> Markdown version of [/jobs/ext/2998948-rmf-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2998948-rmf-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Rmf / Information System Security Officer (isso) - **Company:** Markon, LLC. - **Location:** Annapolis, MD, United States - **Salary:** $200,000.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Linux, Information Security Management, Red Hat Enterprise Linux, Kubernetes, Docker - **Published:** September 19, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9177957/rmf-information-system-security-officer-isso ## About the Role * Active TS/SCI w/ Polygraph * CompTIA Security+ certification * Professional U.S. Government/DoD GRC and RMF experience * Demonstrated ability to independently develop, maintain, and own SSPs * Working knowledge of the DoD Risk Management Framework * Familiarity with NIST SP 800-53 security controls * Familiarity with DISA STIGs * Experience preparing RMF/ATO documentation, control evidence, and assessment artifacts * Experience supporting systems through authorization and/or continuous monitoring * Experience working with RHEL systems * Strong technical writing and documentation skills * Strong customer-facing communication skills, * Experience serving as an ISSO or equivalent RMF/GRC role * Docker, Kubernetes, or other container/container-orchestration experience is a major plus * Experience with eMASS * Experience developing and managing POA&Ms * Experience with DoD authorization packages and ATOs * Experience reviewing or implementing DISA STIG requirements * Experience with vulnerability and compliance scanning * Linux/RHEL system administration experience ## Description * Own and drive the RMF process for assigned systems * Develop, maintain, and update System Security Plans (SSPs) * Support systems through ATO, reauthorization, and continuous monitoring * Interpret and document implementation of NIST SP 800-53 security controls * Work with DISA STIGs, findings, remediation, and compliance documentation * Prepare and maintain required RMF documentation and authorization artifacts * Gather and organize control implementation evidence * Identify documentation, control, and evidence gaps and coordinate their resolution * Develop and maintain POA&Ms and associated remediation documentation * Work with engineers and system administrators to understand and document technical control implementations * Support government security reviews and assessment activities * Communicate directly with government customers, assessors, technical teams, and other stakeholders * Maintain authorization documentation as systems and environments change ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Beyond SBOMs: The Future of Container Supply Chain Security](https://www.wearedevelopers.com/videos/100235-beyond-sboms-the-future-of-container-supply-chain-security) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)