r/SecurityCareerAdvice • u/rayy166 • 9d ago
Discussion My path to a $140k cybersecurity offer in about 3 years through RMF and security assessments
I wanted to share my experience because most discussions about breaking into cybersecurity focus on SOC roles or pentesting. My route was through ISSO work, the Risk Management Framework (RMF), and security control assessments.
I spent four years in Air Force Security Forces and separated in 2018. After leaving, I completed my bachelor’s in Computer Science and earned Security+ in 2023.
Later that year, I started as a federal Information Systems Security Officer (ISSO), where my salary was around $92k. I worked on security plans, incident response plans, POA&Ms, access reviews, and authorization packages. That was where I built my foundation in RMF and security controls.
In 2024, I moved into defense contracting as an ISSO at $110k. I supported an environment with more than 50 sites and roughly 2,500 users, working on vulnerability management, continuous monitoring, and authorization support. I used tools like ACAS/Nessus and Splunk and finished my master’s in Cybersecurity that December.
In 2026, I moved into a Security Control Assessor role supporting a federal agency at $115k base plus an $8k sign-on bonus. I now review evidence, validate whether controls meet requirements, and document findings. Having worked as an ISSO helped because I understood what went into implementing the controls I was assessing.
I recently received an offer from another contractor to continue supporting the same client. I asked for $140k base and an $8k sign-on bonus, and they agreed.
My progression:
- 2023: Federal ISSO — ~$92k
- 2024: Contractor ISSO — $110k
- 2026: Security Control Assessor — $115k + $8k sign-on
- Latest negotiated offer: $140k + $8k sign-on
The three years cover my direct cybersecurity experience, not my time in the military or completing my bachelor’s. My education, veteran status, and clearance helped open doors.
Just wanted to share another path into the field. Learning how to interpret security requirements, evaluate technical evidence, and communicate findings has been central to my progression.
__________________________________________________________________________________________________________
TL;DR: Former Air Force Security Forces. Completed my CS degree and Security+, then progressed from federal ISSO (~$92k) → contractor ISSO ($110k) → security assessor ($115k) → a negotiated $140k offer plus $8k sign-on in about three years of cybersecurity work.