Stand out for this role — generate a tailored resume and cover letter in about a minute.
ISSE Services is seeking a Security Analyst II to implement and manage RMF controls for assigned information systems, coordinating with the ISSM to ensure compliance with NIST RMF SP 800-37 and SP 800-53. The role includes maintaining RMF documentation and monitoring vulnerabilities.
You will support ATO activities, coordinate with admins and security teams, and advise leadership on risk mitigation while ensuring operational security across the environment.
Description
Annual pay range $75,000 to $85,000 (Non-Exempt, Hourly)
WE ARE A CONTRACTED FEDERAL DRUG-FREE WORKPLACE
All shifts available in 24/7 Operations Center
(Day, Swing, Grave)
ISSE Services is a cybersecurity and mission assurance company supporting defense, aerospace, and regulated industry customers. We specialize in Governance, Risk, and Compliance (GRC), cybersecurity engineering, managed security services, and CMMC readiness for organizations handling Controlled Unclassified Information (CUI).
Our mission is to help customers securely enable and accelerate their operations through practical compliance, technical expertise, and mission-focused security solutions.
ISSE Services has vast experience maintaining the ATO and coordinating the Prime to ensure continued compliance with the RMF controls. The ATO control baseline (r5 and the SAF/CN control set) has recently been increased to a larger workload with more controls being required than in previous ATO cycles.
The Security Analyst II supports theInformation System Security Manager (ISSM)by implementing and managing security controls in accordance withNIST RMF (SP 800-37)and applicable control baselines (e.g.,NIST SP 800-53). The Security Analyst II ensures that system security requirements are met during system development, operation, and maintenance, and that risks are identified, documented, and mitigated.
The Security Analyst II is responsible forassisting the ISSM inmaintaining RMF documentation such as theSystem Security Plan (SSP),Security Assessment Plan (SAP),Security Assessment Report (SAR),Plan of Action and Milestones (POA&M), and continuous monitoring artifacts. They track vulnerabilities, ensure timely remediation, and coordinate with system administrators, engineers, and security teams to implement technical, administrative, and operational controls.
Requirements
The ideal candidate must have CompTIA Security+ at least one of the following certifications: GMON, SecurityX / CASP+, CCISO, CCSP, CGRC/CAP, CISSO, Cloud+, GCSA, GSEC, SSCP
Nice to have but not required: CISM, CISSP, CISSP-ISSMP, FITSP-M, GCIA, GCIH, GICSP, GSLC
Summary
We are an equal opportunity employer and celebrate diversity. All qualified applicants will receive consideration without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, disability, or veteran status.