> Markdown version of [/jobs/ext/1855445-rmf-cybersecurity-isso-sme-3](https://www.wearedevelopers.com/jobs/ext/1855445-rmf-cybersecurity-isso-sme-3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF Cybersecurity ISSO/SME 3 - **Company:** KBR Inc - **Location:** Houston, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $107,600.0 - $161,400.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Cyber Security, Information Systems, Information Security Management, Microsoft Office, Microsoft Project, Package Development Process, Microsoft PowerPoint, Microsoft SharePoint, Information Technology, Scap Compliance Checker - **Published:** July 19, 2026 - **Apply:** https://www.juju.com/job/00000000ghpw3b ## About the Role + U.S. Citizen. Active DoD Secret security clearance + Bachelor's degree in cybersecurity, information technology, or related field with 6+ years of experience; or 14+ years of relevant cybersecurity/IT experience in lieu of degree. + DoD Manual 8140.03 (formerly 8570.01)-compliant certification (e.g., Security+, CISSP, CASP+/SecurityX) + Demonstrated experience performing RMF activities as an ISSO/ISSM/SME, including ATO process support and RMF package development (Security Plans, POA&Ms, architecture diagrams, system security policies, etc.) + Demonstrated experience assessing and documenting NIST SP 800-53 controls + Experience using Microsoft Office applications: Word, PowerPoint, Excel, and SharePoint Preferred Qualifications: + Experience using eMASS or equivalent compliance-tracking application + Experience supporting RMF processes under DHA + Familiarity with ACAS and DISA STIGs/SRGs and tools such as STIG Viewer and SCAP Compliance Checker + Familiarity with Continuous Monitoring and Risk Scoring (CMRS) + Experience using Microsoft Project to build Integrated Master Schedules (IMS) Compensation: $107,600.00 - $161,400.00. The salary range posted is based on the national average. The offered rate will be based on the contract affordability and the selected candidate's location, knowledge, skills, abilities, and/or experience, and in consideration of internal parity. ## Description KBR is seeking a Cybersecurity Risk Management Framework (RMF) Information System Security Officer (ISSO) to support the DHA Solution Delivery Division (SDD). In this role, you will lead Assessment & Authorization (A&A) activities and guide systems through the RMF lifecycle to achieve and maintain Authorizations to Operate (ATOs) for mission-critical medical systems. You will work closely with engineers, developers, and government stakeholders to ensure compliance with NIST, DoD, and DHA cybersecurity requirements while supporting continuous monitoring and risk management efforts. This 100% remote position requires availability during standard Eastern Time (ET) day shift hours. Join KBR to contribute directly to protecting critical healthcare systems supporting warfighters and their families. Roles and Responsibilities: + Manage one or more information systems throughout the full six-step RMF lifecycle, including assessment, authorization, and continuous monitoring activities + Serve as an RMF Subject Matter Expert (SME), advising stakeholders on cybersecurity compliance, risk posture, and ATO readiness + Develop, review, and maintain RMF packages and associated documentation, including Security Plans, POA&Ms, Risk Assessment Reports, and security control policies + Assess system compliance against NIST SP 800-53 controls and DHA RMF requirements as part of self-assessment and annual reviews + Document and maintain evidence supporting control implementation and compliance + Lead and participate in A&A and stakeholder meetings to track system status, resolve issues, and drive RMF progress + Coordinate with engineers and system owners to develop architecture diagrams, system asset inventories, and security policies + Prepare and deliver status reports to DHA leadership on system authorization and compliance efforts ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [In-depth .NET Azure Functions: Isolated mode, performance and durable AI agents](https://www.wearedevelopers.com/videos/100207-in-depth-net-azure-functions-isolated-mode-performance-and-durable-ai-agents) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How Much Does a Software Engineer Make? Realistic Software Engineering Salaries](https://www.wearedevelopers.com/magazine/425-how-much-does-a-software-engineer-make-realistic-software-engineering-salaries) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany)