> Markdown version of [/jobs/ext/2294439-isso-rmf-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/2294439-isso-rmf-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSO / RMF Cybersecurity Analyst - **Company:** Xcelerate Solutions - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Windows, Amazon Web Services, Systems Engineering, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Databases, System Configuration, Linux, Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, Network Security, Software Vulnerability Management, SARS Software Products, SC Clearance, Kubernetes, Information Technology, Nessus, Operating System Security, Scap Compliance Checker, Devsecops, Docker, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9126379/isso-rmf-cybersecurity-analyst ## About the Role * Education: Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field (equivalent professional experience may be considered). * Experience: + Minimum of 5+ years of experience in cybersecurity, information assurance, or IT compliance. + 3+ years of direct, hands-on experience guiding systems through the RMF process (Steps 1 through 7) to successful ATO determinations. * Technical Skills: + Deep working knowledge of NIST SP 800-37, NIST SP 800-53, and CNSSI 1253. + Direct experience using automated vulnerability assessment tools (e.g., Nessus, ACAS, SCC). + Proven experience managing and navigating security control databases (such as eMASS). + Solid understanding of operating system security configurations (Windows, Linux) and network security architectures. * Soft Skills: + Strong technical writing skills with demonstrated ability to produce clear, structured compliance documentation. + Excellent communication and interpersonal skills, with the ability to bridge the gap between technical teams and authorizing officials. Preferred Qualifications * Experience with cloud security compliance models (e.g., FedRAMP, AWS GovCloud, Azure Government). * Familiarity with secure software development principles, DevSecOps pipelines, and container security (e.g., Docker, Kubernetes). * Experience implementing Section 508 accessibility standards within cybersecurity practices. * Experience supporting defense contract execution or secure federal program architectures. Certifications To meet federal cybersecurity and technical baseline requirements, candidates must possess or be willing to obtain: 1. Cybersecurity Baseline Certification (Required) Active DoD 8570.01-M / DoD 8140 Information Assurance Management (IAM) Level II certification (or higher). Acceptable certifications include: * Certified Authorization Professional (CAP / CGRC) (highly preferred) * CompTIA Security+ CE (acceptable depending on IAM/IAT alignment) * Certified Information Security Manager (CISM) * Certified Information Systems Security Professional (CISSP) * GIAC Security Leadership (GSLC) ## Description Xcelerate Solutions seeks an Information System Security Officer (ISSO) / RMF Cybersecurity Analyst to play a critical role in ensuring the security posture, compliance, and continuous monitoring of our secure enterprise IT systems. The successful candidate will guide systems through the federal Risk Management Framework (RMF) lifecycle to obtain and maintain an active Authorization to Operate (ATO). This position requires a deep understanding of federal cybersecurity policies, NIST Special Publications (specifically NIST SP 800-37 and NIST SP 800-53), and hands-on experience managing security controls. The ISSO will collaborate closely with system administrators, software developers, and government authorizing officials to identify risks, implement mitigation strategies, and maintain robust system defenses. Come join our award-winning organization and work with some of the most talented and brightest minds in the GovCon industry. Key Responsibilities In accordance with established cybersecurity performance standards, the ISSO / RMF Cybersecurity Analyst will perform the following duties: 1. Risk Management Framework (RMF) & Compliance * Lead the system categorization, security control selection, implementation, assessment, and continuous monitoring processes across the RMF lifecycle. * Develop, update, and maintain comprehensive Security Authorization Packages, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action and Milestones (POA&Ms), and continuous monitoring plans. * Utilise government systems of record (e.g., Enterprise Mission Assurance Support Service - eMASS) to document and track compliance packages. 2. Vulnerability Management & Assessment * Coordinate and conduct regular vulnerability scans using automated tools (e.g., ACAS, Nessus, SCAP Compliance Checker). * Analyze scan results, coordinate with technical teams to remediate vulnerabilities, and document necessary exceptions or POA&Ms. * Review Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) to ensure secure system configurations. 3. Continuous Monitoring & Incident Response * Monitor and assess security controls on an ongoing basis to ensure they remain effective over time in a dynamic operational environment. * Assist with the identification, investigation, and reporting of security incidents or anomalies in accordance with established reporting procedures. * Ensure log management, system auditing, and boundary protections are maintained in compliance with federal guidelines. 4. Technical Collaboration & Advisory * Act as the primary cybersecurity advisor to technical development, systems engineering, and management teams. * Ensure that new software features, infrastructure changes, and system updates are designed and implemented with security-by-design principles. * Support the planning and execution of security control assessments (SCAs) conducted by external assessment teams., Due to the secure nature of the enterprise environment and associated federal mandates: * Work Status Allowable: U.S. citizenship * Minimum Clearance to Start: Public Trust or Favorably Adjudicated Secret Clearance * Compliance: Must strictly adhere to government cybersecurity policies, operations security (OPSEC) rules, and secure system access regulations. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)