Hiring.Camp

SME – Information Security Analyst DoS CSS

OneZero Solutions

Location
Washington, DC
Workplace
Remote, Hybrid
Type
Full-time
Department
Security
Education
Master
Source
ApplicantPro

Description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/ 

Position Title: SME – Information Security Analyst

Location: Remote; must reside within the National Capital Region (NCR).

Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures.

Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award

Position Summary

The SME – Information Security Analyst is the program's most senior ISSO practitioner. The SME serves as ISSO of record for DT/EA/CST's High Value Assets, High-baseline, cloud/hybrid, and most complex consular systems; leads categorization, control selection, and authorization packages for new and re-authorizing systems; and acts as technical mentor and peer reviewer for the Senior and Information Assurance analysts.

Key Responsibilities

  • Serve as ISSO of record and primary cybersecurity point of contact for an assigned portfolio of approximately 3–4 HVA, High-baseline, or otherwise complex systems.
  • Lead RMF Steps 1–3 for new and re-authorizing systems: FIPS 199 / NIST SP 800-60 categorization with documented CIA justifications; baseline selection and HVA, zero-trust, and cloud overlays; Control Tailoring Rationale; Inherited Controls Matrix; SSP development; Security Plan Approval Recommendation Letter; Evidence Index; and Implementation Readiness Review.
  • Develop and maintain the full authorization artifact set: SSP, Security Control Implementation Statements, PIA, DIRA, ISA/MOU, Security Assessment Plan, POA&M, SIA, system inventory, IRP, CP/ISCP, CP Test reports, and CMP.
  • Lead Security Control Review Meetings and control demonstrations with the independent Security Control Assessor; attend A&A Findings Meetings; support remediation validation; prepare the AODR Information Sheet for risk briefings(RMF Steps 4–5).
  • Direct system-specific security operations contractors to obtain technical evidence and implement remediation; validate closure evidence before POA&M closure.
  • Maintain authoritative POA&Ms in the GRC tool with monthly updates and updates within 5 business days of status changes; ensure realistic milestones, accurate risk levels, and attached closure evidence(RMF Step 6).
  • Review iPost scores weekly, coordinate remediation of findings contributing to elevated risk, and track and report findings open more than 30 days.
  • Review vulnerability, KEV, CVE, and STIG scan results within 5 business days; ensure critical and high vulnerabilities are addressed within Department and BOD timelines.
  • Plan and conduct annual Contingency Plan tests and Annual Control Assessments for assigned systems; document objectives, scope, results, and lessons learned.
  • Perform Security Impact Analyses for CCB/ECM changes; prepare the Quarterly Configuration and Change Impact Summary.
  • Coordinate with the SOC, incident response teams, and system owners on incidents; support post-incident reviews and update RMF artifacts accordingly.
  • Serve as first line of defense during OIG, GAO, CISA, HVA, BOD, OMB, penetration test, and CDM audits and data calls; maintain the Audit and Data Call Response Package.
  • Develop system retirement memos and POA&M (risk) transfer memos; validate and close POA&Ms at decommissioning.
  • Mentor Senior and Information Assurance analysts; peer-review artifacts for accuracy, completeness, and Department format compliance.

Required Qualifications

  • Ten (10)+ years of information security experience, including six (6)+ years as an ISSO or A&A lead for federal information systems.
  • Expert working knowledge of NIST SP 800-37 Rev. 2, SP 800-53/53A Rev. 5, SP 800-60, SP 800-34, and FIPS 199/200; demonstrated experience authoring complete authorization packages.
  • Experience as ISSO for High-baseline or HVA systems, or for cloud/hybrid authorization boundaries.
  • Current CISSP (or CISM, or CGRC/CAP with CISSP obtained within 12 months).
  • Active, final SECRET security clearance; U.S. citizenship.
  • Experience managing POA&Ms and authorization packages in an enterprise GRC tool.
  • Excellent technical writing skills; able to produce Government-ready artifacts with minimal editing.

Preferred Qualifications

  • Master's degree in a related field.
  • Department of State (DT/CA/CST) experience; ArchAngel and iPost proficiency.
  • CISA, CRISC, or CCSP certification.
  • Experience with FedRAMP inheritance, DevSecOps pipeline controls, and Privacy (PIA) / Digital Identity (DIRA, NIST SP 800-63) assessments.

Technical Skills

  • NIST RMF end to end; SSP, SAR, POA&M, SIA, CP/ISCP, IRP, CMP, PIA, DIRA, ISA/MOU authoring.
  • GRC platforms (ArchAngel or equivalent), iPost or equivalent risk scoring, CDM data.
  • Interpretation of Tenable and Wiz vulnerability/compliance results, KEV reports, STIG scans, and penetration test findings.
  • Visio boundary and data-flow diagramming; advanced Word/Excel for artifact and metrics production.

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant ISSO experience in lieu of degree.

Remote/Hybrid/On-site and any other relevant work-environment requirement

Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.

Position Status:

New Position, contingent upon Call Order award

OneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Skills

ExcelCybersecuritySOCComplianceTechnical WritingCISSP

Similar Jobs

23

Cyber Security SME - Information System Security Officer (ISSO)

Pae·US-AK-Fairbanks-Arctics, US·Onsite

1w ago

6520 - Laboratory IT Support SME/ Information Systems Engineer 2

"Verista, Inc."·Cambridge, MA +1

2w ago

SME Instructor Information Security

Team Carney·Linthicum, MD·Onsite

6d ago

J39 Information Operations SME

Universal Strategy Group·Tampa, FL

1w ago

Research SME - Quantum Information Science

Bluemont Technology & Research, Inc.·Bethesda, MD

4mo ago

J39 Information Operations (IO) SME

K2 Solutions·MacDill AFB, FL

1d ago

Information Security Analyst - SME

Tyto Athene·Camp Lejeune, NC

2w ago

Information Security Analyst - SME

Tyto Athene·Quantico, VA

4w ago

Senior Information Security Analyst, SME

Dminc·Atlanta, GA

2mo ago

Information Security Analyst - SME

Zantech·Camp Springs, MD·Remote

1y+ ago

Project Manager - Team Lead / Information Security Analyst - SME

Zantech·Camp Springs, MD·Remote

1y+ ago

Sr. Information Assurance/Security SME

Amyx·Washington, DC

1y+ ago

Information System Security Manager SME

Galapagos·Colorado Springs, CO

1w ago

Information Systems Security Engineer - SME

Agile Defense·Washington, D.C.·Onsite

7mo ago

Information Technology Program Manager - SME

Zantech·Camp Springs, MD·Remote

1y+ ago

Information Systems Security Engineer (ISSE) - SME/Cloud-based, Senior Advisor - TS/SCI w/poly

Peraton·Washington, DC

1mo ago

Information Systems Security Manager (ISSM) – SME

Cgsfederal·Washington, DC·Onsite

5mo ago

Information, Review and Release Analyst- SME

Nwis·VA543: 22270 Pacific Blvd, VA·Onsite

8mo ago

Information, Review and Release Analyst- SME

Nwis·VA543: 22270 Pacific Blvd, VA·Onsite

10mo ago

Information Warfare Space Subject Matter Expert (SME)

Scires·Norfolk, VA

2d ago

Counterintelligence/Information Operations Intelligence (CI/IOI) Analyst - SME

Gdit·USA CO Colorado Springs - - Customer Proprietary, US

2w ago

Counterintelligence/Information Operations Intelligence (CI/IOI) Analyst - SME

GDIT·USA CO Colorado Springs - - Customer Proprietary, US

2w ago

Information Technology/Data Warehouse Subject Matter Expert (SME)

Anavationllc·Huntsville, AL·Onsite

4w ago