RMF Information System Security Officer

Inc. (osi)
San Antonio, TX, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

CompTIA Security+ Cyber Security Identity and Access Management Information Security Management Open Systems Interconnection (OSI) Public Key Infrastructure Security Content Automation Protocol Software Vulnerability Management Information Technology

Job description

Osi Vision is seeking an experienced ISSO to support the Air Force Public Key Infrastructure (PKI) System Program Office. You will own the RMF lifecycle for PKI and Air Force Identity and Access Management (IdAM) systems, maintaining accreditation packages, conducting compliance scans, and working directly alongside a government counterpart to keep systems authorized and secure., * Own and manage RMF packages in eMASS to achieve and maintain Authority to Operate (ATO) and Approval to Connect (ATC)

  • Conduct compliance scans using ACAS, SCAP, and AF-approved tools; document and track findings in the POA&M
  • Apply and validate STIGs across system components; coordinate SCA-V assessments
  • Develop and maintain System Security Plans, Incident Response plans, and supporting artifacts
  • Assist the FSO with implementation and management of the facility Security Program per NISPOM (32 CFR Part 117) and DAAPM
  • Identify and document local threats and vulnerabilities; report indicators into the Insider Threat process
  • Brief stakeholders on security posture, schedule updates, and compliance status
  • Conduct periodic self-inspections and ensure corrective action on all findings

Requirements

Do you have experience in Vuls?, Do you have a Bachelor’s degree?, This is a hands-on technical role. You need to be able to work independently in eMASS and run ACAS scans from day one., * Active Secret clearance

  • DoD 8570.01-M IAT Level II certification (Security+, CISSP, CCNA Security, GSEC, or equivalent)
  • Hands-on eMASS experience, managing controls and accreditation records independently
  • Hands-on ACAS and HBSS experience
  • Familiarity with RMF policy: DoDD 8500.1, DoDI 8500.2, DoDI 8510.01, NIST SP 800-53
  • Experience with Industrial Security programs and NISPOM compliance
  • Bachelor’s degree in Computer Science, Cybersecurity, or related field (or equivalent experience)

Preferred

  • Experience supporting PKI or IdAM systems
  • Vulnerability management program experience including policy development and metrics tracking

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:59 min

Why existing security and device management tools fail

Marcus Wermuth Marcus Wermuth · WWC Europe 2026

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · WWC Europe 2026

Videos

See all

Related articles

See all