Cybersecurity Subject Matter Expert (SME)

IBSS

$110K — $130K *
Education, Government & Non-Profit
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, Computer Science, Business Management, or a related field.
  • 8+ years of professional cybersecurity experience.
  • CISSP or similar cybersecurity certification (CISM, CASP+, GSLC, etc.).
  • Familiarity with NIST SP 800-53, FISMA, and risk management frameworks.
  • Experience in risk/vulnerability assessments and security testing procedures.
  • Strong communication skills for briefing technical findings.
  • Active Secret Clearance.

Responsibilities

  • Enhance assessment operations by developing standard operating procedures (SOPs).
  • Oversee the integrity and confidentiality of the security assessment process; analyze vulnerabilities.
  • Review program-level documentation, making improvement recommendations.
  • Create security evaluation test plans, conduct hands-on testing, and recommend countermeasures.
  • Assess risks related to threats and vulnerabilities, identifying mitigation strategies.
  • Coordinate the design and implementation of security support systems.
  • Research and develop information security policies and guidance.

Benefits

  • Medical, dental, vision, and prescription coverage with a company-paid deductible.
  • Paid time off and federal holidays.
  • 401K matching program.
  • Tuition/professional development reimbursement.
  • Flex-Spending (FSA) and Dependent Care Account (DCA) options.
Full Job Description
Job Title: Cybersecurity Subject Matter Expert (SME)

Location: Washington, DC

Clearance Required: Active Secret

Description
IBSS is seeking a Cyber Security Subject Matter Expert (SME) to support a Federal customer. This position serves as the principal information assurance and cybersecurity expert on the contract, leading IA engineering, risk and vulnerability assessments, and security evaluation activities that protect NTIA's classified and unclassified systems, data, and networks and that maintain compliance with NIST, FISMA, and Department of Commerce (DOC) security policy. The Cyber Security SME works closely with the security engineer, ISSOs/Security Assessors, and customer leadership to sustain a strong security posture and Authority to Operate (ATO) portfolio.

Key Responsibilities:
  • Provide enhancement capabilities and standard operating procedures (SOPs) to assessment operations for execution and implementation.
  • Maintain accountability for the integrity and confidentiality of the security assessment process; provide in-depth analysis of vulnerabilities across customer systems.
  • Review and make recommendations on program-level documentation, including requirements specifications, system architecture, design documents, test plans, and security plans.
  • Develop and document security evaluation test plans and procedures; conduct hands-on security testing, analyze results, document risk, and recommend countermeasures.
  • Assess and calculate risk based on threats, vulnerabilities, and shortfalls uncovered in testing, and identify mitigating countermeasures.
  • Provide oversight of the design, development, and implementation of security-related support systems.
  • Research, evaluate, and develop Information Security policies and guidance.
  • Develop, review, and update Information Assurance (IA) policies, procedures, and guidelines to keep NTIA systems aligned with evolving federal security requirements and enterprise governance expectations.
  • Perform comprehensive risk and vulnerability assessments; document findings and recommend mitigation and remediation strategies to reduce organizational exposure to cyber threats.
  • Ensure compliance with federal cybersecurity regulations, including NIST and FISMA, by reviewing security controls, identifying gaps, and supporting continuous monitoring activities.
  • Develop and maintain system- and enterprise-level IA documentation, including System Security Plans (SSPs), risk assessments, control implementation statements, POA&Ms, and audit-ready ATO artifacts.
  • Support system security engineering activities, ensuring security requirements are incorporated into system design, architecture, and configuration baselines throughout each system's lifecycle.
  • Coordinate with system owners, ISSOs, architecture teams, and cybersecurity leadership to validate system requirements, address IA concerns, and resolve compliance or security issues.
  • Monitor IA-related compliance activities, ensuring artifacts, assessments, and system configurations remain aligned with NIST SP 800-53 controls, agency policy, and Department directives.
  • Actively participate in or lead technical exchange meetings, document action items and results, and brief customer leadership on the status of activities and risk findings.


Required Skills /Education/ Certifications & Qualifications:
  • Bachelor's degree in Information Technology, Computer Science, Business Management, or a related field.
  • Minimum of eight (8) years of professional cybersecurity experience.
  • CISSP or similar (CISM, CASP+, GSLC, etc.) recognized cybersecurity certification.
  • Working knowledge of NIST SP 800-53, FISMA, and federal Risk Management Framework / ATO processes.
  • Demonstrated experience conducting risk and vulnerability assessments and developing security evaluation test plans and procedures.
  • Strong written and verbal communication skills, with experience briefing technical findings to leadership and government stakeholders.
  • Active Secret Clearance required.


Desired Skills:
  • Experience supporting the Department of Commerce or another Federal Civilian Executive Branch (FCEB) agency's cybersecurity or information assurance program.
  • Experience developing and maintaining ATO documentation (SSPs, SARs, POA&Ms) within a NIST Risk Management Framework or FedRAMP environment.
  • Experience coordinating with Security Operations Center (SOC) or incident response teams on continuous monitoring and mitigation activities.
  • Additional certifications such as CISM, CAP, Security+, or CEH.


IBSS offers a competitive benefits package that includes medical, dental, vision, and prescription drug coverage with a company-paid deductible, paid time off, federal holidays, a matching 401K plan, tuition/professional development reimbursement, and Flex-Spending (FSA)/Dependent Care Account (DCA) options.

Similar Jobs

More Jobs at IBSS

  • Senior Security Engineer
    $120K — $145K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person
  • IT Project Manager
    $100K — $115K *
    Remote
    Education, Government & Non-Profit
    Remote in Woods Hole, MA
  • IT Project Manager
    $100K — $115K *
    Woods Hole, MA 02543 (Barnstable County)
    Education, Government & Non-Profit
    In-Person
  • Mid-Level Network Engineer
    $88K — $105K *
    Washington, DC 20011 (District Of Columbia County)
    Technical Services
    In-Person
  • Cybersecurity Subject Matter Expert (SME)
    $110K — $130K *
    Washington, DC 20011 (District Of Columbia County)
    Education, Government & Non-Profit
    In-Person

More Education, Government & Non-Profit Jobs

Find similar Cybersecurity Subject Matter Expert (SME) jobs: