RMF Cybersecurity ISSO/SME 3
Core
Lead Assessment & Authorization (A&A) activities and guide systems through the RMF lifecycle to achieve and maintain Authorizations to Operate (ATOs) for mission-critical medical systems.
Role type
Senior IC Information System Security Officer (ISSO)
Builds
Production security compliance packages and ATOs for healthcare systems
Domain
Defense Health Agency (DHA) / Cybersecurity / Risk Management Framework
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
RMF lifecycle management, NIST SP 800-53 control assessment, security plan development, POA&M creation, risk assessment reporting, stakeholder coordination, security policy drafting
Preferred skills
eMASS compliance tracking, DHA RMF process experience, ACAS familiarity, DISA STIGs/SRGs knowledge, Continuous Monitoring and Risk Scoring (CMRS), Integrated Master Schedules (IMS) planning
Technologies
Microsoft Office (Word, PowerPoint, Excel, SharePoint), eMASS, STIG Viewer, SCAP Compliance Checker, Microsoft Project
Responsibilities
Manage information systems through the full six-step RMF lifecycle, Serve as an RMF Subject Matter Expert advising on compliance and risk posture, Develop and maintain RMF packages including Security Plans and POA&Ms, Assess system compliance against NIST SP 800-53 controls, Document evidence supporting control implementation, Lead A&A and stakeholder meetings, Prepare status reports for leadership
Seniority
Senior, hands-on IC