ISSO/RMF Engineer - 174936
REMOTE, Remote
Job Id:
0000174936
Job Category:
Information Technology
Job Location:
REMOTE, Remote
Security Clearance:
Secret
Business Unit:
Zachary Piper
Division:
Not Defined
Position Owner:
Cameron Bagwell
Zachary Piper Solutions is hiring for an Information Systems Security Officer (ISSO) / RMF Engineer to support a growing federal technology organization focused on accelerating the secure deployment of modern software and cloud applications across regulated government environments. This is a REMOTE position supporting a rapidly growing federal delivery organization responsible for security authorization, RMF execution, control implementation, and ATO readiness for modern SaaS, cloud, containerized, and platform-based applications. The ISSO / RMF Engineer will support customers through the federal authorization process, translating technical architectures and security implementations into RMF, NIST, and eMASS requirements. This individual will work directly with application teams, system owners, security stakeholders, and government assessors to develop and maintain security documentation, populate eMASS, interpret security controls, address findings, and drive systems toward ATO. The ideal candidate combines hands-on RMF/eMASS expertise with enough technical depth to understand modern cloud, Kubernetes, containerized applications, APIs, identity services, and infrastructure rather than simply applying compliance requirements without understanding the underlying technology.
This is an opportunity for a technically curious security professional to join a growing organization where they can help modernize and automate the RMF process, improve security delivery workflows, and contribute to solutions that reduce the barriers between commercial technology and government users.
Responsibilities of the ISSO / RMF Engineer
- Execute and support Risk Management Framework (RMF) activities from system categorization through ATO and ongoing continuous monitoring
- Create, maintain, and populate eMASS records, including security controls, implementation statements, artifacts, evidence, and supporting documentation
- Translate technical implementations into clear NIST/RMF security control language for government customers and assessors
- Guide customers and system owners through RMF requirements, particularly organizations that have limited prior federal authorization experience
- Support system categorization, control selection, control implementation, assessment, remediation, and ATO activities
- Develop and maintain high-quality security evidence and documentation supporting authorization packages
- Review security findings and scan results, determine applicability, and work with technical teams to develop appropriate remediation or response
- Support Control Allocation Worksheets (CAWs), overlays, tailored control sets, and shared responsibility models
- Apply knowledge of NIST SP 800-53, NIST SP 800-60, RMF, FedRAMP, DoD security requirements, and cloud security frameworks to modern technology environments
- Understand and apply Cloud Computing Security Requirements Guide (CC SRG) concepts and DoD impact levels as they relate to cloud-based systems
- Work with modern technical environments including cloud platforms, Kubernetes, containerized applications, APIs, and federated identity services
- Support Data Sharing Agreements, Authorities to Connect (ATCs), and related security authorization documentation
- Interface directly with system owners, application teams, security personnel, and government security stakeholders to explain security requirements and implementation decisions
- Work through disagreements or questions with Security Control Assessors (SCAs) and provide clear technical justification for security implementations
- Help customers understand how their technical architecture and operational processes map to security controls and authorization requirements
- Identify opportunities to automate repetitive RMF and security documentation activities and contribute to improved security delivery processes
- Leverage APIs, automation, and emerging technologies to reduce manual security and compliance workloads
- Operate independently, identify obstacles quickly, and proactively develop solutions rather than requiring step-by-step direction
- Contribute to the development of repeatable RMF processes, security playbooks, and best practices as the federal delivery organization scales
- Work remotely with occasional, pre-planned travel for team working sessions or onsite collaboration
Qualifications of the ISSO / RMF Engineer
- 3–5+ years of experience in information systems security, cybersecurity, ISSO, RMF, security engineering, or a related field
- Active Secret clearance and CAC required - Top Secret Clearance preferred
- Strong hands-on experience with RMF and eMASS; candidates should be able to contribute immediately without requiring extensive RMF training
- Demonstrated experience supporting systems through significant portions of the RMF lifecycle and ATO process
- Strong understanding of NIST SP 800-53, NIST SP 800-60, RMF, security controls, control implementation, and authorization requirements
- Experience creating, reviewing, and uploading security artifacts and control evidence in eMASS
- Ability to understand technical environments and translate technical implementations into security and compliance requirements
- Experience with cloud, SaaS, PaaS, containerized applications, Kubernetes, APIs, identity services, or modern enterprise infrastructure
- Understanding of DoD cloud security requirements, CC SRG, impact levels, and shared responsibility/control inheritance models
- Experience supporting system categorization, control selection, control allocation, overlays, CAWs, or similar RMF activities
- Experience working with Security Control Assessors (SCAs) and/or supporting assessment and remediation activities
- Ability to guide technical personnel, application teams, and system owners who may have limited familiarity with federal RMF requirements
- Strong written and verbal communication skills with the ability to translate complex technical and regulatory concepts for different audiences
- Highly self-directed and execution-oriented, with the ability to take ownership of an assignment and execute with limited oversight
- Demonstrated ability to identify process inefficiencies and recommend smarter, faster, or more automated approaches
- Technical background in IT, systems administration, networking, cloud, software, or cybersecurity strongly preferred
- Experience supporting federal, DoD, defense, or other government environments strongly preferred
- Experience working for a federal contractor, defense organization, or military environment preferred
Compensation to include:
Salary Range: $145,000 – $155,000+ (depending on experience)
Full Benefits: Medical, Dental, Vision, 401K, PTO, Sick Leave if Required by Law
This job opens for applications on September 23, 2026. Applications for this job will be accepted for at least 30 days from the posting date.
#LI-CB1
#LI-REMOTE
Keywords: Cybersecurity, ISSO, ATO, Assessment and Authorization, Risk Management Framework, RMF, NIST, FISMA, DOE, NNSA, Compliance, POA&M, Vulnerability Management, Incident Response, Security Documentation, System Security Plans, Continuous Monitoring, Cyber Risk Assessment, Federal Security, Information Assurance, Security Operations, Policy Development, Threat Mitigation, Authorization to Operate, top secret, software, network, infrastructure, cloud, AWS