Cyber RMF ISSO

3 Reasons Consulting
United States
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Unix CompTIA Security+ Cyber Security Linux Networking Hardware Inventory Management Software Microsoft SQL Server Oracle (Applications) Package Development Process Information Technology Scap Compliance Checker
+2 more
Vulnerability Analysis Vmware

Job description

3 Reasons Consulting is seeking a Cybersecurity RMF ISSO / RMF SME to support Assessment & Authorization (A&A) and Risk Management Framework (RMF) activities for Department of Defense (DoD) medical systems. This remote role focuses on guiding systems through the RMF lifecycle, ensuring mission readiness, continuous monitoring, and compliance with DoD cybersecurity policies and frameworks. The ideal candidate brings deep technical knowledge, strong documentation skills, and a collaborative approach to system authorization and security.

Services to be performed include, but are not limited to:

  • Guide multiple systems through RMF processes and maintain ATO status via continuous monitoring and annual reviews.
  • Lead or support A&A and RMF compliance efforts for DoD medical networks, applications, and devices.
  • Conduct risk and vulnerability assessments using DISA SCAP Compliance Checker, ACAS, and manual STIG reviews.
  • Develop and maintain RMF documentation including Security Plans, POA&Ms, Implementation Plans, and Risk Assessments.
  • Serve as Subject Matter Expert (SME) in A&A technologies and provide strategic guidance to teams.
  • Facilitate stakeholder meetings, provide weekly status updates, and submit program reports to leadership.
  • Maintain system compliance with NIST 800-53, DISA STIGs/SRGs, and other DoD security standards.
  • Collaborate with system admins and ISSMs to update system/site policies, diagrams, and inventories.
  • Lead and participate in sessions to address emerging RMF and cybersecurity guidance.
  • Produce audit evidence and compliance artifacts as required.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, or a related field. (or equivalent experience)
  • Minimum 4 years of experience in cybersecurity, including RMF and ATO support.
  • DoD 8570-compliant (CompTIA Security+ certified).
  • Demonstrated experience in RMF package development: POA&Ms, Security Plans, Risk Assessments, diagrams, and inventory tracking using Enterprise Mission Assurance Support Service (eMASS).
  • Hands-on experience with eMASS and NIST publications.
  • Strong organizational, customer service, verbal, and written communication skills.

Required Certification(s):

  • CompTIA Security+ CE (IAT II level or higher)

Additional Qualifications (Preferred):

  • Knowledge of ACAS and Host-Based Security System (HBSS).
  • Experience with RMF policy development and continuous monitoring strategies.
  • Knowledge of CMRS and experience with the following technologies:
  • Medical Devices
  • Windows, Linux, Unix
  • Network Devices
  • MS SQL, Oracle
  • VMware

Clearance Level: Active DoD Secret Security Clearance

Benefits & conditions

  • Basic Life Insurance
  • Direct Payroll Deposit
  • Leave Accrual
  • Holidays
  • 401(k) Match

Employee / Company Shared Benefits:

  • Additional (Voluntary) Life Insurance
  • 401(k)
  • Medical Coverage
  • Dental Coverage
  • Vision Care Plan
  • Flexible Spending Account Plan

An Equal Opportunity Employer

3 Reasons Consulting is an Equal Opportunity Employer. We are committed to providing a workplace free from discrimination or harassment and hold all 3 Reasons employees accountable to protect this mission. We do not discriminate on the basis of race, color, gender, religion, national origin, sexual orientation, age, marital status, veteran status, military status, disability status, or any other characteristic protected by federal, state, or local law. All applicants will receive consideration for employment without regard to protected bases.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

1:40 min

Managing containerized infrastructure with Podman Desktop

Cedric Clyburn Cedric Clyburn +1 · WWC 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

1:41 min

Parallels between cloud and legacy infrastructure lock-ins

Björn Stahl Björn Stahl · WWC 2024

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all