Supports RMF and ISSO activities across DoD enterprise systems, managing eMASS registrations, security plans, ATO sustainment, continuous monitoring, STIG compliance, vulnerability assessments, system categorization, and POA&M remediation. Analyzes ACAS and SCAP results, coordinates technical stakeholders, provides cybersecurity risk guidance and status reporting, and maintains audit-ready security artifacts and procedures.
SAIC is seeking a Risk Management Framework (RMF) Analyst for an Information Systems Security Officer (ISSO) position supporting the RMF requirements of the North American Aerospace Defense Command and United States Northern Command (NORAD/USNORTHCOM) Information Technology (IT) Enterprise Services (NITES) contract. The primary work location is onsite in Colorado Springs.
Responsibilities:
- Supporting and executing the RMF process across multiple enterprise systems and enclaves by maintaining system registrations, security baselines, and evidentiary records within the Enterprise Mission Assurance Support Service (eMASS).
- Operating with ISSO-level ownership to independently drive continuous monitoring and Authority to Operate (ATO) sustainment, ensuring an uninterrupted and robust security posture.
- Ensuring cybersecurity standards and operational hygiene are consistently maintained to support a Cyber Operational Readiness Assessment (CORA)-ready posture.
- Managing the continuous cybersecurity posture of enterprise systems and identifying mitigations necessary to meet Department of Defense Directive (DoDD) 8500.01, Department of Defense Instruction (DoDI) 8510.01, DoDD 8140.01, and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 requirements.
- Analyzing and correlating scan results from the Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP), and other approved tools to evaluate system risk, determine security posture, and maintain ATO and Assess Only authorizations.
- Assisting with system categorization in accordance with Committee on National Security Systems Instruction (CNSSI) 1253, including confidentiality, integrity, and availability impact levels, as information types, mission profiles, and system interconnections evolve.
- Leading the development, maintenance, and technical validation of System Security Plans (SSPs), ensuring evidentiary artifacts accurately reflect current technical architectures and that applicable Security Technical Implementation Guides (STIGs) are implemented.
- Exercising end-to-end ownership of Plans of Action and Milestones (POA&Ms) by systematically evaluating deficiencies, determining risk impacts, and coordinating with technical stakeholders to drive findings to timely closure.
- Collaborating proactively with system administrators, network engineers, and leadership to remediate STIG findings, vulnerability scan results, and architectural deficiencies.
- Providing strategic cybersecurity guidance, risk assessments, and status updates to system owners and leadership.
- Providing weekly status reports that summarize accomplishments across assigned packages, risk posture, issues, and paths forward.
- Creating, refining, and enforcing the operational policies, procedures, and artifacts necessary to ensure security controls are fully implemented and audit-ready.
Required Qualifications:
- Certification required in accordance with DoD Manual (DoDM) 8140.03 at the Intermediate level, such as CompTIA Security+ or an equivalent certification.
- Bachelor’s degree in information assurance, cybersecurity, or a related field, plus 3–5 years of relevant experience; or a high school diploma or equivalent plus 7–10 years of relevant information assurance or cybersecurity experience.
- At least 2 years of direct experience serving as an ISSO or cybersecurity practitioner supporting DoD systems, including:
- Direct experience managing RMF lifecycle artifacts and end-to-end eMASS package management across multiple concurrent systems.
- Proven experience authoring, tracking, and coordinating technical remediation to drive POA&Ms to validated completion.
- Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.
- Demonstrated ability to operate with a high degree of autonomy, self-direct work, and lead cross-functional technical teams through complex authorization lifecycles.
Desired Qualifications:
- Ability to work effectively in a team-focused, dynamic, high-tempo operational environment.
- Experience using STIG Viewer and automated compliance tools.
- Prior experience participating in Change Advisory Boards (CABs).
We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.
Spectrum San Diego Alamosa, Colorado, USA Office
Alamosa, United States
Spectrum San Diego Broomfield, Colorado, USA Office
Broomfield, United States
Spectrum San Diego Centennial, Colorado, USA Office
Centennial, United States
Spectrum San Diego Denver, Colorado, USA Office
Denver, United States
Spectrum San Diego Englewood, Colorado, USA Office
Englewood, United States
Spectrum San Diego Greenwood Village, Colorado, USA Office
Greenwood Village, United States
Similar Jobs
Fintech • HR Tech
Leads enterprise-wide People Operations process transformation, HRIS Operations, and People Services. Develops strategies, redesigns employee lifecycle workflows, drives automation and AI-enabled improvements, establishes governance and metrics, improves HR service delivery, and manages cross-functional teams. Partners with HR, Finance, Legal, IT, Security, and business leaders to deliver scalable, compliant, data-driven operational improvements.
Top Skills:
AICase Management PlatformsHrisSystem IntegrationsWorkdayWorkflow Automation
Fintech • HR Tech
Investigate partner- and API-originated fraud and ACH risk cases, validate AI-generated decisions, manage operational queues, identify suspicious patterns, and mitigate risk while minimizing legitimate partner friction. The analyst will handle complex escalations, document AI feedback, improve workflows with automation, collaborate with risk, product, engineering, and partners, and provide subject-matter expertise for embedded payroll risk operations.
Top Skills:
APIsClaudeGeminiGenerative AiSQL
Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Leads payer back-office strategy, technology, and operations consulting engagements for health services clients. Responsibilities include modernizing payer operations, optimizing processes, analyzing business data, managing change, improving service delivery models, coaching teams, engaging stakeholders, and validating quality and compliance outcomes. The role leads large projects and develops strategic recommendations for operational excellence.
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute


