Position Title: SME - Information Security Analyst
Location: Remote; must reside within the National Capital Region (NCR).
Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. - 3:00 p.m. ET, Monday - Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures.
Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award
Position SummaryThe SME - Information Security Analyst is the program's most senior ISSO practitioner. The SME serves as ISSO of record for DT/EA/CST's High Value Assets, High-baseline, cloud/hybrid, and most complex consular systems; leads categorization, control selection, and authorization packages for new and re-authorizing systems; and acts as technical mentor and peer reviewer for the Senior and Information Assurance analysts.
Key Responsibilities- Serve as ISSO of record and primary cybersecurity point of contact for an assigned portfolio of approximately 3-4 HVA, High-baseline, or otherwise complex systems.
- Lead RMF Steps 1-3 for new and re-authorizing systems: FIPS 199 / NIST SP 800-60 categorization with documented CIA justifications; baseline selection and HVA, zero-trust, and cloud overlays; Control Tailoring Rationale; Inherited Controls Matrix; SSP development; Security Plan Approval Recommendation Letter; Evidence Index; and Implementation Readiness Review.
- Develop and maintain the full authorization artifact set: SSP, Security Control Implementation Statements, PIA, DIRA, ISA/MOU, Security Assessment Plan, POA&M, SIA, system inventory, IRP, CP/ISCP, CP Test reports, and CMP.
- Lead Security Control Review Meetings and control demonstrations with the independent Security Control Assessor; attend A&A Findings Meetings; support remediation validation; prepare the AODR Information Sheet for risk briefings(RMF Steps 4-5).
- Direct system-specific security operations contractors to obtain technical evidence and implement remediation; validate closure evidence before POA&M closure.
- Maintain authoritative POA&Ms in the GRC tool with monthly updates and updates within 5 business days of status changes; ensure realistic milestones, accurate risk levels, and attached closure evidence(RMF Step 6).
- Review iPost scores weekly, coordinate remediation of findings contributing to elevated risk, and track and report findings open more than 30 days.
- Review vulnerability, KEV, CVE, and STIG scan results within 5 business days; ensure critical and high vulnerabilities are addressed within Department and BOD timelines.
- Plan and conduct annual Contingency Plan tests and Annual Control Assessments for assigned systems; document objectives, scope, results, and lessons learned.
- Perform Security Impact Analyses for CCB/ECM changes; prepare the Quarterly Configuration and Change Impact Summary.
- Coordinate with the SOC, incident response teams, and system owners on incidents; support post-incident reviews and update RMF artifacts accordingly.
- Serve as first line of defense during OIG, GAO, CISA, HVA, BOD, OMB, penetration test, and CDM audits and data calls; maintain the Audit and Data Call Response Package.
- Develop system retirement memos and POA&M (risk) transfer memos; validate and close POA&Ms at decommissioning.
- Mentor Senior and Information Assurance analysts; peer-review artifacts for accuracy, completeness, and Department format compliance.
Required Qualifications- Ten (10)+ years of information security experience, including six (6)+ years as an ISSO or A&A lead for federal information systems.
- Expert working knowledge of NIST SP 800-37 Rev. 2, SP 800-53/53A Rev. 5, SP 800-60, SP 800-34, and FIPS 199/200; demonstrated experience authoring complete authorization packages.
- Experience as ISSO for High-baseline or HVA systems, or for cloud/hybrid authorization boundaries.
- Current CISSP (or CISM, or CGRC/CAP with CISSP obtained within 12 months).
- Active, final SECRET security clearance; U.S. citizenship.
- Experience managing POA&Ms and authorization packages in an enterprise GRC tool.
- Excellent technical writing skills; able to produce Government-ready artifacts with minimal editing.
Preferred Qualifications- Master's degree in a related field.
- Department of State (DT/CA/CST) experience; ArchAngel and iPost proficiency.
- CISA, CRISC, or CCSP certification.
- Experience with FedRAMP inheritance, DevSecOps pipeline controls, and Privacy (PIA) / Digital Identity (DIRA, NIST SP 800-63) assessments.
Technical Skills- NIST RMF end to end; SSP, SAR, POA&M, SIA, CP/ISCP, IRP, CMP, PIA, DIRA, ISA/MOU authoring.
- GRC platforms (ArchAngel or equivalent), iPost or equivalent risk scoring, CDM data.
- Interpretation of Tenable and Wiz vulnerability/compliance results, KEV reports, STIG scans, and penetration test findings.
- Visio boundary and data-flow diagramming; advanced Word/Excel for artifact and metrics production.
EducationBachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant ISSO experience in lieu of degree.
Remote/Hybrid/On-site and any other relevant work-environment requirementRemote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.
Position Status:New Position, contingent upon Call Order award