Cyber Security Assessment & Authorization SME
$110,000–$160,000 year
RemoteUnited States
Job Summary
Execute cybersecurity authorization processes for complex enterprise IT environments, including cloud-hosted services, operational technology, and outsourced IT systems. Assess security controls against NIST SP 800-53, identify deficiencies, determine residual risk, and develop risk-based recommendations to support informed authorization decisions. Provide expert guidance to stakeholders throughout the lifecycle, communicate RMF status and outcomes via briefings to senior leadership, and ensure compliance with Department of Defense and Defense Logistics Agency policies. Requires five years of RMF and NIST C&A experience, a Secret clearance, and 8570/8140 certification.
Required Qualifications
- Expert knowledge of the Department of Defense (DoD) Risk Management Framework (RMF), Assessment and Authorization (A&A) processes, and applicable DoD, DLA, and NIST cybersecurity policies and guidance, including NIST SP 800-53 security controls
- Demonstrated ability to plan, execute, and maintain cybersecurity authorizations for complex information systems, ensuring compliance throughout the system lifecycle and supporting timely authorization decisions
- Skill in assessing security controls, identifying and evaluating control deficiencies, analyzing residual risk, and developing risk-based recommendations to support informed authorization and cybersecurity risk management decisions
- Knowledge of cybersecurity principles and best practices for enterprise IT environments, including cloud-hosted services, operational technology (OT), application information systems, and outsourced IT services across large, complex infrastructures
- Ability to serve as a cybersecurity subject matter expert (SME) by providing technical guidance, interpreting cybersecurity requirements, and collaborating with system owners, program managers, engineers, and other stakeholders to achieve compliance and mission objectives
- Skill in communicating complex cybersecurity concepts and RMF activities through clear written documentation, briefings, and presentations to senior leadership, technical teams, and other stakeholders regarding authorization status, risks, and recommended courses of action
- Five (5) years of relevant certification and accreditation experience
- Risk Management Framework (RMF) and NIST C&A experience
- DOD cybersecurity experience
- Experience for large complex organizations
- 8570/8140 compliant certification
- Minimum Clearance: Secret
- Required to stand, walk and sit
- Required to communicate verbally both in person and by telephone
- Required to use hands to finger, handle or feel objects or controls
- Required to reach with hands and arms
- Required close vision
- Required distance vision
- Required depth perception
- Required color vision
- Required the ability to adjust focus
Desired Qualifications
- Be a positive, self-motivated, and proactive person with the ability to adapt to change and tolerate stressful situations
- Candidate must communicate effectively with team members, team lead, management, and government customer
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.