CybersecurityJobs.io
← Back to all jobs

Job Description

Context: The ISSO Senior Analyst role supports federal systems across the NIST RMF lifecycle by owning authorization workstreams and delivering security control assessment documentation.

Responsibilities

  • Own RMF delivery workstream for assigned systems by maintaining security posture documentation and supporting system owners and government ISSMs throughout the authorization lifecycle.
  • Use NIST SP 800-53A assessment procedures alongside NIST SP 800-53 controls and applicable overlays to select examination, interview, and test methods, judge evidence sufficiency, and document objective results with traceability from implementation statements to architecture and evidence.
  • Develop and maintain core authorization artifacts, including System Security Plans, Security Assessment Plans, Security Assessment Reports, control implementation statements, and supporting appendices.
  • Perform analysis for information types and impact analysis, including FIPS 199 categorization and NIST SP 800-60 mapping; identify stakeholders and roles; document authorization boundary rationale and risk context.
  • Define and document system boundary information and authorization boundaries, component inventories, data flows, interconnections, and inherited or shared controls.
  • Determine control baseline selection, tailoring, overlays, scoping, parameter assignment, compensating controls, and common-control inheritance based on system architecture and hosting model.
  • Draft findings and create POA&M items linking condition and evidence to control requirements, including threat and vulnerability context, likelihood, impact, recommended action, and acceptance criteria.
  • Manage POA&M execution for assigned systems, including remediation tracking, evidence validation, closure packages, and deviation or risk acceptance documentation.
  • Execute NIST 800-137 continuous monitoring and event-driven monitoring activities, including control review cycles, vulnerability management reporting, configuration compliance tracking, and monthly reporting deliverables.
  • Conduct security impact analyses for proposed changes and document results for system owner review.
  • Review scan results and STIG or CIS benchmark results; validate findings, distinguish false positives, and connect technical evidence to NIST controls.
  • Maintain accurate system records and authorization artifacts in governance, risk, and compliance tools such as eMASS, JCAM, and Xacta.
  • Facilitate evidence-gathering sessions and control interviews with system owners, engineers, and application teams.
  • Coordinate assigned workstreams, review Analyst deliverables for quality and consistency, provide task-level guidance, manage dependencies, and escalate risk.
  • Track delivery commitments, monitor schedule and quality risks, and escalate issues to engagement leadership.
  • Provide day-to-day coaching to Analysts on assessment procedures, evidence expectations, and documentation standards.
  • Review Analyst work products for accuracy, completeness, and consistency before submission; provide specific, actionable feedback.
  • Use knowledge of cybersecurity industry trends to identify engagement and client service issues and communicate through written correspondence and verbal presentations.
  • Stay current on cybersecurity industry trends relevant to delivered services.

Requirements

  • Bachelor’s degree in cybersecurity, information technology, information systems, computer science, engineering, business, or related field.
  • Minimum 3 years of related work experience in cybersecurity, technology risk, compliance, or information technology, including hands-on federal RMF support.
  • Ability to obtain and maintain a secret level clearance.
  • Comfortable working in a hybrid setting.
  • Experience developing or maintaining RMF documentation, collecting and organizing control evidence, supporting assessment readiness, tracking POA&Ms, or executing continuous monitoring activities.
  • Experience in one or more areas such as:
    • Federal authorization package development and maintenance.
    • NIST SP 800-53 control implementation statements and evidence mapping.
    • Security control assessment preparation and response coordination.
    • POA&M tracking, remediation support, or continuous monitoring reporting.
    • Federal governance, risk, and compliance tools such as eMASS, JCAM, CSAM, or Xacta.
    • Technical security artifacts such as network diagrams, inventories, vulnerability scans, STIG or CIS benchmark results, change records, or configuration data.
  • Flexibility to travel up to 20%.

Technologies

  • NIST CSF
  • NIST 800-53r5
  • NIST 800-37r2
  • NIST SP 800-53A
  • NIST SP 800-53
  • NIST SP 800-60
  • NIST SP 800-30
  • NIST SP 800-137
  • FIPS 199
  • FISMA
  • eMASS
  • JCAM
  • Xacta
  • CSAM
  • STIG
  • CIS
  • FISMA and relevant agency-specific policies

Ideally, You’ll Also Have

  • CISSP, CISM, CISA, CGRC, CIPT, CIPM, CIPP, CRISC, or other relevant certification.
  • Prior experience supporting a federal agency, consulting engagement, service delivery center, or managed service.

Skills and Attributes for Success

  • Applied knowledge of federal security frameworks and standards including NIST SP 800-37, 800-53/53A, 800-60, 800-30, 800-137, FIPS 199/200, FISMA, and relevant agency-specific policies.
  • Applied knowledge of the NIST Risk Management Framework and security control assessment methodology.
  • Ability to analyze technical information and translate it into clear control documentation.
  • Ability to manage multiple systems or workstreams concurrently.
  • Ability to review work products for quality and consistency.
  • Clear communication with technical stakeholders and engagement leadership.

Location: San Antonio, TX (hybrid)

Similar Jobs