Responsibilities
Empower AI is seeking an ISSO / RMF Analyst to support Risk Management Framework (RMF) activities for the systems and assets managed by an enterprise IT Customer Support Services program supporting a Department of War agency. Acting on behalf of the Government System Owner, the ISSO develops and maintains complete, accurate, and timely RMF documentation packages in eMASS, executes continuous monitoring, manages Plans of Action and Milestones, and keeps in-scope systems (endpoint infrastructure, printers, communications, dashboards, and support platforms) reaccredited before their ATO expiration. The role works daily with systems administrators, engineers, and the Risk Management Support Lead to translate technical configurations into compliant security controls and audit-ready evidence. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers.
THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.
JOB DUTIES:
- Develop, compile, update, and maintain RMF package artifacts for assigned systems in eMASS, including the System Security Plan (SSP), Security Assessment Report (SAR) inputs, Plan of Action & Milestones (POA&M), control implementation statements, and supporting artifacts required by DoDI 8510.01 and agency A&A process documentation.
- Execute the continuous monitoring strategy for assigned systems: analyze weekly ACAS vulnerability scan results, track STIG compliance, validate remediation, and manage POA&M items to maintain security posture between authorization cycles.
- Prepare the weekly Vulnerability Scan Analysis Report and the monthly STIG Compliance Report for assigned systems, identifying critical vulnerabilities and their remediation status.
- Work with systems administrators, telecommunications engineers, and endpoint engineers to select, implement, and document NIST SP 800-53 security controls, verify STIG/SRG baseline configurations, and collect implementation evidence.
- Track ATO expiration dates and drive reaccreditation activities so that every in-scope system is reauthorized prior to its 3-year ATO expiration and 100% of complete packages are delivered on the required timeline.
- Support security control assessments and audits: prepare systems and documentation, participate in technical exchange meetings with assessors, respond to findings, and maintain a state of continuous audit readiness.
- Review and process change requests for security impact (CM-4), support incident handling and reporting procedures, and ensure security requirements are addressed in Change Management for in-scope systems.
- Maintain RMF process documentation, SOPs, and status trackers; provide RMF and compliance posture inputs to the Monthly Customer Support Activity Report; and mentor technicians on secure configuration and evidence collection practices.
Qualifications
REQUIREMENTS:
- Bachelor's degree and a minimum of 3 years of related experience (an additional 4 years of related experience may be substituted for the degree).
- Must have an Active Top Secret Clearance with SCI eligibility (favorably adjudicated T5/T5R) to start.
- Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
- Must possess and maintain a current DoD 8570/8140 IAM Level I baseline certification (e.g., CAP, CND, Cloud+, GSLC, or Security+ CE).
- Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
- Minimum of 3 years of experience performing ISSO or RMF/assessment and authorization duties for DoD or Federal information systems.
- Working knowledge of NIST SP 800-37 (RMF), NIST SP 800-53 (Security Controls), CNSSI 1253, and DoDI 8510.01.
- Hands-on experience with eMASS for RMF package development, control implementation, and POA&M management.
- Experience interpreting ACAS/Nessus vulnerability scan results and STIG Viewer/SCAP compliance results and managing remediation through POA&Ms.
- Ability to write clear, accurate security documentation (SSP, control narratives, POA&M entries) and to explain requirements to technical teams.
- Strong organizational skills and attention to detail; ability to manage multiple systems and deadlines concurrently.
DESIRED SKILLS:
- CAP/CGRC, Security+ CE, CISSP Associate, or CISM certification (IAM Level II is a plus).
- Experience with enterprise technologies commonly in scope, including Windows Server, Active Directory, VMware virtualization, Linux (RHEL), enterprise endpoint management, VoIP/VTC, and network printers.
- Experience supporting Department of War (DoW), DoD, or Intelligence Community systems across NIPRNet, SIPRNet, and JWICS enclaves.
- Familiarity with DoD Zero Trust, DoDI 8500.01, DoDI 8531.01 vulnerability management, and CJCSM 6510.01B incident handling.
- Experience supporting Supply Chain Risk Management (SCRM) controls and plans.
- Experience using ServiceNow (incident, request, knowledge, CMDB, Service Catalog, Virtual Agent) or a comparable enterprise ITSM platform.
Pay Band MinUSD $96,050.00/Yr.
Pay Band MaxUSD $148,670.00/Yr.