KBR · North Charleston, SCremote

Salary
$107,600–$161,400from the description
Posted
Jul 17, 2026
Location
North Charleston, SC
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

This fully remote role centers on guiding Defense Health Agency medical information systems through the full RMF lifecycle — from assessment and authorization to continuous monitoring — to achieve and maintain ATOs. The work involves building and maintaining RMF documentation packages, assessing NIST SP 800-53 controls, coordinating with engineers and government stakeholders, and reporting on compliance status to DHA leadership. It suits an experienced cybersecurity professional with a DoD Secret clearance and a solid background as an ISSO or ISSM.

Senior level · 6+ years · Remote · Secret clearance · Full-time

Must have (6)
RMFSecurity+, CISSP or Casp+Microsoft WordMicrosoft PowerPointMicrosoft ExcelSharePoint
Nice to have (7)
eMASSACASDISA STIGsSTIG ViewerSCAP Compliance CheckerCMRSMicrosoft Project

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
SharePoint8%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Security+45%RMF40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (10)

The title 'RMF Cybersecurity ISSO/SME 3' carries no standard seniority label; 'Unspecified' is used for the level advertised in the title. The requirements (6+ years with a degree, or 14+ without, plus demonstrated ISSO/ISSM/SME experience) support a Senior classification.

Degree requirement is marked None because the JD explicitly accepts 14+ years of relevant experience in lieu of a degree.

The overall years minimum is set to 6, the lower bound of the degree-holder path; the 14-year alternative is the no-degree path, not a higher floor for all candidates.

The DoD 8140.03-compliant certification requirement names Security+, CISSP, and CASP+/SecurityX as examples; these are treated as interchangeable alternatives satisfying a single hard gate.

eMASS is listed under Preferred Qualifications with 'or equivalent compliance-tracking application,' so it is marked preferred with no alternatives populated (the qualifier acknowledges any equivalent tool).

DISA STIGs/SRGs, STIG Viewer, SCAP Compliance Checker, ACAS, CMRS, and Microsoft Project all appear under Preferred Qualifications and are marked preferred accordingly.

No metro is inferred per caller instruction; the role is fully remote with Eastern Time availability required.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53.

Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗