RMF/ ISSO Lead
FEDITCAbout the role
Job Details
Level ExperiencedJob Location Washington DC - U.S. Government Publishing Office (GPO) - Washington, DCRemote Type HybridPosition Type Full TimeEducation Level 4 Year DegreeSalary Range $155000.00 - $169000.00 SalaryDescription
FEDITC, LLC is a fast-growing business supporting DoD and other intelligence agencies worldwide. FEDITC develops mission critical national security systems throughout the world directly supporting the Warfighter, DoD Leadership, & the country. We are proud & honored to provide these services.
Overview of position:
FEDITC is seeking an experienced, RMF/ ISSO Lead to support IT Security staff augmentation to develop plans to assess current cybersecurity state and develop processes for a fully implemented Zero Trust Architecture ZTA. In accordance with Executive Order (EO) 14028 (3)(b)(ii), plan to implement ZTA to strengthen the Cyber Hygiene and Security Posture for the Government Publishing Office (GPO).
This is an upcoming opportunity with a projected start date of 1 September 2025.
A United States Citizenship and Background Investigation NAC initiated is required to be considered for this position.
Responsibilities:
Preparation of Task Order Management Plans, cost analyses, activity and project tracking schedules, risk registers, and risk and issue mitigation strategies for all GPO SOC activities. This task consists of:
- Plan, implement, upgrade, or monitor security measures for the protection of computer networks and information.
- Assess system vulnerabilities for security risks and propose and implement risk mitigation strategies.
- Ensure appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure.
- Respond to computer security breaches and viruses.
- Year-round tracking, reporting, and providing recommendations on Plan of Action & Milestones (POA&Ms)
- Maintenance of Federal Information Security Modernization Act (FISMA) inventory records in Xacta360 app/tool
Qualifications
Experience/Skills:
Must possess a blend of technical cybersecurity skills, Microsoft Sentinel expertise, program/project management experience, and real-time security operations knowledge.
- Minimum 3+ working with Microsoft Cloud environments Government Community Cloud GCC-H/GCC.
- Demonstrated experience with the NIST Risk Management Framework (RMF) lifecycle:
- Categorization → Selection → Implementation → Assessment → Authorization → Monitoring
- Proven ability to develop or maintain System Security Plans (SSPs), Support Security Authorization Packages, Lead Security Control Assessments (SCA), Manage Plans of Action & Milestones (POA&Ms)
- Experience maintaining security documentation and FISMA inventory
- Familiarity with OMB A-130, FIPS 199/200, and NIST SP 800 series:
- Experience in Security Incident, Detection and Response
- Experience using tools such as Xacta360, Nessus, Qualys, Splunk, Sentinel, and Microsoft Defender
Education:
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or Engineering. Master’s degree preferred
Certifications:
- CAP (Certified Authorization Professional)
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- Security+ or CySA+
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s