COLSA Corporation

RMF Information System Security Officer (ISSO)

COLSA Corporation$95K — $115K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Cybersecurity, Information Technology, or related field, or equivalent experience
  • At least 8 years of experience in cybersecurity supporting DoD RMF and A&A activities
  • Proficient in developing RMF authorization packages, SSPs, SARs, and POA&Ms
  • Experience with security control implementation, vulnerability management, and STIGs
  • Strong communication skills to present technical findings effectively
  • Must possess an active Secret security clearance and be a US Citizen

Responsibilities

  • Oversee the completion of A&A packages within 120 days of ATO expiration
  • Inform stakeholders about risk, status, and responsibilities during RMF processes
  • Assist information owners with System Registration in Compliance and Authorization Support Tool
  • Assist in System Categorization based on input from information owners
  • Support information owners in selecting security controls and defining defense levels
  • Provide information owners with security control outputs for Implementation Details
  • Review security control implementations to obtain validator approval
  • Guide the creation of System Security Plans that define assessment objectives
  • Collaborate with ISSM and Government RMF ISSO for initial security control assessments
  • Develop and manage a project plan and POA&M to address vulnerabilities
  • Monitor networks for security breach events and potential compromises
  • Audit adherence to information security policies and recommended best practices
  • Conduct compliance audits and vulnerability assessments
  • Lead response to security anomalies in line with standards

Benefits

  • Health, dental, and vision insurance
  • 401(k) retirement plan
  • Paid time off and holidays
  • Professional development opportunities
  • Flexible work schedule
Full Job Description
Job Description

COLSA is seeking an experienced RMF Information System Security Officer (ISSO) to join our team and play a critical role in supporting cybersecurity and Risk Management Framework (RMF) activities. This position will provide expertise throughout the RMF authorization process, including developing and maintaining RMF Assessment and Authorization (A&A) packages, guiding information owners through RMF requirements, supporting security control assessments, and managing vulnerability and remediation activities. The RMF ISSO will work closely with ISSMs, Government RMF ISSOs, information owners, validators, and other stakeholders to support system authorization and maintain the security posture of assigned information systems.

This position is contingent upon contract award, with work anticipated to begin in March 2027. The selected candidate will be proposed as Key Personnel in accordance with proposal requirements.
  • Completes authorization and assessment packages within 120 days of system ATO expiration.
  • Ensures stakeholders are kept informed of risk, status, and roles and responsibilities throughout the RMF process
  • Guides information owners through completion of Step 0 System Registration in Compliance and Authorization Support Tool
  • Guides information owners through Step 1, System Categorization, based on information provided by the information owner
  • Guides information owners through Step 2, select security controls, and determining appropriate defense level and appropriate overlays
  • Provides information owner with an export of selected security controls and applied overlays to populate the Implementation Details
  • Reviews completed security control implementation details and gain validator approval
  • Guides information owners in the development of a System Security Plan (SSP) that addresses objectives for the assessment, methods for verifying security control compliance, the schedule for the initial control assessment, and actual assessment procedures
  • Works with ISSM and lead Government RMF ISSO to conduct the initial assessment of the effectiveness of the security controls and document the issues, findings, and recommendations in a Security Assessment Report (SAR)
  • Develops a project plan and Plan of Action and Milestones (POA&M) for the RMF package that addresses all un-remediated vulnerabilities, failed Security Technical Implementation Guideline (STIG) failures and failed security controls
  • Works the POA&M, to include updating the POA&M at least monthly for the life cycle of the IS using the latest vulnerability scans and STIG checklists
  • Monitors the network and supporting systems to detect security compromise events (including intrusions and virus incidents).
  • Identifies where systems/networks deviate from acceptable configurations, enclave policy, or local policy.
  • Conducts audits to ensure information systems security policies and procedures are implemented as defined in security plans and best practices.
  • Performs evaluations (compliance audits) and/or active evaluations (vulnerability assessments).
  • Leads response teams to ensure any anomalies are corrected in accordance with government or industry standards.

Required Experience

  • Bachelor's Degree (or higher) in Cybersecurity, Information Technology, or a related field or equivalent experience
  • Minimum of eight (8) years of related work experience, including experience supporting DoD Risk Management Framework (RMF) and Assessment and Authorization (A&A) activities
  • Experience developing and maintaining RMF authorization packages, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms)
  • Experience with security control implementation and assessment, vulnerability management, and Security Technical Implementation Guides (STIGs)
  • Ability to clearly present and communicate technical approaches and findings
  • Active Secret security clearance; US Citizenship required;

Preferred Qualifications
  • DoD 8570/8140-compliant certification such as Security+, CGRC (formerly CAP), or equivalent

Applicant selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

About COLSA Corporation

COLSA Corporation is a technology services and solutions provider primarily serving the U.S. government and defense industry. The company offers a range of services including engineering, program management, cyber security, and information technology. COLSA Corporation was founded in 1980 and is headquartered in Huntsville, Alabama.
Learn more about COLSA Corporation
Size
2,000 employees
Industry

Similar Jobs

More Jobs at COLSA Corporation

More Information Technology Jobs

Find similar RMF Information System Security Officer (ISSO) jobs: