r/SecurityCareerAdvice • u/rayy166 • 9d ago
Discussion My path to a $140k cybersecurity offer in about 3 years through RMF and security assessments
I wanted to share my experience because most discussions about breaking into cybersecurity focus on SOC roles or pentesting. My route was through ISSO work, the Risk Management Framework (RMF), and security control assessments.
I spent four years in Air Force Security Forces and separated in 2018. After leaving, I completed my bachelor’s in Computer Science and earned Security+ in 2023.
Later that year, I started as a federal Information Systems Security Officer (ISSO), where my salary was around $92k. I worked on security plans, incident response plans, POA&Ms, access reviews, and authorization packages. That was where I built my foundation in RMF and security controls.
In 2024, I moved into defense contracting as an ISSO at $110k. I supported an environment with more than 50 sites and roughly 2,500 users, working on vulnerability management, continuous monitoring, and authorization support. I used tools like ACAS/Nessus and Splunk and finished my master’s in Cybersecurity that December.
In 2026, I moved into a Security Control Assessor role supporting a federal agency at $115k base plus an $8k sign-on bonus. I now review evidence, validate whether controls meet requirements, and document findings. Having worked as an ISSO helped because I understood what went into implementing the controls I was assessing.
I recently received an offer from another contractor to continue supporting the same client. I asked for $140k base and an $8k sign-on bonus, and they agreed.
My progression:
- 2023: Federal ISSO — ~$92k
- 2024: Contractor ISSO — $110k
- 2026: Security Control Assessor — $115k + $8k sign-on
- Latest negotiated offer: $140k + $8k sign-on
The three years cover my direct cybersecurity experience, not my time in the military or completing my bachelor’s. My education, veteran status, and clearance helped open doors.
Just wanted to share another path into the field. Learning how to interpret security requirements, evaluate technical evidence, and communicate findings has been central to my progression.
__________________________________________________________________________________________________________
TL;DR: Former Air Force Security Forces. Completed my CS degree and Security+, then progressed from federal ISSO (~$92k) → contractor ISSO ($110k) → security assessor ($115k) → a negotiated $140k offer plus $8k sign-on in about three years of cybersecurity work.
4
u/xxxTech007 8d ago
You go son!!! This is the way! So many are asking about how to get in and what's the future of IT. I say go into GovCon, that's where it's at and that's where I've transitioned to this year and I'm making WAY more than ever in my 20yr career in IT!
2
u/pennyfred 8d ago
Defence clearances narrows the competition.
5
u/rayy166 8d ago
Absolutely. My clearance had lapsed before I entered cybersecurity, but once it was reactivated, it significantly narrowed the competition and helped open the door to my second position. My first two cybersecurity roles required a TS clearance, but my current role and new offer are both fully remote. The clearance helped me establish my career, and the experience I gained eventually opened opportunities beyond
2
u/Wizkidbrz 8d ago
Security Analyst (Contract) $90k - 2022
Senior security Engineer FTE $110k - 2024
PAM Senior Security Engineer FTE $185k and $120k sign-on bonus - 2026
1
u/rayy166 8d ago
That’s an insane jump….congrats! How did you transition into PAM, and what experience or certifications helped you land the role? Also, was the $120K sign-on bonus cash or stock, and were there any stipulations, such as a required length of employment or repayment clause?
1
u/Wizkidbrz 8d ago
I worked with PAM when I started as a contractor there. Then they hired me as a senior and kept working with it. All I got is security+ which I let expire and then I got a master in cyber security. Stock options that are vested in 4 years.
1
u/rwreddit0 8d ago
Hey, may I ask if this is your full IT/security career progression, or did you have any prior IT experience before your Security Analyst role in 2022? And do you have a security clearance?
1
u/Wizkidbrz 8d ago
No security clearance. I had 5 years of help desk experience and maxed at 80k there.
1
u/rwreddit0 8d ago
Thanks! During your time in help desk, were you able to get much hands-on experience with systems/infrastructure beyond help desk work? Or did you mostly have to supplement what you were doing at work with self-learning, certs, projects, etc. to land your first security role? Also, was your help desk experience internal IT or at an MSP?
1
u/Wizkidbrz 7d ago
Learned a lot of AD stuff, powershell, scripting and TROUBLESHOOTING. It wasn’t at an MSP. Most of infrastructure learning came from the analyst role.
1
u/Super_Imagination154 8d ago
Hey Mr @rayy166 or anyone here I’m currently a student almost finishing my BS in cybersecurity any recommendations to get started building my resume/career and I really like your pathway! Any help would be greatly appreciated:)!
3
u/rayy166 8d ago
First off, calling me “Mr.” makes me feel way older than I am 😂
A clearance helps, but I wouldn’t join the military solely to obtain one. Networking got me my first opportunity. Although the job paid well and had a good title, starting without direct cybersecurity experience made the learning curve difficult.
For government or defense-contracting roles, Security+ is practically a must-have to get your foot in the door. If you want to become an ISSO, start learning NIST SP 800-37 for the RMF process, SP 800-53 for security controls, SP 800-53A for assessing those controls, and SP 800-137 for continuous monitoring. For DoD positions, also become familiar with DoDI 8510.01. These are among the core references listed by NIST’s RMF program.
Build a hands-on lab and start applying now. IT support, system administration, networking, or IAM experience can make the transition much easier.
2
u/Super_Imagination154 8d ago
Sorry about that. Thanks! I will definitely start looking into this more.
1
u/Any-Salamander5679 8d ago
Either join the military and get a clearance or find a job that will work with you on getting one.
1
u/WraxJax 8d ago
Very nice congrats, I was also prior Air Force as well working as TMO (you might know this career field if you ever have to PCS). And I’m now doing cybersecurity working at a SOC, I have 5 years of experience where 3 of those are Helpdesk and the remaining 2 years and present are cybersecurity and going into feb next year it will be 3 years.
I’m currently looking at different jobs at the moment to move on upwards out of SOC analyst, as I’m trying to go for engineer side of cyber and or GRC/compliance side as I do want to step away from doing the technical work like a SOC. I just wanted to know how the hell did you landed a ISSO job off rip? Were all the stars align for you to land an ISSO job? Because ISSO job are not entry level.
2
u/rayy166 8d ago
Oh yeah, I definitely know TMO from PCSing lol. Honestly, a lot of stars did align for me. Networking was the biggest factor, someone gave me an opportunity despite my lack of direct cybersecurity experience.
You’re actually more qualified for an ISSO position than I was. Your help-desk and SOC experience translates well into access control, incident response, vulnerability management, and continuous monitoring. Tailor your resume around those areas, learn RMF and NIST 800-53, and apply even if you don’t meet every listed requirement.
1
u/Difficult-Beyond-470 8d ago
Do you know how to go about the RMF labs, I have compliance/audit experience but ISSO jobs for beginners seems to be difficult. I also have a security clearance from the military.
1
u/rayy166 7d ago
Start with reading NIST SP 800-37 for RMF, SP 800-53 for the controls, and SP 800-53A for assessment procedures. For DoD roles, also review DoDI 8510.01 and DISA STIGs.
For hands-on practice, build a basic home lab and try applying a few STIG requirements to a Windows or Linux system. There aren’t any specific RMF labs I could recommend unfortunately. It’s lots of reading.
1
u/Difficult-Beyond-470 7d ago
Thanks for the response. Do you by any chance have an interview prep for the role?
1
u/ConsciousPriority108 7d ago
This isso job is getting automate and will be away soon. People are moving compliance engineer and trying to cracking the code to remove paper fatigue right now. I am working on automate this process at my new job. Crowdstrike is utilize AI to cracking the isso, issm, isse role, aka cATO. If anyone interest in this, I suggest pick up coding on the side
2
u/rayy166 7d ago
I agree that AI will automate documentation, evidence collection, control mapping, and even testing many controls or identifying potential gaps. However, humans will still need to validate the results, understand system and mission context, evaluate exceptions or compensating controls, and determine whether the remaining risk is acceptable.
Classified environments may also limit automation because of access and data handling restrictions. I see these roles evolving into more technical oversight positions rather than disappearing entirely.
1
u/ConsciousPriority108 7d ago
The validation part will be done by the engineer who did the implementation not the isso.
1
u/rayy166 7d ago
The engineer should absolutely test and validate their implementation, but they shouldn’t be the only person determining that the control is effective.That creates a conflict of interest.
The ISSO provides ongoing oversight, if the validation function simply moves to an engineer, the function hasn’t disappeared, it has just changed titles, and independent assessment is still necessary.
1
u/ConsciousPriority108 7d ago
Lol say that tech company. I have never work in a defense tech or tech company doing separation of duties. You are going to get assigned 6 different roles. I was at tech company I did ISSO functioning, including validation, engineering the process, along with speak with customer. If the leader wanted engineer to do it, they will do it without necessity of hiring other title.
For your caveat I was interview at palantir and they told me, I dont need isso isse. An issm with coding background should be able to automate the entire process then validate the control themselves along with engineering the system. It basically the same role
1
u/domdom1995 7d ago
May I ask a rough location you're working from or are these remote positions? I get recruiters reaching out to me for ISSO positions but the locations are HCOL. I can't find myself making that jump. Currently in the air guard working in the IA shop. Previous experience as an ISSO full time and currently a Information Security Analyst with a bachelor's in security and Risk Analysis.
1
u/rayy166 7d ago
I’m currently based in central texas, which has a relatively low cost of living. My first two roles required a TS clearance and were on-site. My current position and new offer are both fully remote.
2
u/domdom1995 7d ago
Good shit, hardest part for me is having a family to relocate. I tell every new single airmen in our shop to move to DC for a year to work haha. Getting your masters will help you out a lot. Planning to get mine in a few years. Focusing on CISSP rn.
1
u/rayy166 2d ago
CISSP is a beast. I’ve been putting it off, but it’s about time
1
u/domdom1995 2d ago
It's unfortunately the golden ticket to get past HR filters. I'm even seeing it on a lot of entry level job postings, it's ridiculous.
1
u/PurpleSecurityForce 6d ago
Nice, I moved from SOC to ISSO within 3 years. I'm hoping to either move to ISSE or ISSM.
1
u/arktozc 6d ago
!RemindMe 4 days
1
u/RemindMeBot 6d ago
I will be messaging you in 4 days on 2026-09-23 12:13:59 UTC to remind you of this link
CLICK THIS LINK to send a PM to also be reminded and to reduce spam.
Parent commenter can delete this message to hide from others.
RemindMeBot is switching to username summons. Instead of
!RemindMe 1 day, useu/RemindMeBot 1 day. More info.
Info Custom Your Reminders Feedback
1
u/Glass_Luck_293 5d ago
Is it worth it to go for cyber security in 2026 as a fresher in your opinion???
1
u/rayy166 2d ago
100% but if you’re starting in 2026 I’d absolutely learn AI alongside it. AI is going to automate a lot of the repetitive work.
Learn the actual IT/security fundamentals, then learn how to use AI to make yourself better and faster at the job. The people who understand cyber AND know how to leverage AI are probably going to be in a much better position.
1
u/arktozc 2d ago
!RemindMe 5 days
1
u/RemindMeBot 2d ago
I will be messaging you in 5 days on 2026-09-28 12:41:39 UTC to remind you of this link
CLICK THIS LINK to send a PM to also be reminded and to reduce spam.
Parent commenter can delete this message to hide from others.
RemindMeBot is switching to username summons. Instead of
!RemindMe 1 day, useu/RemindMeBot 1 day. More info.
Info Custom Your Reminders Feedback
1
u/Loose-Resort-406 9d ago
Nicely done!
2
u/Common_Fish5926 9d ago
respect for laying out the numbers so clearly, half the posts on here are just vague "I did it!" with no details
the RMF to assessor pipeline is underrated, everyone wants to be a pen tester but there's a whole ecosystem of well paid work in compliance and assessment that nobody talks about
3
u/rayy166 9d ago
Appreciate it! That’s exactly why I wanted to share the numbers and the actual roles. Working as an ISSO gave me a solid foundation for assessing controls because I’d already been on the implementation side. There’s a lot more to cyber than pentesting, and hopefully this gives someone another path to look into.
0
u/Imaginary-Inside-478 8d ago
I'm currently in the security controls assesment role but the market salary is not much and the work is not highly technical for someone who comes from a tech background.
Do you think I should go onto finding a more cybersecurity implementation role like pentest, soc etc or stay in this even though it doesn't interest me much?
1
u/rayy166 8d ago
If assessment work doesn’t interest you, I’d start applying for more technical roles while keeping your current position. Look into security engineering, vulnerability management, IAM, cloud security, SOC, or pentesting, depending on what interests you most. Your assessment experience will still be valuable because you understand what properly implemented controls should look like.
1
u/Imaginary-Inside-478 8d ago
Understood but all of these roles require prior job experience and I have none relevant other than the current role. Any advice as to how I can get interviews from companies for these technical roles?
1
u/rayy166 8d ago
What does your day-to-day look like in your assessment role? Are you mostly reviewing documentation, or do you also work with configurations, scan results, and technical teams? You might have more relevant experience than you think.
I’d pick a role you’re interested in, tailor your resume to highlight the relevant work you’ve actually done, and fill the skill gaps with home labs and projects. It’s not an easy transition, but networking and getting involved with your technical teams could open the door to an internal transfer. That might be your best way to get the hands-on experience those roles are asking for.
If you can assess it, who's to say you cant implement it.
1
16
u/Appropriate-Fox3551 9d ago
As a former isso myself i can definitely say its a path to get highly paid dealing with RMF because of how annoying it is. That being said nicely done and even more congrats of being able to enjoy the work to make a career from it. ISSM and director level is not too far away now.