> Markdown version of [/jobs/ext/2431194-rmf-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2431194-rmf-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF/Information System Security Officer - **Company:** Chickasaw Nation Industries, Inc. - **Location:** Rock Island, IL, United States - **Experience:** Expert - **Salary:** $95,000.0 - $125,000.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Information Systems, Information Security Management, Security Content Automation Protocol, Information Security Management System, Information Technology, Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 8, 2026 - **Apply:** https://www.jofdav.com/jobs/59147207-rmf-information-system-security-officer ## About the Role The ability to obtain, maintain and access classified information at the Top Secret level. CompTIA Security+ certification is required and must be maintained throughout the duration of employment. Technical Skills: Demonstrated mastery of eMASS, vulnerability scanning tools (e.g., ACAS/Nessus), COMSEC, and security compliance checkers (e.g., SCAP), A Bachelor's degree from an accredited institution in Information Technology, Cybersecurity, Business Management, or a related field; or experience equal to. Minimum 5+ years of hands-on experience dedicated to applying RMF to complex DoD IT systems., Work is primarily performed in an office environment. Regularly required to sit. Regularly required use hands to finger, handle, or feel, reach with hands and arms to handle objects and operate tools, computer, and/or controls. Required to speak and hear. Occasionally required to stand, walk and stoop, kneel, crouch, or crawl. Must frequently lift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, and ability to adjust focus. Exposed to general office noise with computers printers and light traffic. ## Description The RMF/Information System Security Officer (ISSO) is responsible for supporting the security, compliance, and integrity of information systems by implementing cybersecurity best practices and ensuring adherence to organizational, federal, and customer security requirements. This role collaborates with technical and program teams to identify and mitigate security risks, maintain system compliance, support security assessments, and promote the protection of sensitive information throughout the system lifecycle. This expert is responsible for guiding IT systems through the entire Risk Management Framework (RMF) lifecycle to achieve and maintain the Authority to Operate (ATO)., * Essential Duties and responsibilities include the following. Other duties may be assigned. * RMF Execution: Lead all aspects of the RMF process, from system categorization and security control selection to implementation and assessment. * Security Documentation: Develop, maintain, and update all required RMF documentation, including the System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action & Milestones (POA&M). * eMASS Management: Manage the system's security posture within the Enterprise Mission Assurance Support System (eMASS), ensuring all data is accurate and up to date. * Continuous Monitoring: Implement and manage a robust continuous monitoring strategy to actively assess security control effectiveness, track vulnerabilities, and manage configuration changes. * Stakeholder Coordination: Serve as the primary security advisor to the system owner and liaise with the Authorizing Official (AO) and other key stakeholders to ensure a clear understanding of system risks and compliance status. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)