Job Title: Cybersecurity Subject Matter Expert (SME)
Location: Washington, DC
Clearance Required: Active Secret
Description IBSS is seeking a Cyber Security Subject Matter Expert (SME) to support a Federal customer. This position serves as the principal information assurance and cybersecurity expert on the contract, leading IA engineering, risk and vulnerability assessments, and security evaluation activities that protect NTIA's classified and unclassified systems, data, and networks and that maintain compliance with NIST, FISMA, and Department of Commerce (DOC) security policy. The Cyber Security SME works closely with the security engineer, ISSOs/Security Assessors, and customer leadership to sustain a strong security posture and Authority to Operate (ATO) portfolio.
Key Responsibilities:- Provide enhancement capabilities and standard operating procedures (SOPs) to assessment operations for execution and implementation.
- Maintain accountability for the integrity and confidentiality of the security assessment process; provide in-depth analysis of vulnerabilities across customer systems.
- Review and make recommendations on program-level documentation, including requirements specifications, system architecture, design documents, test plans, and security plans.
- Develop and document security evaluation test plans and procedures; conduct hands-on security testing, analyze results, document risk, and recommend countermeasures.
- Assess and calculate risk based on threats, vulnerabilities, and shortfalls uncovered in testing, and identify mitigating countermeasures.
- Provide oversight of the design, development, and implementation of security-related support systems.
- Research, evaluate, and develop Information Security policies and guidance.
- Develop, review, and update Information Assurance (IA) policies, procedures, and guidelines to keep NTIA systems aligned with evolving federal security requirements and enterprise governance expectations.
- Perform comprehensive risk and vulnerability assessments; document findings and recommend mitigation and remediation strategies to reduce organizational exposure to cyber threats.
- Ensure compliance with federal cybersecurity regulations, including NIST and FISMA, by reviewing security controls, identifying gaps, and supporting continuous monitoring activities.
- Develop and maintain system- and enterprise-level IA documentation, including System Security Plans (SSPs), risk assessments, control implementation statements, POA&Ms, and audit-ready ATO artifacts.
- Support system security engineering activities, ensuring security requirements are incorporated into system design, architecture, and configuration baselines throughout each system's lifecycle.
- Coordinate with system owners, ISSOs, architecture teams, and cybersecurity leadership to validate system requirements, address IA concerns, and resolve compliance or security issues.
- Monitor IA-related compliance activities, ensuring artifacts, assessments, and system configurations remain aligned with NIST SP 800-53 controls, agency policy, and Department directives.
- Actively participate in or lead technical exchange meetings, document action items and results, and brief customer leadership on the status of activities and risk findings.
Required Skills /Education/ Certifications & Qualifications:- Bachelor's degree in Information Technology, Computer Science, Business Management, or a related field.
- Minimum of eight (8) years of professional cybersecurity experience.
- CISSP or similar (CISM, CASP+, GSLC, etc.) recognized cybersecurity certification.
- Working knowledge of NIST SP 800-53, FISMA, and federal Risk Management Framework / ATO processes.
- Demonstrated experience conducting risk and vulnerability assessments and developing security evaluation test plans and procedures.
- Strong written and verbal communication skills, with experience briefing technical findings to leadership and government stakeholders.
- Active Secret Clearance required.
Desired Skills:- Experience supporting the Department of Commerce or another Federal Civilian Executive Branch (FCEB) agency's cybersecurity or information assurance program.
- Experience developing and maintaining ATO documentation (SSPs, SARs, POA&Ms) within a NIST Risk Management Framework or FedRAMP environment.
- Experience coordinating with Security Operations Center (SOC) or incident response teams on continuous monitoring and mitigation activities.
- Additional certifications such as CISM, CAP, Security+, or CEH.
IBSS offers a competitive benefits package that includes medical, dental, vision, and prescription drug coverage with a company-paid deductible, paid time off, federal holidays, a matching 401K plan, tuition/professional development reimbursement, and Flex-Spending (FSA)/Dependent Care Account (DCA) options.