Cybersecurity Subject Matter Expert (SME) - Level III

OneZero Solutions

$120K — $145K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a related technical field; no substitutions allowed.
  • 8+ years of progressive cybersecurity experience in a technical role.
  • Active CISSP-ISSAP or CISSP-ISSEP certification, current before start.
  • Active SECRET clearance with eligibility requirements for the task order.
  • U.S. citizenship and ability to obtain a DoD CAC.
  • Strong technical leadership and communication skills at all government levels.
  • Demonstrated experience with Risk Management Framework (RMF) processes.

Responsibilities

  • Serve as the designated Information System Security Engineer (ISSE) for USCG information systems and OT; lead RMF lifecycle activities.
  • Develop and manage RMF authorization packages in eMASS, including various security documentation.
  • Perform Security Readiness Reviews and analyze vulnerability scan results, overseeing remediation efforts.
  • Ensure compliance with DoD and USCG requirements through continuous monitoring.
  • Conduct Security Impact Assessments and contribute to change management processes.
  • Integrate Zero Trust principles and OT-specific security requirements into system designs.
  • Evaluate threats and vulnerabilities in OT/ICS environments and recommend mitigation strategies.

Benefits

  • Hybrid schedule with authorized telework and on-site requirements for classified work.
  • Occasional travel opportunities within the continental U.S. and territories.
Full Job Description
Position Title: Cybersecurity Subject Matter Expert (SME) - Level III

Location: Hybrid - National Capital Region (USCG Headquarters, 2703 Martin Luther King Jr. Ave SE, Washington, DC and USCG CG-C5I-Y, 7323 Telegraph Rd, Alexandria, VA)

Clearance: Active Secret
Position Summary
OneZero, LLC is seeking a Cybersecurity SME (Level II) to support a federal cybersecurity program office under an Information Assurance Risk Management Framework (IA RMF) support services contract. The Cybersecurity SME serves as a technical expert performing Information System Security Engineer (ISSE) services and cybersecurity compliance assessment, management, and reporting for federal information systems and operational technology. The SME provides insight and guidance on strategic, tactical, and operational cybersecurity plans; analyzes system and architecture requirements; recommends cybersecurity solutions; and advises on the impact of new legislation, mandates, regulations, technologies, and industry best practices.
Key Responsibilities
  • Serve as the designated Information System Security Engineer (ISSE) for assigned USCG information systems, operational technology (OT), and hybrid cyber-physical platforms; lead the full NIST SP 800-37 RMF lifecycle from categorization through continuous monitoring and decommissioning.
  • Develop, maintain, and manage RMF authorization packages in eMASS, including SSPs, SCTMs, POA&Ms, Security Assessment Reports, Contingency Plans, Incident Response Plans, risk assessments, hardware/software lists, network topology and boundary diagrams, and data flow diagrams.
  • Perform Security Readiness Reviews (SRRs); review and analyze ACAS/Nessus vulnerability scan results; assign, track, and validate remediation through patching cycles or POA&Ms, including false-positive management and DISA ticket coordination.
  • Maintain continuous monitoring and ensure ongoing compliance with DoD, DHS, and USCG security requirements and DISA STIGs; support cATO initiatives, automated evidence collection, and dashboard integration.
  • Conduct Security Impact Assessments for proposed system changes; participate in change management boards, DHS SELC reviews, acquisition milestones (PMR, PDR, CDR), CONOPS working groups, and technical exchange meetings.
  • Integrate Zero Trust principles, RMF controls, and OT/ICS-specific security requirements into system designs; conduct security engineering analyses, trade studies, and architectural risk assessments.
  • Evaluate emerging threats, adversary TTPs, OT/ICS vulnerabilities, and supply-chain risks; recommend safeguards and mitigation strategies that reduce cyber-attack surface and enhance resilience.
  • Track and report status on authoritative orders (OPORDs, TASKORDs, FRAGOs, ALCOASTs, TCTOs) from JFHQ-DoDIN, USCYBERCOM, and CGCYBER.
  • Produce weekly, monthly, and quarterly cybersecurity readiness updates, metrics, executive-level briefings, and risk memorandums for Government leadership; respond to ad hoc cybersecurity data calls.
  • Provide senior technical leadership and mentorship to the ISSE/SME team; formulate and submit continuous improvement recommendations to the COR regarding contracted operations.
Required Qualifications
  • Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related technical discipline from an accredited institution. No substitution of experience for the education requirement is permitted for this labor category.
  • Minimum 8 years of related, progressive cybersecurity experience in a technical field related to this labor category.
  • Active professional certification (DoD 8140/8570 qualifying): CISSP-ISSAP or CISSP-ISSEP. Certification must be current prior to the start of performance; waivers will not be granted.
  • Active final SECRET personnel security clearance (Tier 3 / SF-86 investigation) with the ability to maintain eligibility for the duration of the task order; execution of a Classified Information Non-Disclosure Agreement (SF-312) required.
  • S. citizenship; favorably adjudicated background investigation and FBI fingerprint check; ability to obtain and maintain a DoD Common Access Card (CAC) as a condition of continued employment.
  • Recognized expertise and technical leadership in the cybersecurity discipline, with exceptional oral and written communication skills and the ability to interface with all levels of Government management.
  • Demonstrated experience implementing the RMF, including system categorization, control selection, implementation, assessment, and continuous monitoring.
  • Core knowledge of: risk management processes; national and international cybersecurity laws, regulations, policies, and ethics; cybersecurity principles; cyber threats and vulnerabilities; computer networking concepts, protocols, and network security methodologies; and the operational impacts of cybersecurity lapses.
Desired Qualifications
  • Experience with USCG/DoD security tools: eMASS, ACAS/Nessus/Security Center, Elastic SIEM, HBSS, Tanium, Splunk, ServiceNow, and Burp Suite.
  • Experience with OT/ICS/SCADA security, shipboard or aviation platform systems, and the DoD "Assess Only" process.
  • Familiarity with DHS 4300A, COMDTINST cybersecurity policy, DoDAF artifacts, ITIL/DESMF practices, and DevSecOps pipelines.
  • Prior USCG, DHS, or DoD RMF support experience.
Work Environment & Additional Requirements
  • Hybrid schedule: routine telework is authorized, but personnel must report on-site (hoteling) for classified (SECRET) work, SIPRNet access, meetings and events requiring presence, training, and personnel on/offboarding.
  • Occasional CONUS travel (and potentially Alaska, Hawaii, or U.S. Territories)

Similar Jobs

More Jobs at OneZero Solutions

More Information Technology Jobs

Find similar Cybersecurity Subject Matter Expert (SME) - Level III jobs: