> Markdown version of [/jobs/ext/1364455-cyber-security-analyst-rmf-isso](https://www.wearedevelopers.com/jobs/ext/1364455-cyber-security-analyst-rmf-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst - RMF (ISSO) - **Company:** the Trace - **Location:** Clinton, MD, United States - **Experience:** Expert - **Salary:** $80,000.0 - **Contract:** Temporary to permanent - **Skills:** Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Knowledge Management, Comptia Pentest+ CE, Security Content Automation Protocol, Security Software, Software Engineering, Software Vulnerability Management, SARS Software Products, Information Technology, Patch Management, CIS Benchmarks, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 21, 2026 - **Apply:** https://www.jofdav.com/jobs/58928457-cyber-security-analyst-rmf-isso ## About the Role * Active, in-scope US Government issued Secret clearance. * Due to the nature of the work and contract requirements, US Citizenship is required. * Candidates must meet the qualification requirements of DoDM 8140.03 511/ Intermediate for an applicable Cybersecurity, Information Systems Security, Security Control Assessment, or RMF-related work role (Education, DoD Military/Training, Certification, or a combination thereof), as defined by the applicable contract. Qualification Pathways (One or More May Apply) * Education (OR) + Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, Software Engineering, or related technical field OR equivalent combination of education and experience. + DoD/Military Training (OR) + Certification such as CompTIA Security+, CEH(P), GMON, GRID, Cloud+, FITSP-O, GCED, GDSA, GSEC, PenTest+, or other approved cybersecurity certifications. * Ability to travel worldwide, including to remote or austere locations. Individual trips may extend up to two months, with the possibility of multiple trips per year. * 6+ years executing RMF Steps 1-6 with eMASS (SSP, SCTM/controls, SAR, POA&M, Continuous Monitoring * 5+ years producing ATO-quality evidence: STIG/SRG checklists, ACAS/Tenable outputs, scan/patch tracking, artifact curation * Proven expertise in audits and metrics, with advanced knowledge of inheritance and boundary documentation, and extensive experience collaborating with ISSO/ISSE and engineering teams. * Demonstrated experience supporting Risk Management Framework (RMF) activities, cybersecurity compliance efforts, and system authorization processes within DoD environments. * Hands-on experience supporting cybersecurity compliance programs, Authorization to Operate (ATO) packages, security control implementation, and continuous monitoring activities. * Working knowledge of NIST 800-53 security controls, RMF lifecycle processes, STIG implementation, vulnerability management, POA&M development, eMASS, and cybersecurity compliance requirements. * Experience conducting security control assessments, log reviews, vulnerability analysis, compliance audits, risk assessments, and root-cause investigations to identify and remediate cybersecurity findings. * Strong verbal and written communication skills with the ability to communicate effectively with technical and non-technical personnel. Desired Qualifications: * Experience supporting SOCOM, CENTCOM, AFRICOM, TRANSCOM, Space Force, or other Combatant Command environments. * Experience supporting OCONUS operations and remote-site sustainment activities. * Prior military service or experience supporting DOD customers. ## Description Trace Systems is seeking an experienced ISSO - RMF Analyst to support a global transport network supporting the US Special Operations Command and mission partners. This role supports critical communications infrastructure and will require shift work. The ISSO will provide ISSO and RMF support for enterprise, tactical, and transport network infrastructures supporting mission-critical operations. * Support 24/7/365 cybersecurity operations and compliance activities in support of mission-critical systems and global operations. * Monitor, assess, and maintain the cybersecurity posture of information systems across classified and unclassified environments. * Support RMF activities throughout the system lifecycle, including system categorization, control implementation, assessment, authorization, and continuous monitoring. * Work closely with system administrators, network engineers, cybersecurity teams, government stakeholders, and OEM partners to ensure systems remain secure, compliant, and operationally available. * Perform root-cause analysis of cybersecurity incidents, vulnerabilities, compliance deficiencies, and operational disruptions while documenting findings and corrective actions. * Develop, maintain, and update Authorization to Operate (ATO) packages, security documentation, System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, and related RMF artifacts. * Support implementation and validation of NIST 800-53 security controls, DISA STIGs, Security Technical Implementation Guides (STIGs), and other cybersecurity requirements. * Conduct vulnerability assessments, security reviews, compliance audits, and risk assessments to identify and remediate security weaknesses. * Prepare and deliver cybersecurity status reports, risk assessments, compliance summaries, outage summaries, and executive briefings to customer leadership. * Provide cybersecurity guidance and technical assistance to users operating from headquarters, regional hubs, remote sites, and forward-deployed locations. * Participate in system upgrades, technology refresh efforts, patch management activities, and configuration management processes to maintain secure system operations. * Maintain cybersecurity documentation, architecture diagrams, standard operating procedures, security baselines, and knowledge management repositories. * Coordinate activities with engineering teams, cybersecurity personnel, logistics support teams, and program management staff to ensure mission success. * Support Information Assurance (IA), Risk Management Framework (RMF), Continuous Monitoring (ConMon), vulnerability management, and cybersecurity compliance activities. * Utilize eMASS, ACAS, HBSS/ESS, SCAP, and other cybersecurity tools to track system compliance, vulnerabilities, and remediation efforts. * Assist with security architecture reviews, system accreditation activities, risk mitigation planning, and modernization initiatives supporting customer objectives. * Support incident response activities, forensic investigations, corrective action planning, and cybersecurity reporting requirements as required. * Support occasional travel requirements, site surveys, security inspections, compliance assessments, and field cybersecurity support activities as required. ## Related Videos - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)