> Markdown version of [/jobs/ext/220846-rmf-cybersecurity-isso-sme-4](https://www.wearedevelopers.com/jobs/ext/220846-rmf-cybersecurity-isso-sme-4). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF Cybersecurity ISSO/SME 4 - **Company:** KBR Inc - **Location:** Houston, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $129,300.0 - $194,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Cyber Security, Information Systems, Microsoft Office, Microsoft Project, Package Development Process, Microsoft PowerPoint, Microsoft SharePoint, Information Technology, Scap Compliance Checker - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d3b2b0bfcad74040 ## About the Role * Active DoD Secret security clearance * Bachelor's degree in cybersecurity, information technology, or related field with 10+ years of experience; or 18+ years of relevant cybersecurity/IT experience in lieu of a degree. * DoD Manual 8140.03 (formerly 8570.01)-compliant certification (e.g., Security+, CISSP, CASP+/SecurityX) * Demonstrated experience performing RMF activities as an ISSO/ISSM/SME, including ATO process support and RMF package development (Security Plans, POA&Ms, architecture diagrams, system security policies, etc.) * Demonstrated experience assessing and documenting NIST SP 800-53 controls * Experience using Microsoft Office applications: Word, PowerPoint, Excel, and SharePoint Preferred Qualifications: * Experience using eMASS or equivalent compliance-tracking application * Experience supporting RMF processes under DHA * Familiarity with ACAS and DISA STIGs/SRGs and tools such as STIG Viewer and SCAP Compliance Checker * Familiarity with Continuous Monitoring and Risk Scoring (CMRS) * Experience using Microsoft Project to build Integrated Master Schedules (IMS) ## Description KBR is seeking a Cybersecurity Risk Management Framework (RMF) Information System Security Officer (ISSO) to support the DHA Solution Delivery Division (SDD). In this role, you will lead Assessment & Authorization (A&A) activities and guide systems through the RMF lifecycle to achieve and maintain Authorizations to Operate (ATOs) for mission-critical medical systems. You will work closely with engineers, developers, and government stakeholders to ensure compliance with NIST, DoD, and DHA cybersecurity requirements while supporting continuous monitoring and risk management efforts. This 100% remote position requires availability during standard Eastern Time (ET) day shift hours. Join KBR to contribute directly to protecting critical healthcare systems supporting warfighters and their families. Roles and Responsibilities: * Manage one or more information systems throughout the full six-step RMF lifecycle, including assessment, authorization, and continuous monitoring activities * Serve as an RMF Subject Matter Expert (SME), advising stakeholders on cybersecurity compliance, risk posture, and ATO readiness * Develop, review, and maintain RMF packages and associated documentation, including Security Plans, POA&Ms, Risk Assessment Reports, and security control policies * Assess system compliance against NIST SP 800-53 controls and DHA RMF requirements as part of self-assessment and annual reviews * Document and maintain evidence supporting control implementation and compliance * Lead and participate in A&A and stakeholder meetings to track system status, resolve issues, and drive RMF progress * Coordinate with engineers and system owners to develop architecture diagrams, system asset inventories, and security policies * Prepare and deliver status reports to DHA leadership on system authorization and compliance efforts ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [In-depth .NET Azure Functions: Isolated mode, performance and durable AI agents](https://www.wearedevelopers.com/videos/100207-in-depth-net-azure-functions-isolated-mode-performance-and-durable-ai-agents) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)