> Markdown version of [/jobs/ext/2575828-senior-isso-rmf-cyber-analyst-avmc](https://www.wearedevelopers.com/jobs/ext/2575828-senior-isso-rmf-cyber-analyst-avmc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior ISSO / RMF Cyber Analyst (AvMC) - **Company:** COLSA CORPORATION - **Location:** Huntsville, AL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Monitoring of Systems, Information Security Management, Security Content Automation Protocol, Security Software, Systems Architecture, Technical Data Management Systems, Information Security Management System, SC Clearance, Tenable Nessus - **Published:** August 6, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9081517/senior-isso-rmf-cyber-analyst-avmc ## About the Role * Bachelor's Degree in related field, or equivalent experience. * Minimum of 10 years of work-related experience. * CompTIA Security+ CE or another DoD 8570 Level II/III certification. * Solid understanding and experience with Risk Management Framework (RMF). * Solid understanding of creating Assessment & Authorization (A&A) accreditation packages. * Very knowledgeable of Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRG). * Experience working with the security team and system administrators to identify, fix, and provide information regarding resolving vulnerabilities and computer incidents. * Experience using eMASS to create and update accreditation package records. * Ability to clearly present and communicate technical approaches and findings either verbally or in writing. * US Secret Clearance; US Citizenship required, * RMF and cyber experience on U.S. Army systems. ## Description COLSA Corporation is seeking a Risk Management Framework (RMF) Cyber Analyst to serve as an Information Systems Security Officer (ISSO) in support of a US Army contract, Aviation and Missile Center. The selected candidate will support system records for Authorization to Operate (ATO) approval on multiple Information Systems, including Enclaves and Major Applications for both classified and unclassified networks. The candidate will provide support for system monitoring and analysis of detected cyber incidents and provide corrective action recommendations., The ISSO/RMF Cyber Analyst will be responsible for the authorization and compliance management of authorized computing enclaves. Additional duties include but are not limited to: * Directly responsible for analyzing and implementing Cybersecurity (IA) requirements into RMF A&A accreditation packages that meet DoD and Army accreditation standards classified and unclassified enclaves. * Develop and implement a Security-Focused Configuration Management Plan that includes, assisting the Information System Owner or Information System Security Manager in completing Information Security Continuous Monitoring responsibilities. * Implement, assess and monitor security controls on systems and within eMASS. Conduct risk assessments to include: + Configuration change security impact analysis. + Vulnerability audits and security configuration checks. + Hardware and software assessments. * Ensure the implementation of vendor-supplied security software packages, performance of diagnostics for security problems, and assist with the identification/mitigation of security risks. * Monitor DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) by using tools similar to STIG Viewer and Security Content Automation Protocol (SCAP). * Complete analysis from monitoring tools such as Tenable Nessus ACAS, Trellix ePO / legacy HBSS, and other IA-specific software. * Create Cyber Security training materials and mentor team members when applicable. * Continuously monitor and update artifacts in eMASS such as System Security Plan (SSP), IS Security Architecture, Hardware/Software list, and POA&Ms. * Perform the activities necessary to obtain security accreditation of solutions/applications as it relates to system administration. * Prepare and deliver the technical data needed for the submissions of accreditation packages in support of RMF. * Provide data and information as well as make recommendations regarding the overall system security as it relates to system administration and system architecture. * Work with System Administrators to identify and provide information regarding resolution of vulnerabilities, and computer incidents. * Identify where systems/networks deviate from acceptable configurations, enclave policy, or local policy. * Provide compliance recommendations for networks, workstations, servers, and IT assets. * Other duties as assigned. ## Related Videos - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)