Central Strategies LLC is seeking a Cybersecurity Subject Matter Expert (SME) to support a federal cybersecurity program office. This position provides Information System Security Engineer (ISSE) services and cybersecurity compliance, assessment, management, and reporting support for federal information systems, operational technology, and hybrid cyber-physical platforms. The SME advises government stakeholders on cybersecurity strategy, architecture, risk, mandates, emerging technologies, and industry best practices.
Key Responsibilities:
- Serve as the designated ISSE for assigned information systems and operational technology; lead the NIST SP 800-37 RMF lifecycle from categorization through continuous monitoring and decommissioning.
- Develop and maintain RMF authorization packages in eMASS, including SSPs, SCTMs, POA&Ms, assessment reports, contingency and incident response plans, risk assessments, inventories, topology diagrams, and data-flow diagrams.
- Conduct Security Readiness Reviews; analyze ACAS/Nessus results; and track remediation, patching, POA&Ms, false positives, and DISA coordination.
- Maintain continuous monitoring and compliance with DoD, DHS, USCG, and DISA STIG requirements; support cATO, automated evidence collection, and dashboard integration.
- Perform Security Impact Assessments and participate in change boards, DHS SELC reviews, acquisition milestones, CONOPS working groups, and technical exchange meetings.
- Integrate Zero Trust, RMF controls, and OT/ICS security requirements into system designs; perform security engineering analyses, trade studies, and architectural risk assessments.
- Evaluate emerging threats, adversary tactics, OT/ICS vulnerabilities, and supply-chain risks; recommend safeguards that reduce attack surface and improve resilience.
- Track cybersecurity directives and produce readiness metrics, executive briefings, risk memoranda, recurring reports, and responses to cybersecurity data calls.
Required Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Software Engineering, Information Systems, Computer Engineering, or a related technical discipline; experience may not substitute for the degree requirement.
- At least 6 years of cybersecurity experience relevant to this position.
- Active CISSP, CompTIA SecurityX/CASP+, CSSLP, CCSP, or CompTIA Cloud+, in good standing, before the start date.
- Active final SECRET clearance based on a Tier 3/SF-86 investigation; ability to obtain and maintain a Common Access Card.
- Demonstrated RMF experience, including categorization, control selection and implementation, assessment, authorization, and continuous monitoring.
- Strong knowledge of cybersecurity risk, laws and policy, threats and vulnerabilities, networking, protocols, network-security methods, and operational impacts.
- Exceptional written and oral communication skills with the ability to advise technical teams and government leadership.
Certification Requirements
Mapped to DoD Cyber Workforce Framework work role 631 (ISSE), Intermediate proficiency. The candidate must hold at least one accepted certification listed above before beginning performance. Security+ alone, Associate of ISC2 status, and certifications in progress do not qualify.
Desired Qualifications
- Experience with eMASS, ACAS/Nessus/Security Center, Elastic SIEM, HBSS, Tanium, Splunk, ServiceNow, or Burp Suite.
- Experience securing OT/ICS/SCADA, shipboard, aviation, or other cyber-physical platforms, including the DoD Assess Only process.
- Familiarity with DHS 4300A, USCG cybersecurity policy, DoDAF artifacts, ITIL/DESMF practices, and DevSecOps pipelines.
- Prior USCG, DHS, or DoD RMF support experience.
Work Environment and Additional Requirements
- Hybrid work with on-site reporting for classified work, SIPRNet access, required meetings, training, and onboarding or offboarding activities.
- SIPRNet access may be required; eligibility includes a final SECRET clearance and any required security briefing or read-on.
- Occasional COR-approved CONUS travel may include other government facilities, vessels, aircraft, Alaska, Hawaii, or U.S. territories.