ISSO / RMF Analyst

Posted Yesterday
Be an Early Applicant
Quantico, VA, USA
In-Office
96K-149K Annually
Mid level
Artificial Intelligence • Information Technology • Software • Defense
The Role
Supports DoD Risk Management Framework activities by maintaining eMASS authorization packages, monitoring vulnerabilities and STIG compliance, managing POA&Ms, preparing audit evidence, supporting assessments, reviewing security-impacting changes, and driving system reaccreditation. The role collaborates with administrators and engineers to implement NIST security controls, maintains compliance documentation and reporting, and mentors technical staff on secure configurations and evidence collection.
Summary Generated by Built In
Overview

Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform® provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai.


Empower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company’s commitment to hiring and supporting active-duty and veteran employees.

Responsibilities

Empower AI is seeking an ISSO / RMF Analyst to support Risk Management Framework (RMF) activities for the systems and assets managed by an enterprise IT Customer Support Services program supporting a Department of War agency. Acting on behalf of the Government System Owner, the ISSO develops and maintains complete, accurate, and timely RMF documentation packages in eMASS, executes continuous monitoring, manages Plans of Action and Milestones, and keeps in-scope systems (endpoint infrastructure, printers, communications, dashboards, and support platforms) reaccredited before their ATO expiration. The role works daily with systems administrators, engineers, and the Risk Management Support Lead to translate technical configurations into compliant security controls and audit-ready evidence. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers. 


THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED. 


JOB DUTIES: 

  • Develop, compile, update, and maintain RMF package artifacts for assigned systems in eMASS, including the System Security Plan (SSP), Security Assessment Report (SAR) inputs, Plan of Action & Milestones (POA&M), control implementation statements, and supporting artifacts required by DoDI 8510.01 and agency A&A process documentation. 
  • Execute the continuous monitoring strategy for assigned systems: analyze weekly ACAS vulnerability scan results, track STIG compliance, validate remediation, and manage POA&M items to maintain security posture between authorization cycles. 
  • Prepare the weekly Vulnerability Scan Analysis Report and the monthly STIG Compliance Report for assigned systems, identifying critical vulnerabilities and their remediation status. 
  • Work with systems administrators, telecommunications engineers, and endpoint engineers to select, implement, and document NIST SP 800-53 security controls, verify STIG/SRG baseline configurations, and collect implementation evidence. 
  • Track ATO expiration dates and drive reaccreditation activities so that every in-scope system is reauthorized prior to its 3-year ATO expiration and 100% of complete packages are delivered on the required timeline. 
  • Support security control assessments and audits: prepare systems and documentation, participate in technical exchange meetings with assessors, respond to findings, and maintain a state of continuous audit readiness. 
  • Review and process change requests for security impact (CM-4), support incident handling and reporting procedures, and ensure security requirements are addressed in Change Management for in-scope systems. 
  • Maintain RMF process documentation, SOPs, and status trackers; provide RMF and compliance posture inputs to the Monthly Customer Support Activity Report; and mentor technicians on secure configuration and evidence collection practices. 
Qualifications

REQUIREMENTS: 

  • Bachelor's degree and a minimum of 3 years of related experience (an additional 4 years of related experience may be substituted for the degree). 
  • Must be a U.S. Citizen. 
  • Must have an Active Top Secret Clearance with SCI eligibility (favorably adjudicated T5/T5R) to start. 
  • Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting. 
  • Must possess and maintain a current DoD 8570/8140 IAM Level I baseline certification (e.g., CAP, CND, Cloud+, GSLC, or Security+ CE). 
  • Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision. 
  • Minimum of 3 years of experience performing ISSO or RMF/assessment and authorization duties for DoD or Federal information systems. 
  • Working knowledge of NIST SP 800-37 (RMF), NIST SP 800-53 (Security Controls), CNSSI 1253, and DoDI 8510.01. 
  • Hands-on experience with eMASS for RMF package development, control implementation, and POA&M management. 
  • Experience interpreting ACAS/Nessus vulnerability scan results and STIG Viewer/SCAP compliance results and managing remediation through POA&Ms. 
  • Ability to write clear, accurate security documentation (SSP, control narratives, POA&M entries) and to explain requirements to technical teams. 
  • Strong organizational skills and attention to detail; ability to manage multiple systems and deadlines concurrently. 

DESIRED SKILLS: 

  • CAP/CGRC, Security+ CE, CISSP Associate, or CISM certification (IAM Level II is a plus). 
  • Experience with enterprise technologies commonly in scope, including Windows Server, Active Directory, VMware virtualization, Linux (RHEL), enterprise endpoint management, VoIP/VTC, and network printers. 
  • Experience supporting Department of War (DoW), DoD, or Intelligence Community systems across NIPRNet, SIPRNet, and JWICS enclaves. 
  • Familiarity with DoD Zero Trust, DoDI 8500.01, DoDI 8531.01 vulnerability management, and CJCSM 6510.01B incident handling. 
  • Experience supporting Supply Chain Risk Management (SCRM) controls and plans. 
  • Experience using ServiceNow (incident, request, knowledge, CMDB, Service Catalog, Virtual Agent) or a comparable enterprise ITSM platform. 
About Empower AI

All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm’s overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.

Pay Band MinUSD $96,050.00/Yr. Pay Band MaxUSD $148,670.00/Yr.

Skills Required

  • Bachelor's degree and at least 3 years of related experience; an additional 4 years of related experience may substitute for the degree.
  • U.S. citizenship.
  • Active Top Secret clearance with SCI eligibility, favorably adjudicated T5/T5R, at start.
  • Within investigation scope and/or currently enrolled in Continuous Evaluation or Continuous Vetting.
  • Current DoD 8570/8140 IAM Level I baseline certification, such as CAP, CND, Cloud+, GSLC, or Security+ CE.
  • At least 3 years performing ISSO or RMF assessment and authorization duties for DoD or federal information systems.
  • Working knowledge of NIST SP 800-37, NIST SP 800-53, CNSSI 1253, and DoDI 8510.01.
  • Hands-on experience with eMASS for RMF package development, control implementation, and POA&M management.
  • Experience interpreting ACAS/Nessus vulnerability scans and STIG Viewer/SCAP compliance results and managing remediation through POA&Ms.
  • Ability to write clear security documentation and explain security requirements to technical teams.
  • Strong organizational skills and attention to detail, with ability to manage multiple systems and deadlines.
  • CAP/CGRC, Security+ CE, CISSP Associate, or CISM certification; IAM Level II is a plus.
  • Experience with Windows Server, Active Directory, VMware, Linux/RHEL, endpoint management, VoIP/VTC, and network printers.
  • Experience supporting DoW, DoD, or Intelligence Community systems across NIPRNet, SIPRNet, and JWICS.
  • Familiarity with DoD Zero Trust, DoDI 8500.01, DoDI 8531.01, and CJCSM 6510.01B.
  • Experience supporting Supply Chain Risk Management controls and plans.
  • Experience using ServiceNow or a comparable enterprise ITSM platform.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
1,000 Employees
Year Founded: 1989

What We Do

Empower AI is a federal government technology contractor that uses artificial intelligence, machine learning, automation, and natural language processing to help agencies improve decision-making, workforce productivity, security, and mission outcomes. Formerly NCI, the Reston-based company provides AI and software solutions, engineering and integration, IT service management, infrastructure modernization, and mission-support services for civilian and defense agencies worldwide.

Similar Jobs

Remote or Hybrid
2 Locations
289097 Employees

AMP Logo AMP

Production Operator

Artificial Intelligence • Computer Vision • Greentech • Machine Learning • Robotics • Industrial • Automation
Easy Apply
Hybrid
Portsmouth, VA, USA
175 Employees
18-24 Hourly

Collectors Logo Collectors

Supervisor, Operations

Consumer Web • eCommerce • Machine Learning • Software • Sports • Analytics
In-Office or Remote
2 Locations
2246 Employees
62K-72K Annually

NinjaOne Logo NinjaOne

Penetration Tester

Information Technology • Productivity • Software • Infrastructure as a Service (IaaS)
Remote or Hybrid
19 Locations
2000 Employees
130K-165K Annually

Similar Companies Hiring

Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account