Isys Technologies

RMF Analyst

Isys Technologies$100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • DoD 8140.03 Intermediate level certification like CompTIA Security+ required.
  • Bachelor's degree in information assurance, cybersecurity, or related field with 3-5 years of experience; or high school diploma with 7-10 years of relevant experience.
  • Minimum of 2 years experience as an ISSO or cybersecurity practitioner for DoD systems.
  • Experience managing RMF lifecycle artifacts and eMASS package management for multiple systems.
  • Proven track record in authoring and tracking POA&Ms to completion.
  • High degree of autonomy and capability to lead cross-functional teams through authorization lifecycles.

Responsibilities

  • Support and execute RMF processes across enterprise systems via eMASS.
  • Drive continuous monitoring and maintain Authority to Operate (ATO) status.
  • Ensure consistent adherence to cybersecurity standards and readiness assessments.
  • Manage cybersecurity posture to align with DoD and NIST guidelines.
  • Analyze security scan results to evaluate system risk and maintain authorizations.
  • Lead development and validation of System Security Plans (SSPs) and related artifacts.
  • Collaborate with technical teams to remediate findings and improve security posture.

Benefits

  • Opportunity to work on-site in a dynamic environment in Colorado Springs, CO.
  • Engagement with a high-tempo operational team focused on national security.
  • Privileged access to top-tier cybersecurity practices in the DoD realm.
  • Development of skills managing complex RMF lifecycle processes across multiple systems.
  • Collaborative environment with regular interaction with leadership and technical stakeholders.
Full Job Description
Minimum Clearance Required
Top Secret SCI Responsibilities

I2X Technologies is seeking an RMF Analyst to support ongoing activities for a customer in Colorado Springs, CO. This position will be on-site and will require an active TS/SCI. 

  • Supporting and executing the RMF process across multiple enterprise systems and enclaves by maintaining system registrations, security baselines, and evidentiary records within the Enterprise Mission Assurance Support Service (eMASS).
  • Operating with ISSO-level ownership to independently drive continuous monitoring and Authority to Operate (ATO) sustainment, ensuring an uninterrupted and robust security posture.
  • Ensuring cybersecurity standards and operational hygiene are consistently maintained to support a Cyber Operational Readiness Assessment (CORA)-ready posture.
  • Managing the continuous cybersecurity posture of enterprise systems and identifying mitigations necessary to meet Department of Defense Directive (DoDD) 8500.01, Department of Defense Instruction (DoDI) 8510.01, DoDD 8140.01, and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 requirements.
  • Analyzing and correlating scan results from the Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP), and other approved tools to evaluate system risk, determine security posture, and maintain ATO and Assess Only authorizations.
  • Assisting with system categorization in accordance with Committee on National Security Systems Instruction (CNSSI) 1253, including confidentiality, integrity, and availability impact levels, as information types, mission profiles, and system interconnections evolve.
  • Leading the development, maintenance, and technical validation of System Security Plans (SSPs), ensuring evidentiary artifacts accurately reflect current technical architectures and that applicable Security Technical Implementation Guides (STIGs) are implemented.
  • Exercising end-to-end ownership of Plans of Action and Milestones (POA&Ms) by systematically evaluating deficiencies, determining risk impacts, and coordinating with technical stakeholders to drive findings to timely closure.
  • Collaborating proactively with system administrators, network engineers, and leadership to remediate STIG findings, vulnerability scan results, and architectural deficiencies.
  • Providing strategic cybersecurity guidance, risk assessments, and status updates to system owners and leadership.
  • Providing weekly status reports that summarize accomplishments across assigned packages, risk posture, issues, and paths forward.
  • Creating, refining, and enforcing the operational policies, procedures, and artifacts necessary to ensure security controls are fully implemented and audit-ready.
Qualifications
  • Certification required in accordance with DoD Manual (DoDM) 8140.03 at the Intermediate level, such as CompTIA Security+ or an equivalent certification.
  • Bachelor’s degree in information assurance, cybersecurity, or a related field, plus 3–5 years of relevant experience; or a high school diploma or equivalent plus 7–10 years of relevant information assurance or cybersecurity experience.
  • At least 2 years of direct experience serving as an ISSO or cybersecurity practitioner supporting DoD systems, including:
  • Direct experience managing RMF lifecycle artifacts and end-to-end eMASS package management across multiple concurrent systems.
  • Proven experience authoring, tracking, and coordinating technical remediation to drive POA&Ms to validated completion.
  • Demonstrated ability to operate with a high degree of autonomy, self-direct work, and lead cross-functional technical teams through complex authorization lifecycles.

Desired Experience and Skills

  • Ability to work effectively in a team-focused, dynamic, high-tempo operational environment.
  • Experience using STIG Viewer and automated compliance tools.
  • Prior experience participating in Change Advisory Boards (CABs).

Essential Requirements:

  • US Citizenship is required
  • Active TS/SCI clearance is required

 

Additional Information:In compliance with Colorado’s Equal Pay for Equal Work Act, the annual base salary range for this position is listed. Please note that the salary information is a general guideline only. I2X Technologies considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer.

 

Physical Demands:

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job with or without reasonable accommodation.

 

While performing the duties of this job, the employee will regularly sit, walk, stand and climb stairs and steps. May require walking long distance from parking to work station. Occasionally, movement that requires twisting at the neck and/or trunk more than the average person, squatting/ stooping/kneeling, reaching above the head, and forward motion will be required. The employee will continuously be required to repeat the same hand, arm, or finger motion many times. Manual and finger dexterity are essential to this position. Specific vision abilities required by this job include close, distance, depth perception and telling differences among colors. The employee must be able to communicate through speech with clients and public. Hearing requirements include conversation in both quiet and noisy environments. Lifting may require floor to waist, waist to shoulder, or shoulder to overhead movement of up to 20 pounds. This position demands tolerance for various levels of mental stress.

 

About Isys Technologies

ISYS Technologies is an information technology services company that provides engineering, integration, and sustainment services to government and commercial clients. ISYS Technologies is headquartered in Colorado and has offices in Virginia, Maryland, and Washington. ISYS Technologies' services include systems engineering, software development, cybersecurity, and data analytics. ISYS Technologies' clients come from a variety of industries, including aerospace, defense, and intelligence. ISYS Technologies was founded in 2004 and has grown to become one of the fastest-growing companies in the United States.
Learn more about Isys Technologies
Size
650 employees
Industry
Net Income
$5 million
Founded
2004
5 Year Trend
+50%
Revenue
$100 million

Similar Jobs

More Jobs at Isys Technologies

More Information Technology Jobs

Find similar RMF Analyst jobs: