Cybersecurity SME Level II

onezerollc

Alexandria (VA)

Hybrid

USD 120,000 - 165,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
Life insurance
401(k) with company matching
Paid time off

Job summary

OneZero, LLC is seeking a Cybersecurity SME Level II to support a federal cybersecurity program under an IA RMF framework. You will provide ISSE services, cybersecurity compliance assessment, management, and reporting for federal information systems and OT, advising on strategic and operational plans.

The role requires active DoD SECRET clearance, DoD 8140 certification with a qualifying credential (CISSP/CASP+/CSSLP/CCSP/Cloud+), and experience leading RMF processes across government

Qualifications

  • Requires a Bachelor’s degree in a technical field from an accredited institution.
  • Minimum 6 years of progressive cybersecurity experience in a related field.
  • Active DoD 8140 certification and one of CISSP, CASP+/CSSLP, CCSP, or CompTIA Cloud+ before starting work.

Responsibilities

  • Lead RMF lifecycle for assigned systems from categorization to continuous monitoring.
  • Develop and manage RMF authorization packages in eMASS including SSPs and related artifacts.
  • Review vulnerability scans, track remediation, and coordinate with patch cycles and POA&Ms.
  • Maintain continuous monitoring and ensure compliance with DoD/agency requirements.
  • Conduct security impact assessments and participate in change management and DHS reviews.
  • Integrate Zero Trust and OT/ICS security requirements into designs.
  • Evaluate threats and supply-chain risks and recommend mitigations.
  • Produce readiness updates and executive briefings for Government leadership.

Skills

RMF cybersecurity
Oral and written communication
ISSE experience
Security certifications

Education

Bachelor's degree in CS/IT or related field

Tools

eMASS
Nessus/ACAS
DISA ticketing systems

Job description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/

Position: Cybersecurity SME Level II

Location: Hybrid – National Capital Region (USCG Headquarters, 2703 Martin Luther King Jr. Ave SE, Washington, DC and USCG CG-C5I-Y, 7323 Telegraph Rd, Alexandria, VA)

Clearance: Active DoD SECRET (final) required

Position Summary

OneZero, LLC is seeking a Cybersecurity SME (Level II) to support a federal cybersecurity program office under an Information Assurance Risk Management Framework (IA RMF) support services contract. The Cybersecurity SME serves as a technical expert performing Information System Security Engineer (ISSE) services and cybersecurity compliance assessment, management, and reporting for federal information systems and operational technology. The SME provides insight and guidance on strategic, tactical, and operational cybersecurity plans; analyzes system and architecture requirements; recommends cybersecurity solutions; and advises on the impact of new legislation, mandates, regulations, technologies, and industry best practices.

Key Responsibilities
  • Serve as the designated Information System Security Engineer (ISSE) for assigned USCG information systems, operational technology (OT), and hybrid cyber-physical platforms; lead the full NIST SP 800-37 RMF lifecycle from categorization through continuous monitoring and decommissioning.
  • Develop, maintain, and manage RMF authorization packages in eMASS, including SSPs, SCTMs, POA&Ms, Security Assessment Reports, Contingency Plans, Incident Response Plans, risk assessments, hardware/software lists, network topology and boundary diagrams, and data flow diagrams.
  • Perform Security Readiness Reviews (SRRs); review and analyze ACAS/Nessus vulnerability scan results; assign, track, and validate remediation through patching cycles or POA&Ms, including false-positive management and DISA ticket coordination.
  • Maintain continuous monitoring and ensure ongoing compliance with DoD, DHS, and USCG security requirements and DISA STIGs; support cATO initiatives, automated evidence collection, and dashboard integration.
  • Conduct Security Impact Assessments for proposed system changes; participate in change management boards, DHS SELC reviews, acquisition milestones (PMR, PDR, CDR), CONOPS working groups, and technical exchange meetings.
  • Integrate Zero Trust principles, RMF controls, and OT/ICS-specific security requirements into system designs; conduct security engineering analyses, trade studies, and architectural risk assessments.
  • Evaluate emerging threats, adversary TTPs, OT/ICS vulnerabilities, and supply-chain risks; recommend safeguards and mitigation strategies that reduce cyber-attack surface and enhance resilience.
  • Track and report status on authoritative orders (OPORDs, TASKORDs, FRAGOs, ALCOASTs, TCTOs) from JFHQ-DoDIN, USCYBERCOM, and CGCYBER.
  • Produce weekly, monthly, and quarterly cybersecurity readiness updates, metrics, executive-level briefings, and risk memorandums for Government leadership; respond to ad hoc cybersecurity data calls.
Required Qualifications
  • Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related technical discipline from an accredited institution. No substitution of experience for the education requirement is permitted for this labor category.
  • Minimum 6 years of related, progressive cybersecurity experience in a technical field related to this labor category.
  • DoD 8140 certification - required on the first day of performance. Must hold one of the certifications listed under Certification Requirements below (CISSP, CompTIA SecurityX/CASP+, CSSLP, CCSP, or CompTIA Cloud+), active and in good standing, before starting work. Waivers will not be granted.
  • Active final SECRET personnel security clearance (Tier 3 / SF-86 investigation)
  • Recognized expertise and technical leadership in the cybersecurity discipline, with exceptional oral and written communication skills and the ability to interface with all levels of Government management.
  • Demonstrated experience implementing the RMF, including system categorization, control selection, implementation, assessment, and continuous monitoring.
  • Core knowledge of: risk management processes; national and international cybersecurity laws, regulations, policies, and ethics; cybersecurity principles; cyber threats and vulnerabilities; computer networking concepts, protocols, and network security methodologies; and the operational impacts of cybersecurity lapses.
Certification Requirements (DoD 8140)

Cyber work roles on this task order are qualified under DoD Directive 8140.01 and DoD Manual 8140.03, Cyberspace Workforce Qualification and Management Program, which replaced DoD 8570.01-M. This position is mapped to DoD Cyber Workforce Framework (DCWF) work role 631 – Information Systems Security Developer (ISSE) at the Intermediate proficiency level. The legacy 8570 equivalent is IASAE Level II.

Accepted certifications - the candidate must already hold one of the following:

  • CISSP - ISC2 Certified Information Systems Security Professional
  • CompTIA SecurityX - the current name for CASP+ (rebranded December 2024). Either name on a résumé refers to the same credential.
  • CSSLP - ISC2 Certified Secure Software Lifecycle Professional
  • CCSP - ISC2 Certified Cloud Security Professional
  • CompTIA Cloud+
  • CISSP-ISSEP or CISSP-ISSAP - exceeds this requirement and also qualifies the candidate for the Level III position

Rules that apply to every candidate:

  • The certification must be "in hand before the start date". "In progress," "test scheduled," or "will
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity SME Level III
Cybersecurity SME Level III

OneZero Solutions • Alexandria (VA)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+5
Cybersecurity SME Level II
Cybersecurity SME Level II

OneZero Solutions • Alexandria (VA)

On-site
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+6
Cybersecurity SME Level III
Cybersecurity SME Level III

onezerollc • Alexandria (VA)

Hybrid
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+4
Senior Cybersecurity Subject Matter Expert (SME)
Senior Cybersecurity Subject Matter Expert (SME)

Central Strategies, LLC • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
Hybrid work with on-site classified
SIPRNet access may be required
Cybersecurity Subject Matter Expert (SME)
Cybersecurity Subject Matter Expert (SME)

Central Strategies, LLC • Washington, Northern (KY)

Hybrid
USD 120,000 - 180,000
Information System Security Officer (SME), Level III
Information System Security Officer (SME), Level III

onezerollc • Baltimore (MD)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+5
Information System Security Officer (SME), Level III
Information System Security Officer (SME), Level III

OneZero Solutions • Baltimore (MD)

On-site
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Senior Cybersecurity ISSE - RMF & OT/ICS Specialist
Senior Cybersecurity ISSE - RMF & OT/ICS Specialist

onezerollc • Alexandria (VA)

Hybrid
USD 120,000 - 165,000
Health insurance
Dental insurance
Vision insurance
+3
SME – Information Security Analyst DoS CSS
SME – Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 150,000 - 190,000
Health insurance
Dental insurance
Vision insurance
+6
Information System Security Officer Level II
Information System Security Officer Level II

onezerollc • Baltimore (MD)

On-site
USD 90,000 - 130,000
Health Insurance
Dental Insurance
Vision Insurance
+6