Full Job Description
Open Security Controls Assessment Language (SME) (TS/SCI)
Koniag IT Systems, a Koniag Government Services company, is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark Center, Alexandria, VA. This is a hybrid opportunity that requires 1-4 days of onsite work.
We offer competitive compensation and an extraordinary benefits package including health, dental, and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
We are seeking an experienced Open Security Controls Assessment Language (OSCAL) Subject Matter Expert (SME) to support the design, implementation, and optimization of automated security compliance and risk management solutions. The OSCAL SME will play a critical role in advancing our cybersecurity compliance initiatives by enabling machine-readable security documentation, enhancing interoperability, and streamlining authorization processes across multiple federal frameworks.
Essential Functions, Responsibilities & Duties may include, but are not limited to:
3 Serve as the technical expert for OSCAL adoption, implementation, and integration within federal compliance programs (e.g., FedRAMP, NIST RMF, DoD).
3 Develop, validate, and maintain OSCAL-based artifacts, including system security plans (SSPs), assessment plans, assessment results, and POA&M packages.
3 Provide guidance on mapping security controls to OSCAL models and ensuring alignment with NIST standards.
3 Support automation of ATO/authorization workflows by integrating OSCAL with governance, risk, and compliance (GRC) tools.
3 Collaborate with system owners, security assessors, and compliance teams to improve efficiency in security control assessment and reporting.
3 Deliver training, documentation, and best practices to internal teams and customers on OSCAL adoption.
3 Provide support and recommendations for the Department of Defense OSCAL standards development.
3 Stay current with OSCAL federal policy changes and industry adoption trends.
Qualifications
Required:
3 TS/SCI security Clearance required.
3 Bachelors degree in Cybersecurity, Information Systems, Computer Science, or related field (or equivalent work experience).
3 15+ years of experience in cybersecurity compliance, security assessment, or risk management.
3 Hands-on expertise with OSCAL schema, XML/JSON/YAML, and associated validation tools.
3 Deep knowledge of NIST frameworks (NIST SP-800-53 Rev. 5, NIST SP-800-37 Rev. 2 RMF, NIST Cybersecurity Framework [CSF 2.0]) and federal compliance standards (e.g., FedRAMP, FISMA, DoD RMF [DoDI 8510.01]).
3 Experience with cybersecurity documentation automation and Governance, Risk, and Compliance (GRC) platforms.
3 Excellent communication and technical writing skills.
3 Ability to work on-site 1-4 days a week.
Preferred:
3 Experience of contributing to or collaborating with the NIST OSCAL community.
3 Familiarity with DevSecOps pipelines, CI/CD automation, and security-as-code practices.
3 Understanding of cloud service provider (CSP) compliance processes (AWS, Azure, GCP, etc.).
3 Active security certification (e.g., CISSP, CISM, CAP, CCSP).