Cybersecurity Plan Reviewer

OneZero Solutions

$95K — $115K *
Transportation
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in cybersecurity, regulatory compliance, or auditing
  • Knowledge of 33 CFR Subchapter H, specifically 33 CFR Part 101 Subpart F
  • Foundational understanding of general cybersecurity principles
  • At least one cybersecurity certification (CISA, CGRC, CISSP)
  • Strong technical writing skills and attention to detail
  • Ability to handle high-volume review requirements
  • Disclosure of any conflicts of interest related to regulated facilities

Responsibilities

  • Conduct cursory reviews of cybersecurity submissions for completeness
  • Identify deficiencies and prepare correspondence for resubmissions
  • Perform detailed technical reviews against regulatory requirements
  • Recommend findings based on Government checklists
  • Ensure findings are technically supported and consistent
  • Prepare review packages for Government review
  • Maintain review status records in appropriate systems
  • Respond to inquiries using Government databases

Benefits

  • Remote work flexibility within the United States
  • Opportunities for company-provided maritime and cybersecurity training
  • Engagement with U.S. Coast Guard and national regulations
  • Impactful role in maritime cybersecurity compliance
  • Collaborative work environment with government entities
Full Job Description
Position Title: Cybersecurity Plan Reviewer

Location: Remote (Within the United States)

Clearance:
  • No security clearance is required. This work is performed at the Controlled Unclassified Information (CUI) level.
  • S. citizenship is required. All personnel must undergo and successfully pass, at minimum, a Tier 1 background investigation (or equivalent) and be favorably adjudicated.

Position Summary

Cybersecurity Plan Reviewers perform the cursory and detailed technical review of cybersecurity plans, cybersecurity assessments, waiver requests, and equivalency requests submitted by U.S.-flagged vessels, facilities, and Outer Continental Shelf facilities under 33 CFR Part 101 Subpart F. Reviewers apply Government-furnished checklists and process guides and recommend findings for Government decision. Maritime knowledge may be met through company-provided training, so candidates from federal RMF and assessment and authorization, regulatory compliance, or audit backgrounds are encouraged to apply.

Key Responsibilities
  • Conduct Stage One cursory review of assigned submittals to determine whether the submission is complete and includes all required documents, information, and elements.
  • Identify incomplete submittals and prepare draft signature-ready correspondence clearly identifying each deficiency, omission, or discrepancy, the associated regulatory basis, and brief instructions for resubmission.
  • Conduct Stage Two detailed technical review to evaluate whether submissions satisfy the applicable requirements of 33 CFR Subpart F and associated Government guidance.
  • Recommend a finding of Satisfactory, Unsatisfactory, or Not Applicable for each regulatory checklist element, using Government-furnished checklists, process guides, and decision matrices.
  • Ensure findings are clearly stated, technically supportable, internally consistent, and traceable to the applicable regulatory requirement, checklist element, or Government guidance.
  • Prepare review packages and draft signature-ready correspondence for Government review and signature.
  • Record and maintain review status in MISLE, USCG SharePoint, and USCG ServiceNow before the close of the following business day.
  • Respond to status inquiries using only information available in Government databases or published Government regulations and guidance, and refer all policy-related inquiries to the designated USCG representative.
  • Complete company-provided maritime operations and OT cybersecurity training as assigned.
  • Report to the Sub-Project Manager any submitter that may present an organizational conflict of interest.


Required Qualifications
  • A working knowledge of 33 CFR Subchapter H, specifically 33 CFR Part 101 Subpart F.
  • A foundational understanding of maritime operations. This may be met through prior experience or through company-provided training.
  • A foundational understanding of general cybersecurity principles and frameworks.
  • At least one cybersecurity certification satisfying the certification requirement for the DoD 8140 DCWF work role of Security Control Assessor Intermediate proficiency level (for example CISA, CGRC, or CISSP)
  • Strong technical writing skills and demonstrated attention to detail in document review.
  • Ability to meet recurring turnaround requirements in a high-volume review environment.
  • Must disclose, for organizational conflict of interest screening, any current or prior engagement performed for MTSA-regulated vessel, facility, or Outer Continental Shelf facility owners or operators involving cybersecurity plan development, cybersecurity assessment, or related advisory services.

Preferred Qualifications
  • Prior maritime industry, port, terminal, or vessel operations experience.
  • Experience performing RMF control assessments, ATO package review, or similar regulatory compliance document review.
  • Familiarity with NIST CSF and NIST SP 800-series guidance.
  • Exposure to OT and ICS environments.
  • Prior U.S. Coast Guard or DHS support experience.

Technical Skills
  • Checklist-based technical review and evidence evaluation.
  • NIST Cybersecurity Framework fundamentals.
  • Technical writing for a regulatory audience.
  • USCG MISLE, SharePoint, and ServiceNow, or comparable case management systems.
  • CUI and SSI handling in accordance with 49 CFR Part 1520 and DHS MD 11042.1.

Security Clearance
  • No security clearance is required. This work is performed at the Controlled Unclassified Information (CUI) level.
  • S. citizenship is required. All personnel must undergo and successfully pass, at minimum, a Tier 1 background investigation (or equivalent) and be favorably adjudicated.

Education

Associate's or Bachelor's degree in cybersecurity, information technology, maritime studies, or a related field preferred. Equivalent experience and certification considered.

Similar Jobs

More Jobs at OneZero Solutions

More Transportation Jobs

Find similar Cybersecurity Plan Reviewer jobs: