Cybersecurity Subject Matter Expert (SME)

Central Strategies, LLC

Washington, Northern (District of Columbia, KY)

Hybrid

USD 120,000 - 180,000

Full time

41 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Central Strategies LLC seeks a Cybersecurity Subject Matter Expert to deliver ISSE services for a federal program office, guiding RMF lifecycle from categorization to continuous monitoring and decommissioning. You will prepare RMF packages in eMASS and coordinate with DoD/DHS stakeholders.

The role requires active SECRET clearance, 6+ years in cybersecurity, and experience with assessing and enforcing cybersecurity controls across OT/ICS platforms.

Qualifications

  • Bachelor's degree in a related technical discipline.
  • At least 6 years of cybersecurity experience.
  • Active CISSP, CompTIA SecurityX/CASP+, CSSLP, CCSP, or CompTIA Cloud+ in good standing.
  • Active final SECRET clearance based on a Tier 3/SF-86 investigation; ability to obtain and maintain a Common Access Card.
  • Demonstrated RMF experience, including categorization, control selection and implementation, assessment, authorization, and continuous monitoring.
  • Strong knowledge of cybersecurity risk, laws and policy, threats and vulnerabilities, networking, protocols, network-security methods, and operational impacts.
  • Exceptional written and oral communication skills with the ability to advise technical teams and government leadership.

Responsibilities

  • Serve as the designated ISSE for assigned information systems; lead the RMF lifecycle.
  • Develop and maintain RMF packages in eMASS including SSPs, SCTMs, POA&Ms, assessment reports, contingency and incident response plans, risk assessments, inventories, topology diagrams, and data-flow diagrams.
  • Conduct Security Readiness Reviews; analyze ACAS/Nessus results; track remediation, patching, POA&Ms, false positives, and DISA coordination.
  • Maintain continuous monitoring and compliance with DoD, DHS, USCG, and DISA STIG requirements; support cATO, automated evidence collection, and dashboard integration.
  • Perform Security Impact Assessments and participate in change boards, DHS SELC reviews, acquisition milestones, CONOPS working groups, and technical exchange meetings.
  • Integrate Zero Trust, RMF controls, and OT/ICS security requirements into system designs; perform security engineering analyses, trade studies, and architectural risk assessments.
  • Evaluate emerging threats, adversary tactics, OT/ICS vulnerabilities, and supply-chain risks; recommend safeguards that reduce attack surface and improve resilience.
  • Track cybersecurity directives and produce readiness metrics, executive briefings, risk memoranda, recurring reports, and responses to cybersecurity data calls.

Skills

RMF experience
Security clearance
Written communication
Oral communication
Cybersecurity risk

Education

Bachelor's degree in a related technical discipline

Tools

eMASS
ACAS/Nessus/Security Center
Elastic SIEM
HBSS
Tanium
Splunk
ServiceNow
Burp Suite

Job description

Central Strategies LLC is seeking a Cybersecurity Subject Matter Expert (SME) to support a federal cybersecurity program office. This position provides Information System Security Engineer (ISSE) services and cybersecurity compliance, assessment, management, and reporting support for federal information systems, operational technology, and hybrid cyber-physical platforms. The SME advises government stakeholders on cybersecurity strategy, architecture, risk, mandates, emerging technologies, and industry best practices.

Key Responsibilities:

  • Serve as the designated ISSE for assigned information systems and operational technology; lead the NIST SP 800-37 RMF lifecycle from categorization through continuous monitoring and decommissioning.
  • Develop and maintain RMF authorization packages in eMASS, including SSPs, SCTMs, POA&Ms, assessment reports, contingency and incident response plans, risk assessments, inventories, topology diagrams, and data-flow diagrams.
  • Conduct Security Readiness Reviews; analyze ACAS/Nessus results; and track remediation, patching, POA&Ms, false positives, and DISA coordination.
  • Maintain continuous monitoring and compliance with DoD, DHS, USCG, and DISA STIG requirements; support cATO, automated evidence collection, and dashboard integration.
  • Perform Security Impact Assessments and participate in change boards, DHS SELC reviews, acquisition milestones, CONOPS working groups, and technical exchange meetings.
  • Integrate Zero Trust, RMF controls, and OT/ICS security requirements into system designs; perform security engineering analyses, trade studies, and architectural risk assessments.
  • Evaluate emerging threats, adversary tactics, OT/ICS vulnerabilities, and supply-chain risks; recommend safeguards that reduce attack surface and improve resilience.
  • Track cybersecurity directives and produce readiness metrics, executive briefings, risk memoranda, recurring reports, and responses to cybersecurity data calls.

Required Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Software Engineering, Information Systems, Computer Engineering, or a related technical discipline; experience may not substitute for the degree requirement.
  • At least 6 years of cybersecurity experience relevant to this position.
  • Active CISSP, CompTIA SecurityX/CASP+, CSSLP, CCSP, or CompTIA Cloud+, in good standing, before the start date.
  • Active final SECRET clearance based on a Tier 3/SF-86 investigation; ability to obtain and maintain a Common Access Card.
  • Demonstrated RMF experience, including categorization, control selection and implementation, assessment, authorization, and continuous monitoring.
  • Strong knowledge of cybersecurity risk, laws and policy, threats and vulnerabilities, networking, protocols, network-security methods, and operational impacts.
  • Exceptional written and oral communication skills with the ability to advise technical teams and government leadership.

Certification Requirements

Mapped to DoD Cyber Workforce Framework work role 631 (ISSE), Intermediate proficiency. The candidate must hold at least one accepted certification listed above before beginning performance. Security+ alone, Associate of ISC2 status, and certifications in progress do not qualify.

Desired Qualifications

  • Experience with eMASS, ACAS/Nessus/Security Center, Elastic SIEM, HBSS, Tanium, Splunk, ServiceNow, or Burp Suite.
  • Experience securing OT/ICS/SCADA, shipboard, aviation, or other cyber-physical platforms, including the DoD Assess Only process.
  • Familiarity with DHS 4300A, USCG cybersecurity policy, DoDAF artifacts, ITIL/DESMF practices, and DevSecOps pipelines.
  • Prior USCG, DHS, or DoD RMF support experience.

Work Environment and Additional Requirements

  • Hybrid work with on-site reporting for classified work, SIPRNet access, required meetings, training, and onboarding or offboarding activities.
  • SIPRNet access may be required; eligibility includes a final SECRET clearance and any required security briefing or read-on.
  • Occasional COR-approved CONUS travel may include other government facilities, vessels, aircraft, Alaska, Hawaii, or U.S. territories.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Subject Matter Expert (SME)
Senior Cybersecurity Subject Matter Expert (SME)

Central Strategies, LLC • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
Hybrid work with on-site classified
SIPRNet access may be required
Cybersecurity Subject Matter Expert (SME) – Level III
Cybersecurity Subject Matter Expert (SME) – Level III

OneZero Solutions • Alexandria (VA)

Hybrid
USD 130,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+6
Cybersecurity SME Level III
Cybersecurity SME Level III

OneZero Solutions • Alexandria (VA)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+5
Federal Cybersecurity ISSE — RMF, OT/ICS, Hybrid
Federal Cybersecurity ISSE — RMF, OT/ICS, Hybrid

Central Strategies, LLC • Washington, Northern (KY)

Hybrid
USD 120,000 - 180,000
Information Systems Security Engineer (ISSE) (TS/SCI with Poly Required)
Information Systems Security Engineer (ISSE) (TS/SCI with Poly Required)

GCI, Inc. • Tysons (VA)

On-site
USD 143,000 - 238,000
Senior Cybersecurity ISSE | RMF Expert | DoD SECRET
Senior Cybersecurity ISSE | RMF Expert | DoD SECRET

OneZero Solutions • Alexandria (VA)

Hybrid
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+5
Cybersecurity SME Level II
Cybersecurity SME Level II

OneZero Solutions • Alexandria (VA)

On-site
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+6
Cyber Security Subject Matter Expert (Security)
Cyber Security Subject Matter Expert (Security)

Snowrelic Inc • United States

On-site
USD 100,000 - 130,000
Senior Cybersecurity SME — RMF & Zero Trust Leader
Senior Cybersecurity SME — RMF & Zero Trust Leader

Central Strategies, LLC • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
Hybrid work with on-site classified
SIPRNet access may be required
Cybersecurity ISSE II — RMF & OT/ICS Expert
Cybersecurity ISSE II — RMF & OT/ICS Expert

OneZero Solutions • Alexandria (VA)

Hybrid
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+6