1

Cybersecurity Rmf Isso Jobs (NOW HIRING)

This role is focused on ensuring cybersecurity requirements, RMF considerations, security ... The position supports ACC/A26 stakeholders, ACC Cybersecurity Chief ISSO/ISSMs, and ISR Enterprise ...

Execute the NIST SP 800-37 Rev. 2 RMF lifecycle for FISMA Moderate systems. * Develop, maintain ... Lead ISSO Qualifications * 10+ years of federal cybersecurity experience. * 8+ years of federal ...

Senior Cybersecurity Project Manager

Hampton, VA · On-site

$121K - $121K/yr

This role is focused on ensuring cybersecurity requirements, RMF considerations, security ... The position supports ACC/A26 stakeholders, ACC Cybersecurity Chief ISSO/ISSMs, and ISR Enterprise ...

Execute the NIST SP 800-37 Rev. 2 RMF lifecycle for FISMA Moderate systems. * Develop, maintain ... Lead ISSO Qualifications * 10+ years of federal cybersecurity experience. * 8+ years of federal ...

Showing results 21-40

Cybersecurity Rmf Isso information

See salary details

$46K

$118.3K

$184.5K

How much do cybersecurity rmf isso jobs pay per year?

As of Sep 10, 2026, the average yearly pay for cybersecurity rmf isso in the United States is $118,327.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,000.00 and $138,000.00 per year, depending on experience, location, and employer.

What is a Cybersecurity RMF ISSO?

A Cybersecurity RMF ISSO (Risk Management Framework Information System Security Officer) is a professional responsible for ensuring the security and compliance of information systems within an organization, following the guidelines of the Risk Management Framework (RMF). The ISSO plays a key role in assessing, implementing, and maintaining security controls, ensuring that systems meet federal or organizational cybersecurity standards. They collaborate with system owners and other stakeholders to manage risks, document security processes, and support continuous monitoring. RMF ISSOs are particularly common in government and defense sectors, where strict security compliance is required.

What are the key skills and qualifications needed to thrive as a Cybersecurity RMF ISSO?

To thrive as a Cybersecurity RMF Information System Security Officer (ISSO), you need in-depth knowledge of risk management frameworks (like NIST RMF), security policies, and compliance requirements, typically backed by a degree in cybersecurity or a related field. Familiarity with technical tools such as vulnerability scanners, security information and event management (SIEM) systems, and certifications like CISSP or Security+ are commonly required. Strong attention to detail, effective communication, and the ability to work collaboratively with both technical and non-technical stakeholders are key soft skills for this role. These abilities are vital to ensure that organizational systems remain compliant and secure against evolving cyber threats.

What are some common challenges faced by a Cybersecurity RMF ISSO when implementing security controls across multiple systems?

A Cybersecurity RMF ISSO often encounters challenges such as aligning security controls with diverse system architectures, ensuring compliance with evolving regulatory requirements, and coordinating with various stakeholders who may have competing priorities. Balancing thorough documentation with tight project deadlines can also be demanding. Effective communication and strong organizational skills are key to overcoming these obstacles and ensuring all systems maintain their required security posture.

What is the difference between Cybersecurity Rmf Isso vs Cybersecurity Analyst?

AspectCybersecurity Rmf IssoCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentFocus on risk management, compliance, and security frameworks within organizationsMonitor security systems, analyze threats, and implement security measures
Employer & Industry UsagePrimarily in government, defense, and regulated industriesAcross various industries including finance, healthcare, and tech

While both roles involve cybersecurity, a Cybersecurity Rmf Isso specializes in risk management and compliance within security frameworks like RMF, often in regulated sectors. A Cybersecurity Analyst focuses on monitoring and analyzing security threats across diverse industries. Understanding these differences helps organizations assign the right responsibilities and certifications for each role.

What are popular job titles related to Cybersecurity Rmf Isso jobs?

For Cybersecurity Rmf Isso jobs, the most frequently searched job titles are:

Infographic showing various Cybersecurity Rmf Isso job openings in the United States as of September 2026, with employment types broken down into 67% Full Time, and 33% Contract. Highlights an 100% In-person job distribution, with an average salary of $118,327 per year, or $56.9 per hour.

Senior Information Systems Security Officer

Washington, DC • On-site

Bamboo Solutions
Software Development • 11 - 50 employees

Full-time

Medical, Dental, Retirement, PTO

Posted 16 days ago


Job description

We are looking for a Senior Information System Security Officer (ISSO) to support a critical U.S. government agency in the National Capital Region. This role reports to the Security Program Management Office (SPMO) Manager and works directly with team members and Federal ISSOs to support authorization, compliance, continuous monitoring, and risk management activities across assigned systems.
This is an excellent opportunity for an experienced cybersecurity professional with a strong technical background to support the secure authorization and ongoing compliance of systems across on-premises and cloud environments. This is not a hands-on engineering position. Instead, the Senior ISSO leverages prior experience as a Systems Administrator, Cloud Engineer, Infrastructure Engineer, Network Engineer, Security Engineer, or similar technical role to independently validate security implementations, assess technical risk, and ensure authorization decisions are supported by accurate technical evidence. The successful candidate must be comfortable engaging engineers, architects, and system owners to validate security controls, identify inconsistencies, and challenge unsupported technical assumptions.
Hybrid: 3 Days On-site in Washington, DC / 2 Days Remote
Must be able to obtain a government security clearance requiring U.S. Citizenship or Permanent Resident Status
Responsibilities:
  • Support the security authorization lifecycle and ongoing continuous monitoring activities for assigned systems.
  • Develop, review, and maintain security documentation and authorization artifacts, including SSPs, SARs, POA&Ms, SIAs, and related documentation, in accordance with NIST SP 800-53, RMF, FISMA, and agency policies.
  • Coordinate and prepare systems for Security Control Assessments (SCAs), ensuring documentation and evidence are complete, accurate, and technically defensible.
  • Conduct Security Impact Analyses (SIAs) for changes to hardware, software, cloud infrastructure, connectivity, or system architecture.
  • Review system architecture, technical documentation, and supporting evidence to validate security controls, independently assess technical implementations, identify inconsistencies, and collaborate with engineers, architects, administrators, and system owners to resolve discrepancies.
  • Support change management, continuous monitoring, POA&M management, risk acceptance, audit responses, and remediation activities to maintain ongoing authorization and compliance.
  • Coordinate with system owners, engineers, architects, and governance stakeholders to support standards reviews, exception requests, policy implementation, compliance reporting, and risk management activities.
  • Develop dashboards, executive risk briefings, status reports, and other stakeholder communications while supporting the Lead ISSO in operational execution and coordination activities.
Required Qualifications:
  • Bachelor's degree and 6+ years of relevant experience, or a master's degree and 5+ years of experience, in cybersecurity, RMF, ISSO, systems security engineering, systems administration, cloud engineering, network engineering, or a related field.
  • Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card.
  • Prior hands-on experience in a technical role such as Systems Administrator, Cloud Engineer, Infrastructure Engineer, Network Engineer, or Security Engineer, with the ability to evaluate technical implementations, validate controls, assess evidence, and challenge unsupported assumptions.
  • Experience supporting federal authorization activities, including SSPs, POA&Ms, SIAs, continuous monitoring, and Security Control Assessments.
  • Working knowledge of NIST RMF, NIST SP 800-53, FISMA, and federal cybersecurity requirements.
  • Familiarity with enterprise and cloud technologies such as AWS, Azure, Microsoft 365, Entra ID, Active Directory, VMware, Cisco, Oracle, or similar platforms.
  • Working knowledge of identity and access management, encryption, system hardening, network and cloud security, secure baselines, logging, and monitoring.
  • Experience with GRC or security authorization tools such as Archer, eMASS, JCAM/CSAM, Xacta, or similar platforms.
  • Strong analytical, technical writing, organizational, and communication skills, including demonstrated professional proficiency in written and spoken English. Ability to independently produce polished, technically accurate documentation; communicate clearly and effectively with technical and non-technical stakeholders; work independently; and manage competing priorities in a fast-paced environment.
  • Proficiency with Microsoft Word, Excel, PowerPoint, and SharePoint.
Preferred Qualifications:
  • Security+, CGRC (formerly CAP), CISSP, CISM, CCSP, or similar cybersecurity certification.
  • Experience supporting federal systems, ATO processes, FedRAMP, federal privacy requirements, or other government compliance programs.
  • Knowledge of modern cybersecurity practices including OWASP Top 10, Zero Trust, application security concepts, and MITRE ATT&CK.
  • Experience participating in incident response, security architecture reviews, technical design reviews, or security remediation efforts.
  • Experience operating in fast-paced, high-visibility environments with competing priorities.

We offer:
  • Competitive salary based on experience
  • Profit sharing distributed twice a year
  • 15 days of paid time off and 10 paid holidays per year
  • 401(k) with employer matching
  • Health and dental benefits
  • Opportunity to work with other talented technical professionals

SharePointXperts is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected Veteran status.
SharePointXperts participates in E-Verify. Click the following links for important information about our participation in this program and your rights.
https://www.e-verify.gov/sites/default/files/everify/posters/IER_RightToWorkPoster%20Eng_Es.pdf
https://www.e-verify.gov/sites/default/files/everify/posters/EVerifyParticipationPoster.pdf