Role: Senior RMF Specialist/Information System Security Officer (ISSO)
Location: Rock Island Arsenal, IL
Education/Certifications: Current IAT Level II industry certification required (e.g., Security+, CCNA, RHCSA, MCSA, etc.)
Years of Experience: 5+ years RMF experience
Clearance Level & Investigation: TS/SCI
IA Cert Level (DoD 8570.01): IAT Level II
Job Description: The System Security Officer / Senior RMF Specialist / ISSO is responsible for guiding IT systems through the entire Risk Management Framework (RMF) lifecycle to achieve and maintain the Authority to Operate (ATO).
Responsibilities:
- RMF Execution:
- Lead all aspects of the RMF process, from system categorization and security control selection to implementation and assessment.
- Security Documentation:
- Develop, maintain, and update all required RMF documentation, including the System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action & Milestones (POA&M).
- eMASS Management:
- Manage the system’s security posture within the Enterprise Mission Assurance Support System (eMASS), ensuring all data is accurate and up to date.
- Continuous Monitoring:
- Implement and manage a robust continuous monitoring strategy to actively assess security control effectiveness, track vulnerabilities, and manage configuration changes.
- Stakeholder Coordination:
- Serve as the primary security advisor to the system owner and liaise with the Authorizing Official (AO) and other key stakeholders to ensure a clear understanding of system risks and compliance status.
Qualifications:
The System Security Officer / Senior RMF Specialist / ISSO must have the following minimum qualifications for eligibility:
- Experience:
- Requires a minimum 5+ years of hands-on experience dedicated to applying RMF to complex DoD IT systems.
- Certifications:
- Must possess at a minimum current IAT level II, industry-standard certifications relevant to specific duties (e.g., CompTIA Security+, CCNA, RHCSA, MCSA).
- Certifications must meet DoD 8570/8140 requirements for their assigned role.
- Technical Skills:
- Demonstrated mastery of eMASS, vulnerability scanning tools (e.g., ACAS/Nessus), COMSEC, and security compliance checkers (e.g., SCAP).
- Clearance:
- Must possess and maintain a Top Secret/SCI security clearance.
- Must be U.S. citizen.