> Markdown version of [/jobs/ext/499943-rmf-analyst-isso-support](https://www.wearedevelopers.com/jobs/ext/499943-rmf-analyst-isso-support). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF Analyst / ISSO Support - **Company:** American Operations Corporation - **Location:** Montgomery, AL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cyber Security, Software Vulnerability Management, SC Clearance, Devsecops - **Published:** June 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=98e9f9e342b5a1bd ## About the Role Do you have experience in Technical documentation?, Must possess DoD Secret Clearance. Technical Skills * eMASS * RMF documentation * ACAS * STIGs * POA&M management * Security compliance reporting Certifications Required: * Security+ Preferred: * CAP Experience * 5+ years RMF support experience. ## Description Supports execution of RMF activities, security documentation, STIG compliance analysis, vulnerability reporting, POA&M management, and cybersecurity artifact preparation for BMx systems. This role assists the Cybersecurity Lead with maintaining authorization readiness, continuous monitoring activities, and eMASS-compatible documentation supporting Government cybersecurity oversight. The RMF Analyst/ISSO Support role works closely with DevSecOps personnel, System Architects, Independent Test Teams, Cloud Engineers, and Product Owners to ensure RMF evidence remains synchronized with deployment activities, modernization changes, infrastructure modifications, and release sequencing. This role also supports continuous monitoring reporting, control validation, cybersecurity audit preparation, and vulnerability remediation coordination. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Dev Digest 212: WebMCP or MCP, What is DevRel, AI's 10% Productivity Boost, and a 49MB Web Page…](https://www.wearedevelopers.com/magazine/717-dev-digest-212-webmcp-or-mcp-what-is-devrel-ai-s-10-productivity-boost-and-a-49mb-web-page) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)