OneZero Solutions logo
OneZero SolutionsPosted 4 weeks ago

Cybersecurity Subject Matter Expert (SME) – Level III

HybridAlexandria, Virginia, United States

Full TimeSenior LevelSmall

Job Summary

Lead the full NIST SP 800-37 RMF lifecycle for USCG information systems, operational technology, and hybrid cyber-physical platforms by serving as the designated Information System Security Engineer. Develop and manage RMF authorization packages in eMASS, including security plans, risk assessments, and incident response procedures. Perform Security Readiness Reviews, analyze vulnerability scan results, and validate remediation through patching cycles and POA&Ms. Maintain continuous monitoring for DoD, DHS, and USCG compliance while integrating Zero Trust principles and OT/ICS requirements into system designs. Evaluate emerging threats, adversary tactics, and supply-chain risks to recommend safeguards that reduce attack surface. Produce weekly, monthly, and quarterly cybersecurity readiness updates and executive briefings for Government leadership. Provide senior technical leadership and mentorship to the ISSE/SME team, formulating continuous improvement recommendations to the contracting officer.

Required Qualifications

  • Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related technical discipline from an accredited institution
  • Minimum 8 years of related, progressive cybersecurity experience in a technical field related to this labor category
  • Active professional certification (DoD 8140/8570 qualifying): CISSP-ISSAP or CISSP-ISSEP
  • Active final SECRET personnel security clearance (Tier 3 / SF-86 investigation) with the ability to maintain eligibility for the duration of the task order
  • Execution of a Classified Information Non-Disclosure Agreement (SF-312)
  • S. citizenship
  • Favorably adjudicated background investigation and FBI fingerprint check
  • Ability to obtain and maintain a DoD Common Access Card (CAC) as a condition of continued employment
  • Recognized expertise and technical leadership in the cybersecurity discipline
  • Exceptional oral and written communication skills
  • Ability to interface with all levels of Government management
  • Demonstrated experience implementing the RMF, including system categorization, control selection, implementation, assessment, and continuous monitoring
  • Core knowledge of: risk management processes
  • Core knowledge of: national and international cybersecurity laws, regulations, policies, and ethics
  • Core knowledge of: cybersecurity principles
  • Core knowledge of: cyber threats and vulnerabilities
  • Core knowledge of: computer networking concepts, protocols, and network security methodologies
  • Core knowledge of: the operational impacts of cybersecurity lapses

Desired Qualifications

  • Experience with USCG/DoD security tools: eMASS, ACAS/Nessus/Security Center, Elastic SIEM, HBSS, Tanium, Splunk, ServiceNow, and Burp Suite
  • Experience with OT/ICS/SCADA security, shipboard or aviation platform systems, and the DoD "Assess Only" process
  • Familiarity with DHS 4300A, COMDTINST cybersecurity policy, DoDAF artifacts, ITIL/DESMF practices, and DevSecOps pipelines
  • Prior USCG, DHS, or DoD RMF support experience

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce