KBR, formerly a subsidiary of Halliburton, is a company in defense and space, offering services in technology, engineering, procurement, and construction on a global scale. Since i
RMF Cybersecurity ISSO/SME 3
Location
United States
Posted
53 days ago
Salary
$107K - $161K / year
Seniority
Mid Level
Job Description
RMF Cybersecurity ISSO/SME 3
KBR
Title: RMF Cybersecurity ISSO/SME 3 Program Summary: KBR’s Mission Engineering Division delivers complex technical solutions and expert support to the U.S. Department of War, specializing in modeling and simulation, cyber transformation, air vehicle mission integration, and lifecycle support. As a trusted partner with a proven history in mission technology, KBR collaborates closely with clients to develop innovative and effective solutions. With a strong ethical framework, KBR prioritizes data security, privacy, and responsible information management to ensure mission success. Job Summary: KBR is seeking a Cybersecurity Risk Management Framework (RMF) Information System Security Officer (ISSO) to support the DHA Solution Delivery Division (SDD). In this role, you will lead Assessment & Authorization (A&A) activities and guide systems through the RMF lifecycle to achieve and maintain Authorizations to Operate (ATOs) for mission-critical medical systems. You will work closely with engineers, developers, and government stakeholders to ensure compliance with NIST, DoD, and DHA cybersecurity requirements while supporting continuous monitoring and risk management efforts. This 100% remote position requires availability during standard Eastern Time (ET) day shift hours. Join KBR to contribute directly to protecting critical healthcare systems supporting warfighters and their families. Roles and Responsibilities: - Manage one or more information systems throughout the full six-step RMF lifecycle, including assessment, authorization, and continuous monitoring activities - Serve as an RMF Subject Matter Expert (SME), advising stakeholders on cybersecurity compliance, risk posture, and ATO readiness - Develop, review, and maintain RMF packages and associated documentation, including Security Plans, POA&Ms, Risk Assessment Reports, and security control policies - Assess system compliance against NIST SP 800-53 controls and DHA RMF requirements as part of self-assessment and annual reviews - Document and maintain evidence supporting control implementation and compliance - Lead and participate in A&A and stakeholder meetings to track system status, resolve issues, and drive RMF progress - Coordinate with engineers and system owners to develop architecture diagrams, system asset inventories, and security policies - Prepare and deliver status reports to DHA leadership on system authorization and compliance efforts Basic Qualifications: - Active DoD Secret security clearance - Bachelor’s degree in cybersecurity, information technology, or related field with 6+ years of experience; or 14+ years of relevant cybersecurity/IT experience in lieu of degree. - DoD Manual 8140.03 (formerly 8570.01)-compliant certification (e.g., Security+, CISSP, CASP+/SecurityX) - Demonstrated experience performing RMF activities as an ISSO/ISSM/SME, including ATO process support and RMF package development (Security Plans, POA&Ms, architecture diagrams, system security policies, etc.) - Demonstrated experience assessing and documenting NIST SP 800-53 controls - Experience using Microsoft Office applications: Word, PowerPoint, Excel, and SharePoint Preferred Qualifications: - Experience using eMASS or equivalent compliance-tracking application - Experience supporting RMF processes under DHA - Familiarity with ACAS and DISA STIGs/SRGs and tools such as STIG Viewer and SCAP Compliance Checker - Familiarity with Continuous Monitoring and Risk Scoring (CMRS) - Experience using Microsoft Project to build Integrated Master Schedules (IMS) Compensation: $107,600.00 - $161,400.00. The salary range posted is based on the national average. The offered rate will be based on the selected candidate’s location, knowledge, skills, abilities, and/or experience, contract affordability, and in consideration of internal parity. Benefits: KBR offers a selection of competitive lifestyle benefits which could include a 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development. Belong, Connect and Grow at KBR At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together. KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Pentest applications across our stack, identifying vulnerabilities in APIs, mobile apps (Android/iOS), and infrastructure before attackers do. • Plan and execute realistic attack campaigns: phishing with custom domains, social engineering, lateral movement, privilege escalation. Measure real organizational resilience, not checkbox compliance. • Engineer security platforms, scanning pipelines, and automation that multiply the team's impact. • Design and build LLM-powered agents that detect, classify, triage and fix vulnerabilities in real time.
Principal Product Researcher, Endpoint Security Posture Management
HuntressManaged endpoint protection, detection and response for the 99% who need it most.
Location: Remote US Reports to: Director of Product Research Compensation Range: $210,000 to $230,000 plus bonus and equity What We Do: Huntress is a fully remote, global team of passionate experts and ethical badasses on a mission to break down the barriers to cybersecurity. Whether creating purpose-built security solutions, hunting down hackers, or impacting our community, our people go above and beyond to change the security game and make a real difference. Founded in 2015 by former NSA cyber operators, Huntress protects all businesses—not just the 1%—with enterprise-grade, fully owned, and managed cybersecurity products at the price of an affordable SaaS application. The Huntress difference is our One Team advantage: our technology is designed with our industry-defining Security Operations Center (SOC) in mind and is never separated from our service. We protect 4M+ endpoints and 7M+ identities worldwide, elevating underresourced IT teams with protection that works as hard as they do. As long as hackers keep hacking, Huntress keeps hunting. Responsibilities: - Lead the security Capabilities we bring to market, owning the layered defense strategy gained by combining multiple data sources - Convert application and endpoint vulnerability research + findings into actionable preventive and remediation actions by generating security software engineering requirements - Translate CVE & vendor hardware/software vulnerability research into security product development - Reverse engineer operating system (OS) components to identify + action OS control mechanism opportunities for security product development - Research vulnerability management automation opportunities to scale patching + security fixes for all operating systems and applications across millions of endpoints - Report on health and security posture for millions of endpoints across tens of thousands of varied environments - Iterate high-impact security posture baselines that align security posture to reduce & remediate risk - Measure endpoint protection software solution effectiveness at reducing risk, closing security gaps & decreasing attacks/access - Design, architect, and build vulnerability management scanning infrastructure and tools - Research technical escalations for endpoint protection Capabilities - Expert experience in configuration management across endpoint platforms - including firewalls, application control, attack surface reduction, & vulnerability management solutions - Balance security with productivity, building an intentional alert strategy that empowers risk owners with security posture improvement opportunities that don’t create friction to business delivery - Leverage AI for security value research - Document research findings through technical write-ups, advisories, internal reports, and blogs. - Identify opportunities to improve existing product features and explore new ones based on feedback from partners, prospects, peers, and industry publications. - Coordinate with Security, Product, and Engineering teams to integrate and operationalize solutions you develop. - Own & nurture the cross-department relationships critical to successful product delivery & launch. - Proven organizational and program management skills, with keen attention to detail and a sense of urgency to deliver an exceptional product under tight deadline pressures. - Eagerness to engage, report, and be accountable to executive stakeholders. - Passion to translate your expertise in nontechnical ways to deliver impactful security outcomes that protect the 99%. - Promote Huntress’ reputation through media appearances, public speaking engagements, and blog posts. - Educate the public on how to be security savvy in novel and fun ways. What You Bring To The Team: - Expert experience in configuration management across endpoint platforms - including firewalls, application control, attack surface reduction, & vulnerability management solutions - Experience reverse engineering - Experience leveraging AI to generate security outcomes - Experience building AI agents for security research & innovation - Expert-level security engineering & vulnerability management skills + experience - Expert skills in performing security assessments, vulnerability testing, and risk analysis on endpoint devices - Demonstrated experience producing proofs of concept - Programming Skills (C/C++/Go) - Passion for the MSP community - Security conference presenter - Security community educator & advocate What We Offer: - 100% remote work environment - since our founding in 2015 - Generous paid time off policy, including vacation, sick time, and paid holidays - 12 weeks of paid parental leave - Highly competitive and comprehensive medical, dental, and vision benefits plans - 401(k) with a 5% contribution regardless of employee contribution - Life and Disability insurance plans - Stock options for all full-time employees - One-time $500 reimbursement for building/upgrading home office - Annual allowance for education and professional development assistance - $75 USD/month digital reimbursement - Access to the BetterUp platform for coaching, personal, and professional growth Huntress is committed to creating a culture of inclusivity where every single member of our team is valued, has a voice, and is empowered to come to work every day just as they are. We do not discriminate based on race, ethnicity, color, ancestry, national origin, religion, sex, sexual orientation, gender identity, disability, veteran status, genetic information, marital status, or any other legally protected status. We do discriminate against hackers who try to exploit businesses of all sizes. Accommodations: If you require reasonable accommodation to complete this application, interview, or pre-employment testing or participate in the employee selection process, please direct your inquiries to accommodations@huntresslabs.com. Please note that non-accommodation requests to this inbox will not receive a response. Huntress uses artificial intelligence tools to assist in reviewing and evaluating job applications, including resume screening, skills assessment, and candidate matching and comparisons. These AI tools support our human recruiters in the initial review process, but do not make final hiring decisions without human involvement. By submitting your application, you acknowledge this use of AI in our recruitment process. Please review our Candidate Privacy Notice for more details on our practices and your data privacy rights. #BI-Remote
Background Investigator
ConcentricConcentric is a risk consultancy specializing in delivering strategic security and intelligence services. We provide holistic, intelligent security solutions for private clients and corporations globally. Concentric offers strategic advisory services, risk assessments, physical protection, threat intelligence, open-source monitoring, program audits, secure embedded staffing, and training for security teams and intelligence analysts. Our ultimate goal is to be recognized as the most innovative, capable, and trusted Risk Management partner in the world, and we do this by following these core values: Integrity Collaboration Relationships Excellence Creativity Results Concentric and SPS Global acknowledge the systemic barriers in the security industry and recognize that removing those barriers will require a collaborative and conscious effort. Concentric and SPS Global are committed to programs and initiatives that promote diversity, equity, and inclusion, enhancing our organization and the broader community. We are creating a diverse environment and are proud to be an equal opportunity employer. We encourage people from all backgrounds to apply. All qualified applicants will receive consideration for employment regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. Concentric Advisors and SPS Global are committed to protecting the privacy and security of all applicants who submit personal information to us. You can access our GDPR and CCPA policy by clicking the GDPR button at the bottom of our career page.
Role Description A Background Investigator and Interviewer conducts and compiles personal and professional background investigations and reinvestigations for Concentric Advisors' potential staff members and clients by: - Interviewing employers, co-workers, neighbors, and personal references - Conducting online court and criminal records searches - Preparing reports on findings This position also conducts Subject Interviews and completes a report narrative on each case. As a Background Investigator and Interviewer, you will: - Conduct background checks, consumer investigative reports, and on-screen interviews - Provide security advice and guidance to our security team related to corporate personnel and client entities - Develop and hone analytic and communication skills across all investigative fields Qualifications - Bachelor's degree in criminal justice, psychology, or related field - 10 years of hands-on background investigation experience Requirements - Must be able to legally work in the country where this position is located without visa sponsorship Preferred Qualifications - Current or former US Government background investigators or multi-disciplined security officers with a Top Secret US Federal Government Clearance - Professional certifications in physical security, personnel security, cyber protection, or acquisition disciplines - Experience as CIA/FBI Polygrapher; MDSO; DCSA Investigator; DCSA Subject Interviewer; Security Adjudicator Benefits - 401k including employer match & immediate vesting - Paid sick leave accrual - Seattle, Washington Pay Range: $50 — $50 USD
• Develop mobile applications for Android and iOS using Flutter. • Design technological solutions aligned with business needs and information security best practices. • Meet requirements defined by the Product Owner (business and technical), ensuring acceptance criteria are fulfilled. • Support and monitor application rollouts from testing/homologation through production. • Ensure adherence to agile methodologies and established development standards. • Apply and enforce mobile application security best practices (e.g., OWASP Mobile). • Perform code reviews with a focus on security and code quality. • Execute security tests and assist in identifying and remediating vulnerabilities. • Maintain and evolve existing applications, fixing defects and proposing improvements. • Create and maintain secure development standards and documentation for mobile applications. • Contribute to the dissemination of security knowledge within the team. • Collaborate with product, engineering, and business teams.



