> Markdown version of [/jobs/ext/1917611-cyber-rmf-isso](https://www.wearedevelopers.com/jobs/ext/1917611-cyber-rmf-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber RMF ISSO - **Company:** 3 Reasons Consulting - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Unix, CompTIA Security+, Cyber Security, Linux, Networking Hardware, Inventory Management Software, Microsoft SQL Server, Oracle (Applications), Package Development Process, Information Technology, Scap Compliance Checker, Vulnerability Analysis, Vmware - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=027f2f78e3376474 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, or a related field. (or equivalent experience) * Minimum 4 years of experience in cybersecurity, including RMF and ATO support. * DoD 8570-compliant (CompTIA Security+ certified). * Demonstrated experience in RMF package development: POA&Ms, Security Plans, Risk Assessments, diagrams, and inventory tracking using Enterprise Mission Assurance Support Service (eMASS). * Hands-on experience with eMASS and NIST publications. * Strong organizational, customer service, verbal, and written communication skills. Required Certification(s): * CompTIA Security+ CE (IAT II level or higher) Additional Qualifications (Preferred): * Knowledge of ACAS and Host-Based Security System (HBSS). * Experience with RMF policy development and continuous monitoring strategies. * Knowledge of CMRS and experience with the following technologies: + Medical Devices + Windows, Linux, Unix + Network Devices + MS SQL, Oracle + VMware Clearance Level: Active DoD Secret Security Clearance ## Description 3 Reasons Consulting is seeking a Cybersecurity RMF ISSO / RMF SME to support Assessment & Authorization (A&A) and Risk Management Framework (RMF) activities for Department of Defense (DoD) medical systems. This remote role focuses on guiding systems through the RMF lifecycle, ensuring mission readiness, continuous monitoring, and compliance with DoD cybersecurity policies and frameworks. The ideal candidate brings deep technical knowledge, strong documentation skills, and a collaborative approach to system authorization and security. Services to be performed include, but are not limited to: * Guide multiple systems through RMF processes and maintain ATO status via continuous monitoring and annual reviews. * Lead or support A&A and RMF compliance efforts for DoD medical networks, applications, and devices. * Conduct risk and vulnerability assessments using DISA SCAP Compliance Checker, ACAS, and manual STIG reviews. * Develop and maintain RMF documentation including Security Plans, POA&Ms, Implementation Plans, and Risk Assessments. * Serve as Subject Matter Expert (SME) in A&A technologies and provide strategic guidance to teams. * Facilitate stakeholder meetings, provide weekly status updates, and submit program reports to leadership. * Maintain system compliance with NIST 800-53, DISA STIGs/SRGs, and other DoD security standards. * Collaborate with system admins and ISSMs to update system/site policies, diagrams, and inventories. * Lead and participate in sessions to address emerging RMF and cybersecurity guidance. * Produce audit evidence and compliance artifacts as required. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Generating code with Angular schematics](https://www.wearedevelopers.com/videos/129-generating-code-with-angular-schematics) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)