SME - Information Security Analyst DoS CSS

OneZero Solutions

• $120K — $145K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of information security experience, including 6+ years as an ISSO or A&A lead for federal information systems.
  • Expert knowledge of NIST SP 800 series, with proven ability to author complete authorization packages.
  • Experience as ISSO for High-baseline or High Value Assets systems, or cloud/hybrid environments.
  • Current CISSP (or CISM, or CGRC/CAP with CISSP obtained within 12 months).
  • Active SECRET security clearance; must be a U.S. citizen.
  • Experience managing POA&Ms and authorization packages in an enterprise GRC tool.
  • Excellent technical writing skills; capable of producing polished Government-ready documents.

Responsibilities

  • Serve as ISSO and primary cybersecurity contact for a portfolio of 3-4 intricate systems.
  • Lead RMF Steps 1-3 for system categorization and security control selection.
  • Develop and maintain complete authorization artifact sets and associated documentation.
  • Facilitate Security Control Review Meetings and oversee remediation validations.
  • Manage system-specific security operations contractors for compliance and evidence collection.
  • Maintain authoritative POA&Ms with timely updates reflecting accurate risk status.
  • Conduct annual Contingency Plan tests and document results and lessons learned.

Benefits

  • Work remotely with minimal travel requirements.
  • Flexible working hours to accommodate day-to-day operations.
  • No work on Federal holidays or during Government closures.
  • A provided laptop and collaboration tools for remote work.
  • Participation in a team working on critical national security assets.
Full Job Description
Position Title: SME - Information Security Analyst

Location: Remote; must reside within the National Capital Region (NCR).

Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. - 3:00 p.m. ET, Monday - Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures.

Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award

Position Summary

The SME - Information Security Analyst is the program's most senior ISSO practitioner. The SME serves as ISSO of record for DT/EA/CST's High Value Assets, High-baseline, cloud/hybrid, and most complex consular systems; leads categorization, control selection, and authorization packages for new and re-authorizing systems; and acts as technical mentor and peer reviewer for the Senior and Information Assurance analysts.

Key Responsibilities
  • Serve as ISSO of record and primary cybersecurity point of contact for an assigned portfolio of approximately 3-4 HVA, High-baseline, or otherwise complex systems.
  • Lead RMF Steps 1-3 for new and re-authorizing systems: FIPS 199 / NIST SP 800-60 categorization with documented CIA justifications; baseline selection and HVA, zero-trust, and cloud overlays; Control Tailoring Rationale; Inherited Controls Matrix; SSP development; Security Plan Approval Recommendation Letter; Evidence Index; and Implementation Readiness Review.
  • Develop and maintain the full authorization artifact set: SSP, Security Control Implementation Statements, PIA, DIRA, ISA/MOU, Security Assessment Plan, POA&M, SIA, system inventory, IRP, CP/ISCP, CP Test reports, and CMP.
  • Lead Security Control Review Meetings and control demonstrations with the independent Security Control Assessor; attend A&A Findings Meetings; support remediation validation; prepare the AODR Information Sheet for risk briefings(RMF Steps 4-5).
  • Direct system-specific security operations contractors to obtain technical evidence and implement remediation; validate closure evidence before POA&M closure.
  • Maintain authoritative POA&Ms in the GRC tool with monthly updates and updates within 5 business days of status changes; ensure realistic milestones, accurate risk levels, and attached closure evidence(RMF Step 6).
  • Review iPost scores weekly, coordinate remediation of findings contributing to elevated risk, and track and report findings open more than 30 days.
  • Review vulnerability, KEV, CVE, and STIG scan results within 5 business days; ensure critical and high vulnerabilities are addressed within Department and BOD timelines.
  • Plan and conduct annual Contingency Plan tests and Annual Control Assessments for assigned systems; document objectives, scope, results, and lessons learned.
  • Perform Security Impact Analyses for CCB/ECM changes; prepare the Quarterly Configuration and Change Impact Summary.
  • Coordinate with the SOC, incident response teams, and system owners on incidents; support post-incident reviews and update RMF artifacts accordingly.
  • Serve as first line of defense during OIG, GAO, CISA, HVA, BOD, OMB, penetration test, and CDM audits and data calls; maintain the Audit and Data Call Response Package.
  • Develop system retirement memos and POA&M (risk) transfer memos; validate and close POA&Ms at decommissioning.
  • Mentor Senior and Information Assurance analysts; peer-review artifacts for accuracy, completeness, and Department format compliance.

Required Qualifications
  • Ten (10)+ years of information security experience, including six (6)+ years as an ISSO or A&A lead for federal information systems.
  • Expert working knowledge of NIST SP 800-37 Rev. 2, SP 800-53/53A Rev. 5, SP 800-60, SP 800-34, and FIPS 199/200; demonstrated experience authoring complete authorization packages.
  • Experience as ISSO for High-baseline or HVA systems, or for cloud/hybrid authorization boundaries.
  • Current CISSP (or CISM, or CGRC/CAP with CISSP obtained within 12 months).
  • Active, final SECRET security clearance; U.S. citizenship.
  • Experience managing POA&Ms and authorization packages in an enterprise GRC tool.
  • Excellent technical writing skills; able to produce Government-ready artifacts with minimal editing.

Preferred Qualifications
  • Master's degree in a related field.
  • Department of State (DT/CA/CST) experience; ArchAngel and iPost proficiency.
  • CISA, CRISC, or CCSP certification.
  • Experience with FedRAMP inheritance, DevSecOps pipeline controls, and Privacy (PIA) / Digital Identity (DIRA, NIST SP 800-63) assessments.

Technical Skills
  • NIST RMF end to end; SSP, SAR, POA&M, SIA, CP/ISCP, IRP, CMP, PIA, DIRA, ISA/MOU authoring.
  • GRC platforms (ArchAngel or equivalent), iPost or equivalent risk scoring, CDM data.
  • Interpretation of Tenable and Wiz vulnerability/compliance results, KEV reports, STIG scans, and penetration test findings.
  • Visio boundary and data-flow diagramming; advanced Word/Excel for artifact and metrics production.

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant ISSO experience in lieu of degree.

Remote/Hybrid/On-site and any other relevant work-environment requirement

Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.

Position Status:

New Position, contingent upon Call Order award

Similar Jobs

More Jobs at OneZero Solutions

More Information Technology Jobs

Find similar SME - Information Security Analyst DoS CSS jobs: