Cybersecurity SME Level III

OneZero Solutions

Alexandria (VA)

Hybrid

USD 120,000 - 180,000

Full time

10 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
Life insurance
401(k) with company matching
Paid time off and holidays
Employee referral program
Educational assistance

Job summary

OneZero, LLC is seeking a Cybersecurity SME (Level III) to support a federal cybersecurity program office under an RMF framework. The SME will serve as the ISSE for DoD information systems and OT/ICS platforms, leading RMF activities, risk assessments, and security reporting.

The role requires active SECRET clearance, DoD 8140 certification on day one, and CISSP with ISSEP/ISSAP. Strong leadership, communication, and RMF experience are essential for success.

Qualifications

  • Bachelor's degree in a related technical discipline.
  • Minimum 8 years of progressive cybersecurity experience.
  • DoD 8140 certification required on the first day.
  • CISSP-ISSEP or CISSP-ISSAP (active CISSP) required.
  • Active final SECRET clearance (Tier 3/SF-86).
  • U.S. citizenship and ability to obtain CAC.
  • Strong leadership and communication skills.
  • Experience implementing RMF, including system categorization.

Responsibilities

  • Serve as ISSE for assigned USCG information systems and OT/hybrid platforms; lead the RMF lifecycle.
  • Develop and manage RMF authorization packages in eMASS (SSPs, SCTMs, POA&Ms, etc).
  • Perform Security Readiness Reviews and manage remediation with patches and POA&Ms.
  • Maintain continuous monitoring and ensure compliance with DoD, DHS, USCG requirements and DISA STIGs.
  • Conduct Security Impact Assessments and participate in governance and design reviews.
  • Integrate Zero Trust principles and OT/ICS security into designs; conduct risk assessments.
  • Evaluate emerging threats and supply-chain risks; propose safeguards.
  • Track and report on orders from JFHQ-DoDIN, USCYBERCOM, CGCYBER; provide leadership updates.
  • Provide senior technical leadership and mentorship to the ISSE/ SME team.

Skills

RMF implementation
ISSE expertise
Security leadership
Vulnerability assessment
Executive communication

Education

Bachelor's degree in related field

Tools

eMASS
ACAS/Nessus
DISA STIGs

Job description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/

Position Title:Cybersecurity SME Level III

Location:Hybrid - National Capital Region (USCG Headquarters, 2703 Martin Luther King Jr. Ave SE, Washington, DC and USCG CG-C5I-Y, 7323 Telegraph Rd, Alexandria, VA)

Clearance:Active DoD SECRET (final) required

Position Summary

OneZero, LLC is seeking a Cybersecurity SME (Level III) to support a federal cybersecurity program office under an Information Assurance Risk Management Framework (IA RMF) support services contract. The Cybersecurity SME serves as a technical expert performing Information System Security Engineer (ISSE) services and cybersecurity compliance assessment, management, and reporting for federal information systems and operational technology. The SME provides insight and guidance on strategic, tactical, and operational cybersecurity plans; analyzes system and architecture requirements; recommends cybersecurity solutions; and advises on the impact of new legislation, mandates, regulations, technologies, and industry best practices.

Key Responsibilities
  • Serve as the designated Information System Security Engineer (ISSE) for assigned USCG information systems, operational technology (OT), and hybrid cyber-physical platforms; lead the full NIST SP 800-37 RMF lifecycle from categorization through continuous monitoring and decommissioning.
  • Develop, maintain, and manage RMF authorization packages in eMASS, including SSPs, SCTMs, POA&Ms, Security Assessment Reports, Contingency Plans, Incident Response Plans, risk assessments, hardware/software lists, network topology and boundary diagrams, and data flow diagrams.
  • Perform Security Readiness Reviews (SRRs); review and analyze ACAS/Nessus vulnerability scan results; assign, track, and validate remediation through patching cycles or POA&Ms, including false-positive management and DISA ticket coordination.
  • Maintain continuous monitoring and ensure ongoing compliance with DoD, DHS, and USCG security requirements and DISA STIGs; support cATO initiatives, automated evidence collection, and dashboard integration.
  • Conduct Security Impact Assessments for proposed system changes; participate in change management boards, DHS SELC reviews, acquisition milestones (PMR, PDR, CDR), CONOPS working groups, and technical exchange meetings.
  • Integrate Zero Trust principles, RMF controls, and OT/ICS-specific security requirements into system designs; conduct security engineering analyses, trade studies, and architectural risk assessments.
  • Evaluate emerging threats, adversary TTPs, OT/ICS vulnerabilities, and supply-chain risks; recommend safeguards and mitigation strategies that reduce cyber-attack surface and enhance resilience.
  • Track and report status on authoritative orders (OPORDs, TASKORDs, FRAGOs, ALCOASTs, TCTOs) from JFHQ-DoDIN, USCYBERCOM, and CGCYBER.
  • Produce weekly, monthly, and quarterly cybersecurity readiness updates, metrics, executive-level briefings, and risk memorandums for Government leadership; respond to ad hoc cybersecurity data calls.
  • Provide senior technical leadership and mentorship to the ISSE/SME team; formulate and submit continuous improvement recommendations to the COR regarding contracted operations.
Required Qualifications
  • Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related technical discipline from an accredited institution. No substitution of experience for the education requirement is permitted for this labor category.
  • Minimum 8 years of related, progressive cybersecurity experience in a technical field related to this labor category.
  • DoD 8140 certification - required on the first day of performance. Must hold CISSP-ISSEP or CISSP-ISSAP (each requires an active CISSP), active and in good standing, before starting work. See Certification Requirements below. Waivers will not be granted.
  • Active final SECRET personnel security clearance (Tier 3 / SF-86 investigation).
  • S. citizenship; favorably adjudicated background investigation and FBI fingerprint check; ability to obtain and maintain a DoD Common Access Card (CAC) as a condition of continued employment.
  • Recognized expertise and technical leadership in the cybersecurity discipline, with exceptional oral and written communication skills and the ability to interface with all levels of Government management.
  • Demonstrated experience implementing the RMF, including system categorization
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Subject Matter Expert (SME) – Level III
Cybersecurity Subject Matter Expert (SME) – Level III

OneZero Solutions • Alexandria (VA)

Hybrid
USD 130,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+6
Cybersecurity SME Level II
Cybersecurity SME Level II

OneZero Solutions • Alexandria (VA)

Hybrid
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+6
Information System Security Officer (SME), Level III
Information System Security Officer (SME), Level III

OneZero Solutions • Baltimore (MD)

On-site
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Senior Cybersecurity SME (RMF & OT/ICS)
Senior Cybersecurity SME (RMF & OT/ICS)

OneZero Solutions • Alexandria (VA)

Hybrid
USD 130,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+6
Information System Security Officer Level II
Information System Security Officer Level II

OneZero Solutions • Baltimore (MD)

On-site
USD 120,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+6
Senior Cybersecurity ISSE | RMF Expert | DoD SECRET
Senior Cybersecurity ISSE | RMF Expert | DoD SECRET

OneZero Solutions • Alexandria (VA)

Hybrid
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+5
Security Control Assessor (SME), Level III
Security Control Assessor (SME), Level III

OneZero Solutions • Baltimore (MD)

Hybrid
USD 120,000 - 180,000
Health insurance
401(k) with company matching
Paid time off
Information Systems Security Engineer (ISSE), Level II
Information Systems Security Engineer (ISSE), Level II

OneZero Solutions • Baltimore (MD)

On-site
USD 140,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+5
Information Assurance Specialist III
Information Assurance Specialist III

OneZero Solutions • Arlington (VA)

Hybrid
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+5
Junior Technician
Junior Technician

Radwell International • Washington

Hybrid
USD 105,000 - 115,000