
  • Guides information owners through Step 2, select security controls, and determining appropriate defense level and appropriate overlays
  • Provides information owner with an export of selected security controls and applied overlays to populate the Implementation Details
  • Reviews completed security control implementation details and gain validator approval
  • Guides information owners in the development of a System Security Plan (SSP) that addresses objectives for the assessment, methods for verifying security control compliance, the schedule for the initial control assessment, and actual assessment procedures
  • Works with ISSM and lead Government RMF ISSO to conduct the initial assessment of the effectiveness of the security controls and document the issues, findings, and recommendations in a Security Assessment Report (SAR)
  • Develops a project plan and Plan of Action and Milestones (POA&M) for the RMF package that addresses all un-remediated vulnerabilities, failed Security Technical Implementation Guideline (STIG) failures and failed security controls
  • Works the POA&M, to include updating the POA&M at least monthly for the life cycle of the IS using the latest vulnerability scans and STIG checklists
  • Monitors the network and supporting systems to detect security compromise events (including intrusions and virus incidents).
  • Identifies where systems/networks deviate from acceptable configurations, enclave policy, or local policy.
  • Conducts audits to ensure information systems security policies and procedures are implemented as defined in security plans and best practices.
  • Performs evaluations (compliance audits) and/or active evaluations (vulnerability assessments).
  • Leads response teams to ensure any anomalies are corrected in accordance with government or industry standards.

At COLSA, people are our most valuable resource and centered at our core value. We invite you to unite your talents with opportunity and be a part of our "Family of Professionals!" Learn about our employee-centric culture and benefits here: https://www.colsa.com/culture_benefits

Required Experience
  • Bachelor’s Degree (or higher) in Cybersecurity, Information Technology, or a relatedfield or equivalent experience
  • Minimum of eight (8) years of related work experience, including experience supporting DoD Risk Management Framework (RMF) and Assessment and Authorization (A&A) activities
  • Experience developing and maintaining RMF authorization packages, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms)
  • Experience with security control implementation and assessment, vulnerability management, and Security Technical Implementation Guides (STIGs)
  • Ability to clearly present and communicate technical approaches and findings
  • Active Secret security clearance; US Citizenship required;
Preferred Qualifications
  • DoD 8570/8140-compliant certification such as Security+, CGRC (formerly CAP), or equivalent

Applicant selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information.COLSA Corporation is an Equal Opportunity Employer, Minorities/Females/Veterans/Disabled. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.

Salary Type

Annually

The salary range, if referenced, represents a good faith estimate. COLSA considers various factors when determining base salary offers, but not limited to, location, the role, function and associated responsibilities, a candidate's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements.

COLSA offers a comprehensive and customizeable benefits program which includes Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, Accidental Death & Dismemberment, Supplemental Income Protection Programs, 401(k) with company match, Flexible Spending Accounts, Employee Assistance Program, Education & Certification Reimbursement, Employee Discount Program, Paid Time Off and Holidays.

This position will be posted for a minimum of 3 business days. If a candidate has not been selected at that time, it will continue to be posted until a suitable candidate is selected or the position is closed.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

RMF Information System Security Officer (ISSO)
RMF Information System Security Officer (ISSO)

COLSA • Albany (GA)

On-site
USD 120,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+1
Cybersecurity Analyst IAM I (Basic)
Cybersecurity Analyst IAM I (Basic)

COLSA • Dahlgren (VA)

On-site
USD 100,000 - 110,000
Medical, Dental, Vision
401(k) with company match
Paid Time Off
Information Security Analyst (Advanced)
Information Security Analyst (Advanced)

Colsa • Northern (KY)

Hybrid
USD 130,000 - 170,000
Medical benefits
Dental benefits
Vision benefits
+5
Information Security Analyst (Advanced)
Information Security Analyst (Advanced)

Colsa-5 • Naval Air Station Patuxent River (MD)

On-site
USD 130,000 - 170,000
Medical, Dental, Vision
401(k) with company match
Education & Certification Reimburse
+1
Information Systems Security Officer (Technical ISSO / RMF Assessor)
Information Systems Security Officer (Technical ISSO / RMF Assessor)

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Eligibility for bonus plan
Information System Security Officer (ISSO) – Senior
Information System Security Officer (ISSO) – Senior

ASRC Federal • Aberdeen (MD), Northern (KY)

Hybrid
USD 110,000 - 165,000
Health care
401(k)
Paid time off
+1
Senior Information Security Engineer
Senior Information Security Engineer

ASRC Federal • Reston (VA), Northern (KY)

Hybrid
USD 110,000 - 160,000
ME00673-Senior Information System Security Officer (ISSO)
ME00673-Senior Information System Security Officer (ISSO)

Momentum Engineering, Inc • Washington, Northern (KY)

Hybrid
USD 120,000 - 165,000
Paid holidays
3 weeks PTO
Group medical plan
+4
ME00673-Senior Information System Security Officer (ISSO)
ME00673-Senior Information System Security Officer (ISSO)

Momentum Engineering, Inc. • Washington

On-site
USD 120,000 - 180,000
11 paid holidays
3 weeks PTO
Company medical plan
+4
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc. • Washington

On-site
USD 120,000 - 180,000
Paid holidays
3 weeks PTO
Group medical plan
+4