View all jobs

RMF Lead

Aberdeen, MD · Government/Military
Founded in 2009, RSC2, Inc. is a Small Business Administration (SBA) Certified HUBZone Professional Services company headquartered in Baltimore, Maryland. RSC2 provides breakthrough expertise, support services, and technologies to make operations, programs and systems of record perform better. Our professional staff is trained to provide world-class services to all types of customers. We uphold the integrity and quality of our work so you can expect only the best from us.

We are looking for a  RMF Lead/ISSO to join our growing company! This role is located at Aberdeen Proving Ground, MD.

Information Systems Security Officer (ISSO) candidate to support Government customer in the APG, Maryland area. The candidate will be responsible for ensuring compliance with the ISSO Roles and Responsibilities as laid out in agency directives, instructions, and memos.

Duties and responsibilities include:
  • Perform tasks delegated by the ISSM in support of various information assurance /cybersecurity programs such as security authorization activities in compliance with Risk Management Framework (RMF) policies and procedures including System Security Plans (SSPs), Risk Assessment Reports, A&A packages, and Security Controls Traceability Matrix (SCTM)
  • Maintains operational security posture to ensure information systems (IS), security policies, standards, and procedures are established and followed
  • Performs vulnerability/risk assessment analysis to support Assessment & Authorization (A&A)
  • Review and analyze system audit logs to identify anomalous activity and potential threats to network resources
  • Conducting vulnerability scans and recognizing vulnerabilities in security systems
  • Ensure that cybersecurity-enabled products or other compensating security control technologies reduce identified risk to acceptable security levels
  • Apply a full range of Cybersecurity policies, principles, and techniques to maintain the security integrity of information systems processing classified information
  • Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk
  • Work with government customers to support computer security incidents and vulnerability compliance
  • Input and maintain system documentation into government record-keeping systems like Xacta and eMASS
  • Provide Configuration Management for security-relevant information system software, hardware, and firmware
  • Perform risk analysis whenever an application or system undergoes a major change
  • Provide input to the Risk Management Framework process activities and related documentation

Required Qualifications:
  • Must be a US Citizen
  • Active security clearance
  • Experience considered in lieu of degree
  • A minimum of 5 years of experience as an IA/Security Specialist and OMB Information Security directives/policy compliance
  • Must hold active Security+, CISSP, CISA, or equivalent certifications (DoD 8570 IAM 2 equivalent)
  • At least 5 years of direct experience and in-depth working knowledge of FISMA and NIST Information Security Guides
  • Advanced written and verbal communication skills
Desired Qualifications:
  • Experience with effective policy, instruction, and development for Federal or DoD Information Security Programs
  • Experience with performing Security Control Assessment in compliance with NIST SP 800- 37, NIST SP 800-53, NIST SP 800-53A, and other NIST 800 guides
  • Experience with risk analysis and assessment determinations
  • Experience with eMASS
  • Experience with Xacta
  • Current CI polygraph


Share This Job

Powered by