RMF Analyst / ISSO Support

American Operations Corporation
Montgomery, AL, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Cyber Security Software Vulnerability Management SC Clearance Devsecops

Job description

Supports execution of RMF activities, security documentation, STIG compliance analysis, vulnerability reporting, POA&M management, and cybersecurity artifact preparation for BMx systems. This role assists the Cybersecurity Lead with maintaining authorization readiness, continuous monitoring activities, and eMASS-compatible documentation supporting Government cybersecurity oversight.

The RMF Analyst/ISSO Support role works closely with DevSecOps personnel, System Architects, Independent Test Teams, Cloud Engineers, and Product Owners to ensure RMF evidence remains synchronized with deployment activities, modernization changes, infrastructure modifications, and release sequencing. This role also supports continuous monitoring reporting, control validation, cybersecurity audit preparation, and vulnerability remediation coordination.

Requirements

Do you have experience in Technical documentation?, Must possess DoD Secret Clearance. Technical Skills

  • eMASS
  • RMF documentation
  • ACAS
  • STIGs
  • POA&M management
  • Security compliance reporting

Certifications

Required:

  • Security+

Preferred:

  • CAP

Experience

  • 5+ years RMF support experience.

Benefits & conditions

Pulled from the full job description

  • AD&D insurance
  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Life insurance, * Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Short Term & Long Term Disability

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:59 min

Why existing security and device management tools fail

Marcus Wermuth Marcus Wermuth · WWC Europe 2026

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:55 min

Executing secure deployments with verified compliance and data residency

Alex Laubscher Alex Laubscher · WWC 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all