We deliver science, technology and engineering solutions to governments and companies around the world.
Cybersecurity Risk Management Framework Information System Security Officer
Location
United States
Posted
3 days ago
Salary
$107.6K - $161.4K / year
Seniority
Mid Level
No structured requirement data.
Job Description
Cybersecurity Risk Management Framework Information System Security Officer
KBR, Inc.
Role Description KBR is seeking a Cybersecurity Risk Management Framework (RMF) Information System Security Officer (ISSO) to support the DHA Solution Delivery Division (SDD). In this role, you will lead Assessment & Authorization (A&A) activities and guide systems through the RMF lifecycle to achieve and maintain Authorizations to Operate (ATOs) for mission-critical medical systems. You will work closely with engineers, developers, and government stakeholders to ensure compliance with NIST, DoD, and DHA cybersecurity requirements while supporting continuous monitoring and risk management efforts. This 100% remote position requires availability during standard Eastern Time (ET) day shift hours. Join KBR to contribute directly to protecting critical healthcare systems supporting warfighters and their families. Roles and Responsibilities - Manage one or more information systems throughout the full six-step RMF lifecycle, including assessment, authorization, and continuous monitoring activities. - Serve as an RMF Subject Matter Expert (SME), advising stakeholders on cybersecurity compliance, risk posture, and ATO readiness. - Develop, review, and maintain RMF packages and associated documentation, including Security Plans, POA&Ms, Risk Assessment Reports, and security control policies. - Assess system compliance against NIST SP 800-53 controls and DHA RMF requirements as part of self-assessment and annual reviews. - Document and maintain evidence supporting control implementation and compliance. - Lead and participate in A&A and stakeholder meetings to track system status, resolve issues, and drive RMF progress. - Coordinate with engineers and system owners to develop architecture diagrams, system asset inventories, and security policies. - Prepare and deliver status reports to DHA leadership on system authorization and compliance efforts. Qualifications - U.S. Citizen. Active DoD Secret security clearance. - Bachelor’s degree in cybersecurity, information technology, or related field with 6+ years of experience; or 14+ years of relevant cybersecurity/IT experience in lieu of degree. - DoD Manual 8140.03 (formerly 8570.01)-compliant certification (e.g., Security+, CISSP, CASP+/SecurityX). - Demonstrated experience performing RMF activities as an ISSO/ISSM/SME, including ATO process support and RMF package development (Security Plans, POA&Ms, architecture diagrams, system security policies, etc.). - Demonstrated experience assessing and documenting NIST SP 800-53 controls. - Experience using Microsoft Office applications: Word, PowerPoint, Excel, and SharePoint. Preferred Qualifications - Experience using eMASS or equivalent compliance-tracking application. - Experience supporting RMF processes under DHA. - Familiarity with ACAS and DISA STIGs/SRGs and tools such as STIG Viewer and SCAP Compliance Checker. - Familiarity with Continuous Monitoring and Risk Scoring (CMRS). - Experience using Microsoft Project to build Integrated Master Schedules (IMS). Compensation $107,600.00 - $161,400.00. The salary range posted is based on the national average. The offered rate will be based on the contract affordability and the selected candidate’s location, knowledge, skills, abilities, and/or experience, and in consideration of internal parity. Benefits - Selection of competitive lifestyle benefits which could include a 401K plan with company match. - Medical, dental, vision, life insurance, AD&D. - Flexible spending account, disability, paid time off, or flexible work schedule. - Support for career advancement through professional training and development.
Related Guides
Related Categories
Related Job Pages
More Risk Jobs
International Consultant: Sexual and Reproductive Health (SRH) Specialist for Disaster Risk Reduction (DRR), Climate Change, and Anticipatory Action (AA)
UNDPUN Women works for the elimination of discrimination against women and girls; the empowerment of women; and the achievement of equality between women and men as partners and beneficiaries of development, human rights, humanitarian action and peace and security.
Role Description The consultant will lead key initiatives, including: - Completion of country-specific Sendai GAP one-pagers for 8 countries - Co-designing a regional Community of Practice for SRH - Producing a manuscript on regional coordination - Providing technical support for Cash and Voucher Assistance (CVA) training with Fiji National University - Ongoing MRA validations in Fiji, Tonga, and Vanuatu - Development of SOPs for MISP implementation in Kiribati, Solomon Islands, and Vanuatu - Advocacy, stakeholder engagement, and resource mobilization through project proposals and concept notes The Consultant reports to the Humanitarian Specialist as the primary supervisor for day-to-day work and point of escalation for strategic decisions, with the Director to review the final outputs. The contract is for a part-time consultancy of a total of 49 days commencing on the date of the signed contract. The consultant will work remotely with no travel expectations unless deemed necessary. Qualifications - Advanced degree [Master's] in social sciences, gender studies, public health, research, or a related field - At least 5 years of relevant experience, including recent field experience working with GBV/SRHR/Climate Change programming, specifically in remote and low-resource settings and/or humanitarian settings - Strong understanding of the Sendai Framework, Gender Action Plan, and gender-focused DRR approaches - Familiarity with UNFPA’s GBV and SRHR work in humanitarian contexts - Previous experience leading or conducting assessments (survey/interview tool design, data collection and analysis, visualization and/or reporting) - Demonstrated experience in conducting field consultations, data collection, and developing guidance documents or toolkits - Strong analytical and writing skills - Excellent planning and organizational skills - Excellent interpersonal skills with good communication including oral and written - Good research and analytical skills with data management skills - Initiative-taking and resourcefulness - Fluent in English; other language skills are a plus Requirements - Complete drafts of eight 1-pager Sendai GAP for Niue, Tokelau, Tuvalu, Cook Islands, FSM, Kiribati, Nauru, and RMI - Update the Sendai GAP regional status - Co-design the Community of Practice for SRH in the Pacific - Produce a maximum of 10-pager manuscript for the need for regional coordination for SRH - Support packaging the Cash and Voucher Assistance Training with Fiji National University - Provide desk review and support for ongoing validations for MRA in Fiji, Tonga, and Vanuatu - Provide technical support on writing and facilitating the development of SOPs for MISP implementation - Support on writing project proposals and concept notes to advance the agenda on SRHiE in the Pacific Benefits - Payments will be made upon satisfactory delivery of associated deliverables and with acceptable quality by the UNFPA Representative - Submission of Certificate of Payment and Accomplishment Report agreed by the supervisor Company Description UNFPA is the lead United Nations agency for delivering a world where every pregnancy is intended, every childbirth is safe, and every young person's potential is fulfilled. The UNFPA Strategic Plan for 2026-2029 articulates the organization’s response to a complex global environment, providing a roadmap for resilience and renewal. - Focus on four interconnected outcomes: - Ending the unmet need for family planning - Ending preventable maternal deaths - Ending gender-based violence and harmful practices - Adapting to demographic change through evidence and rights-based policies UNFPA promotes equal opportunities in terms of appointment, training, compensation, and selection for all regardless of personal characteristics and dimensions of diversity.
Principal Cyber Governance & Risk Advisor, Senior Associate
IntelanceEnterprise Architecture. Cybersecurity. AI Operating Models. We build strategic systems for the future of business.
• Lead independent cyber governance and risk reviews for complex organisations. • Assess risk appetite, risk ownership, control effectiveness and risk-treatment decisions. • Review policies, risk registers, control mappings, assurance evidence and governance arrangements. • Judge whether evidence supports the conclusions being presented to senior leaders. • Explain cyber risks and control gaps clearly to boards, executives and non-technical stakeholders. • Lead interviews and workshops with CISOs, risk owners, technology leaders and control owners. • Work alongside security architects, technical assessors and other Intelance specialists. • Write clear, defensible and client-ready reports. • Complete scheme-specific training and participate in internal quality reviews where required.
• Support management of innovation programs and organize the backlog of ideas and new initiatives. • Conduct market research and benchmarking, and assist in building business cases. • Assist in monitoring pilots, POCs (Proofs of Concept) and innovation projects, consolidating results and lessons learned. • Create high-quality executive presentations for company leadership. • Translate complex technical information and data into clear, fluid and engaging visual narratives (corporate storytelling techniques). • Support internal communications to publicize the achievements, results and benefits generated by projects. • Structure meeting agendas and draft meeting minutes, ensuring follow-up and enforcement of action plans. • Manage timelines, documentation and keep the programs' knowledge base up to date. • Monitor area performance indicators (KPIs) and support program budget control.
Principal Cyber Governance & Risk Advisor, Senior Associate
IntelanceEnterprise Architecture. Cybersecurity. AI Operating Models. We build strategic systems for the future of business.
Role Description We are appointing a small number of senior Cyber Governance and Risk specialists to our associate panel. This is not permanent employment. Work will be offered on a project-by-project basis according to client demand, suitability and availability. There is no guaranteed volume of work. - Lead independent cyber governance and risk reviews for complex organisations. - Assess risk appetite, risk ownership, control effectiveness and risk-treatment decisions. - Review policies, risk registers, control mappings, assurance evidence and governance arrangements. - Judge whether evidence supports the conclusions being presented to senior leaders. - Explain cyber risks and control gaps clearly to boards, executives and non-technical stakeholders. - Lead interviews and workshops with CISOs, risk owners, technology leaders and control owners. - Work alongside security architects, technical assessors and other Intelance specialists. - Write clear, defensible and client-ready reports. - Complete scheme-specific training and participate in internal quality reviews where required. Qualifications - Substantial senior experience in cyber security governance, risk management or formal cyber assurance, normally gained over at least ten years. - Experience working with large, complex or regulated organisations. - Strong evidence of advising boards, executive teams or senior risk committees. - Practical knowledge of recognised frameworks such as ISO 27001, NIST CSF, Cyber Essentials or equivalent. - Excellent written English. Reports must be ready for clients without heavy editing. - The ability to work independently and challenge weak evidence respectfully. - UK Cyber Security Council professional registration at Principal or Chartered level in Cyber Security Governance & Risk Management is preferred. - Experience aligned with Chartered level and willingness to undergo formal professional assessment will also be considered. - General certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor or Lead Implementer are useful, but do not replace the professional registration requirement. - Must be based in the UK, able to attend UK client sites when agreed, and able to contract through a limited company or another compliant arrangement. Benefits - Senior cyber assurance and advisory assignments. - Flexible associate working based on your availability. - Direct access to Intelance leadership. - Work with experienced governance, architecture and technical-assurance specialists. - Clear scopes, templates and quality-review arrangements. - Potential inclusion in Intelance proposals and associate credentials, subject to agreement. Company Description Intelance is a strategic consultancy specialising in Enterprise Architecture, AI transformation, and cybersecurity. We help organisations design the systems, structures, and operating models needed to scale, secure, and lead in a volatile world. Our team combines TOGAF-based architecture thinking with cybersecurity governance (Cyber Essentials, ISO 27001), cloud-native patterns, and AI operating model design. From EA blueprints to Zero Trust frameworks to AI adoption roadmaps - Intelance transforms complexity into strategic clarity. We serve public and private sector clients across the UK, Africa, and the Middle East - particularly in regulated industries such as government, healthcare, finance, energy, and pharma.


