Cybersecurity SME / ISSO- Federal Health at rockITdata
Arlington, VA
—
Jul 16, 2026
Arlington, VA
Jul 21, 2026
What this job asks for AI summary
This role centers on cybersecurity compliance and risk management for a large federal healthcare modernization program. Day-to-day work involves managing RMF activities, producing and maintaining ATO packages and related security documentation (SSPs, POA&Ms, SARs), coordinating security control assessments, and supporting vulnerability management across cloud and enterprise environments. It suits an experienced ISSO or information assurance professional familiar with NIST, FISMA, and federal healthcare IT contexts.
Senior level · 5+ years · Remote · Bachelor's required · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
The posting is tagged '#LIREMOTE', indicating a fully remote position. No specific metro or state is mentioned.
The required clearance is a Level 3 Public Trust — this is a federal suitability determination, not a national security clearance (Confidential/Secret/TS), so the clearance requirement is set to None.
The degree requirement is a hard gate: 'Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Systems, or a related technical discipline' — no equivalent-experience substitution is offered.
Cloud environment experience (AWS GovCloud / Azure Government) is listed under Required Qualifications but explicitly qualified with 'is preferred', so it is treated as preferred.
Cybersecurity certifications (CISSP, CAP, Security+, CISM) are also explicitly marked 'is preferred' in the posting.
Experience supporting VA, VHA, DHA, or other Federal healthcare organizations is listed as preferred and is not captured as a named technology skill.
The title carries no seniority level word; the title states no level. The 5-year requirement and scope (leading RMF/ATO activities, advising government stakeholders) support a Senior classification.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): ATO documentation, NIST SP 800-53.
This posting reads as a fully-remote role, so it was scored against the national candidate pool rather than a single metro.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.